05-09-2005 11:36 PM - edited 02-21-2020 01:45 PM
Hi There,
I`m trying to create a vpn between a Pix and a linsys firewall. I don`t know what`s wrong but even fase 1 is`nt working, I`v tried des/md5, 3des/sha des/sha but nothing is working. Please see debug from crypto isakmp:
crypto_isakmp_process_block:src:LINKSYS IP, dest:PIX IP spt:500 dpt:500
OAK_AG exchange
ISAKMP (0): processing SA payload. message ID = 0
ISAKMP (0): Checking ISAKMP transform 1 against priority 21 policy
ISAKMP: encryption DES-CBC
ISAKMP: hash MD5
ISAKMP: auth pre-share
ISAKMP: default group 1
ISAKMP: life type in seconds
ISAKMP: life duration (VPI) of 0x0 0x1 0x51 0x80
ISAKMP (0): atts are acceptable. Next payload is 3
ISAKMP (0): processing KE payload. message ID = 0
ISAKMP (0): processing NONCE payload. message ID = 0
ISAKMP (0): processing ID payload. message ID = 0
ISAKMP (0): ID payload
next-payload : 10
type : 1
protocol : 17
port : 500
length : 8
ISAKMP (0): Total payload length: 12
return status is IKMP_NO_ERRORdebug cr
ISAKMP (0): retransmitting phase 1 (0)...ypto ipsec
PIX#
ISADB: reaper checking SA 0xee0c1c, conn_id = 0
ISADB: reaper checking SA 0xf72984, conn_id = 0
ISADB: reaper checking SA 0xf80614, conn_id = 0
ISAKMP (0): retransmitting phase 1 (1)...
ISAKMP (0): deleting SA: src LINKSYS IP, dst PIX IP
ISADB: reaper checking SA 0xee0c1c, conn_id = 0
ISADB: reaper checking SA 0xf72984, conn_id = 0
ISADB: reaper checking SA 0xf80614, conn_id = 0 DELETE IT!
VPN Peer:ISAKMP: Peer Info for LINKSYS IP/500 not found - peers:2
ISADB: reaper checking SA 0xee0c1c, conn_id = 0
Can someone help me?
Thanks
Bas van der Horst
05-16-2005 06:45 AM
ERROR: This device has recorded a Peer Info for LINKSYS IP/500 not found - peers:2 log message. This error indicates a configuration mismatch. TRY THIS: Ensure that the IP address of peer in Isakmp key keystring address peer-address PIX command is correct. Check the network connectivity to the peer on udp port 500. In the Access control list that defines interesting traffic for VPN, if the larger network is used then change the ACL to match the specific host first.
05-16-2005 11:42 PM
Hi There,
Problem is solved.
Linksys was unstable, after firmware upgrade it worked.
With regards,
Bas van der Horst
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide