cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
453
Views
0
Helpful
1
Replies

ISAKMP problem between ASA and 1751 router

s_colombo
Level 1
Level 1

I'm trying to set up a VPN between anASA 5505 and a Cisco 1751 router.

So far we're having problem witha ISAKMP which cannot establish SA .

On the 1751 router I can find the following error

Mar  9 01:18:38.804: ISAKMP (0:103): incrementing error counter on sa: reset_retransmission

Mar  9 01:18:39.804: ISAKMP (0:103): retransmitting phase 1 MM_KEY_EXCH...

Mar  9 01:18:39.804: ISAKMP (0:103): incrementing error counter on sa: retransmit phase 1

Mar  9 01:18:39.804: ISAKMP (0:103): retransmitting phase 1 MM_KEY_EXCH

Mar  9 01:18:39.804: ISAKMP (0:103): sending packet to 213.217.163.199 (R) MM_KEY_EXCH

Mar  9 01:18:39.836: ISAKMP (0:103): received packet from 213.217.163.199 (R) MM_KEY_EXCH

Mar  9 01:18:39.840: %CRYPTO-6-IKMP_NOT_ENCRYPTED: IKE packet from 213.217.163.199 was not encrypted and it should've been.

Mar  9 01:19:06.716: ISAKMP (0:104): vendor ID seems Unity/DPD but bad major

Mar  9 01:19:06.716: ISAKMP (0:104): vendor ID is XAUTH

Mar  9 01:19:06.716: ISAKMP (0:104): processing vendor id payload

Mar  9 01:19:06.716: ISAKMP (0:104): speaking to another IOS box!

Mar  9 01:19:06.716: ISAKMP (0:104): processing vendor id payload

Mar  9 01:19:06.716: ISAKMP (0:104:): vendor ID seems Unity/DPD but bad hash

Mar  9 01:19:06.720: ISAKMP (0:104): Input = IKE_MESG_INTERNAL, IKE_PROCESS_MAIN_MODE

Mar  9 01:19:06.720: ISAKMP (0:104): Old State = IKE_R_MM3  New State = IKE_R_MM3

Mar  9 01:19:06.720: ISAKMP (0:104): sending packet to 213.217.163.199 (R) MM_KEY_EXCHL, IKE_PHASE1_DEL

Mar  9 01:18:40.840: ISAKMP (0:103): Old State = IKE_R_MM4  New State = IKE_DEST_SA

1 Reply 1

s_colombo
Level 1
Level 1

found a solution

closed thread