10-08-2016 03:01 AM
Hi,
configuration to connect asa 5510 and asa 5505 double checked, ph2 proposal matching and so on ... , 3 other vpn tunnels with same configuration but different peers are ok and up for days, bot we're getting this when creating interesting traffic on the new tunnel on our side (5505) :
Group = 83.***.0.3, IP = 83.***.0.3, Automatic NAT Detection Status: Remote end is NOT behind a NAT device This end IS behind a NAT device
6|Oct 06 2016 14:05:48|113009: AAA retrieved default group policy (DfltGrpPolicy) for user = 83.***.0.3
5|Oct 06 2016 14:05:48|713119: Group = 83.***.0.3, IP = 83.***.0.3, PHASE 1 COMPLETED
5|Oct 06 2016 14:05:48|713068: Group = 83.***.0.3, IP = 83.***.0.3, Received non-routine Notify message: No proposal chosen (14)
5|Oct 06 2016 14:05:48|713050: Group = 83.***.0.3, IP = 83.***.0.3, Connection terminated for peer 83.***.0.3. Reason: Peer Terminate Remote Proxy N/A, Local Proxy N/A
1|Oct 06 2016 14:05:48|713900: Group = 83.***.0.3, IP = 83.***.0.3, construct_ipsec_delete(): No SPI to identify Phase 2 SA!
3|Oct 06 2016 14:05:48|713902: Group = 83.***.0.3, IP = 83.***.0.3, Removing peer from correlator table failed, no match!
4|Oct 06 2016 14:05:48|113019: Group = 83.***.0.3, Username = 83.***.0.3, IP = 83.***.0.3, Session disconnected. Session Type: IKE, Duration: 0h:00m:00s, Bytes xmt: 0, Bytes rcv: 0, Reason: Unknown
5|Oct 06 2016 14:05:49|713041: IP = 83.***.0.3, IKE Initiator: New Phase 1, Intf inside, IKE Peer 83.***.0.3 local Proxy Address 10.***.10.2, remote Proxy Address 10.***.17.17, Crypto map (outside_map)
6|Oct 06 2016 14:05:49|713172: Group = 83.***.0.3, IP = 83.***.0.3, Automatic NAT Detection Status: Remote end is NOT behind a NAT device This end IS behind a NAT device
6|Oct 06 2016 14:05:49|113009: AAA retrieved default group policy (DfltGrpPolicy) for user = 83.***.0.3
any good fellow had seen and solved this case? what's going on ?
thanks.
10-08-2016 08:37 AM
Hi skander,
Can you share the tunnel configuration of both ends, this looks just like a configuration mismatch or just something wrong configured:
5|Oct 06 2016 14:05:48|713068: Group = 83.***.0.3, IP = 83.***.0.3, Received non-routine Notify message: No proposal chosen (14)
Hope this info helps!!
Rate if helps you!!
-JP-
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide