07-17-2007 11:01 PM - edited 02-21-2020 03:09 PM
Please help.
When I do a 'show crypto isakmp sa' on asa5510 ver 7.2(1) for a L2L ipsec tunnel, this is the message it gives me. Pls explain what it means.
I have also attached the debug messages, please expalin what that means.
07-18-2007 11:55 AM
Hi
The sh cry isa sa output with MM_ACTIVE indicates that the main mode is in active state i.e phase 1 is up.
The debugs are indicating that it failing at Quick Mode (QM) or phase2. You would need to get the isa as well as ipsec debugs on both ends to find why it is failing at phase 2.
Thanks
07-18-2007 05:16 PM
07-19-2007 12:58 PM
Hi
Looks like the debug was taken from the buffer and hence incomplete and not really helpful. Is it possible to capture the debugs on the console or monitor session and log the entire debugs , right from the time, the tunnel is starting to come up.
Thanks
07-19-2007 03:09 PM
if I accessing the ASA from remote telnet rather than directly connected to the Console how can I capture debugs from a session monitor? How do I do a monitor session?
07-18-2007 08:52 PM
please explain the debug information I attached. This from the asa5510 ver 7.2(1)
I need help urgently, pls.
07-19-2007 02:42 PM
This is a long shoot since the debugs are incomplete. Check whether both side are setup to do PFS (Perfect forward secrecy). You will find it under the crypto map statements on the ASA.
07-19-2007 03:12 PM
Both Firewalls are set to do pfs group 2.
What next?
07-19-2007 04:12 PM
Get the complete debugs, since we don't have the configurations set the level of debugs to 255.
07-23-2007 06:33 PM
Hi
I set the level of debugs on the asa to 255 for cryto ipsakmp & crypto ipsec.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide