cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
336
Views
0
Helpful
2
Replies

Connecting vpn with Pix 506 & Linksys BEFSX41

michael
Level 1
Level 1

Hi There,

I`m trying to create a vpn between a Pix and a linsys firewall. I don`t know what`s wrong but even fase 1 is`nt working, I`v tried des/md5, 3des/sha des/sha but nothing is working. Please see debug from crypto isakmp:

crypto_isakmp_process_block:src:LINKSYS IP, dest:PIX IP spt:500 dpt:500

OAK_AG exchange

ISAKMP (0): processing SA payload. message ID = 0

ISAKMP (0): Checking ISAKMP transform 1 against priority 21 policy

ISAKMP: encryption DES-CBC

ISAKMP: hash MD5

ISAKMP: auth pre-share

ISAKMP: default group 1

ISAKMP: life type in seconds

ISAKMP: life duration (VPI) of 0x0 0x1 0x51 0x80

ISAKMP (0): atts are acceptable. Next payload is 3

ISAKMP (0): processing KE payload. message ID = 0

ISAKMP (0): processing NONCE payload. message ID = 0

ISAKMP (0): processing ID payload. message ID = 0

ISAKMP (0): ID payload

next-payload : 10

type : 1

protocol : 17

port : 500

length : 8

ISAKMP (0): Total payload length: 12

return status is IKMP_NO_ERRORdebug cr

ISAKMP (0): retransmitting phase 1 (0)...ypto ipsec

PIX#

ISADB: reaper checking SA 0xee0c1c, conn_id = 0

ISADB: reaper checking SA 0xf72984, conn_id = 0

ISADB: reaper checking SA 0xf80614, conn_id = 0

ISAKMP (0): retransmitting phase 1 (1)...

ISAKMP (0): deleting SA: src LINKSYS IP, dst PIX IP

ISADB: reaper checking SA 0xee0c1c, conn_id = 0

ISADB: reaper checking SA 0xf72984, conn_id = 0

ISADB: reaper checking SA 0xf80614, conn_id = 0 DELETE IT!

VPN Peer:ISAKMP: Peer Info for LINKSYS IP/500 not found - peers:2

ISADB: reaper checking SA 0xee0c1c, conn_id = 0

Can someone help me?

Thanks

Bas van der Horst

2 Replies 2

umedryk
Level 5
Level 5

ERROR: This device has recorded a Peer Info for LINKSYS IP/500 not found - peers:2 log message. This error indicates a configuration mismatch. TRY THIS: Ensure that the IP address of peer in Isakmp key keystring address peer-address PIX command is correct. Check the network connectivity to the peer on udp port 500. In the Access control list that defines interesting traffic for VPN, if the larger network is used then change the ACL to match the specific host first.

Hi There,

Problem is solved.

Linksys was unstable, after firmware upgrade it worked.

With regards,

Bas van der Horst