cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
460
Views
0
Helpful
1
Replies

Cisco IPSec client VPN fails to connect

dkramkowski
Level 1
Level 1

I have a new issue that cropped up after I updated our 5510 to 8.2(5)59. We have several ASAs at different sites, and have been using both AnyConnect VPN and the older Cisco IPSec VPN. From outside all of the networks, both VPN types work just fine to all sites. However, from the site with the 5510, if we try to connect to the site with a HA pair of 5515-X ASAs (it's an isolated site with no site to site VPN to it for security reasons), the client prompts for credentials, starts going through the motions of connecting, and then just stops, with the log indicating 'DEL_REASON_IKE_NEG_FAILED'.

This did work through that ASA, and the only thing that changed between the time it worked and stopped working was the update to the ASA, so I suspect something about the update affected the ability to connect out using IPSec.

Has anyone else seen this issue after updating to patch the IPSec vulnerability that came out a few months ago? Any thoughts on how to fix it?

1 Reply 1

Cisco Freak
Level 4
Level 4

Hi,

This looks like some mis-matched configuration between the VPN client and the ASA.

Can you please post your full configurations.

CF

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: