cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
234
Views
5
Helpful
1
Replies

connectivity problem ASA55--

skander
Level 1
Level 1

Hi,

 configuration to connect asa 5510 and asa 5505 double checked, ph2 proposal matching and so on ... , 3 other vpn tunnels with same configuration but different peers are  ok and up for days,  bot we're getting this when creating interesting traffic on the new tunnel on our side (5505) :

Group = 83.***.0.3, IP = 83.***.0.3, Automatic NAT Detection Status:     Remote end is NOT behind a NAT device     This   end   IS   behind a NAT device
6|Oct 06 2016 14:05:48|113009: AAA retrieved default group policy (DfltGrpPolicy) for user = 83.***.0.3
5|Oct 06 2016 14:05:48|713119: Group = 83.***.0.3, IP = 83.***.0.3, PHASE 1 COMPLETED
5|Oct 06 2016 14:05:48|713068: Group = 83.***.0.3, IP = 83.***.0.3, Received non-routine Notify message: No proposal chosen (14)
5|Oct 06 2016 14:05:48|713050: Group = 83.***.0.3, IP = 83.***.0.3, Connection terminated for peer 83.***.0.3.  Reason: Peer Terminate  Remote Proxy N/A, Local Proxy N/A
1|Oct 06 2016 14:05:48|713900: Group = 83.***.0.3, IP = 83.***.0.3, construct_ipsec_delete(): No SPI to identify Phase 2 SA!
3|Oct 06 2016 14:05:48|713902: Group = 83.***.0.3, IP = 83.***.0.3, Removing peer from correlator table failed, no match!
4|Oct 06 2016 14:05:48|113019: Group = 83.***.0.3, Username = 83.***.0.3, IP = 83.***.0.3, Session disconnected. Session Type: IKE, Duration: 0h:00m:00s, Bytes xmt: 0, Bytes rcv: 0, Reason: Unknown
5|Oct 06 2016 14:05:49|713041: IP = 83.***.0.3, IKE Initiator: New Phase 1, Intf inside, IKE Peer 83.***.0.3  local Proxy Address 10.***.10.2, remote Proxy Address 10.***.17.17,  Crypto map (outside_map)
6|Oct 06 2016 14:05:49|713172: Group = 83.***.0.3, IP = 83.***.0.3, Automatic NAT Detection Status:     Remote end is NOT behind a NAT device     This   end   IS   behind a NAT device
6|Oct 06 2016 14:05:49|113009: AAA retrieved default group policy (DfltGrpPolicy) for user = 83.***.0.3

any good fellow had seen and solved this case? what's going on ?

thanks.

1 Reply 1

JP Miranda Z
Cisco Employee
Cisco Employee

Hi skander,

Can you share the tunnel configuration of both ends, this looks just like a configuration mismatch or just something wrong configured:

5|Oct 06 2016 14:05:48|713068: Group = 83.***.0.3, IP = 83.***.0.3, Received non-routine Notify message: No proposal chosen (14)

Hope this info helps!!

Rate if helps you!! 

-JP-