12-16-2004 01:31 AM - edited 02-21-2020 01:30 PM
Hello,
I'm currently having problem with pix506e vpn, the pix running fine yesterday, but today morning the problem appears, the pix doesn't allowed more that 2 vpn client connections, if user A connected, User B will disconnect, meanwhile..if user B connected, User A will disconnect, i've write erase the config and rebuild again with the basic one, but still the problem occurs, what could be the problem, software or...hardware?here i attach my config start from basic, and vpn client logging.
Our network is down now..please help.
118 17:07:12.460 12/16/04 Sev=Info/6 IKE/0x6300003D
Sending DPD request to 218.xxx.xxx.161, seq# = 1257657895
119 17:07:12.460 12/16/04 Sev=Info/4 IKE/0x63000013
SENDING >>> ISAKMP OAK INFO *(HASH, NOTIFY:DPD_REQUEST) to 218.xxx.xxx.161
120 17:07:17.468 12/16/04 Sev=Info/6 IKE/0x6300003D
Sending DPD request to 218.xxx.xxx.161, seq# = 1257657896
121 17:07:17.468 12/16/04 Sev=Info/4 IKE/0x63000013
SENDING >>> ISAKMP OAK INFO *(HASH, NOTIFY:DPD_REQUEST) to 218.xxx.xxx.161
122 17:07:22.475 12/16/04 Sev=Info/4 IKE/0x63000013
SENDING >>> ISAKMP OAK INFO *(HASH, DEL) to 218.xxx.xxx.161
123 17:07:22.475 12/16/04 Sev=Info/5 IKE/0x63000018
Deleting IPsec SA: (OUTBOUND SPI = 695320B5 INBOUND SPI = F0A2471)
124 17:07:22.475 12/16/04 Sev=Info/4 IKE/0x63000048
Discarding IPsec SA negotiation, MsgID=7A8F1E11
125 17:07:22.475 12/16/04 Sev=Info/4 IKE/0x63000017
Marking IKE SA for deletion (I_Cookie=BAF3D743B1D25DD6 R_Cookie=ED5BAEF920BA3244) reason = DEL_REASON_PEER_NOT_RESPONDING
126 17:07:22.475 12/16/04 Sev=Info/4 IKE/0x63000013
SENDING >>> ISAKMP OAK INFO *(HASH, DEL) to 218.xxx.xxx.161
127 17:07:22.475 12/16/04 Sev=Info/4 IPSEC/0x63700013
Delete internal key with SPI=0x71240a0f
128 17:07:22.475 12/16/04 Sev=Info/4 IPSEC/0x6370000C
Key deleted by SPI 0x71240a0f
129 17:07:22.475 12/16/04 Sev=Info/4 IPSEC/0x63700013
Delete internal key with SPI=0xb5205369
130 17:07:22.475 12/16/04 Sev=Info/4 IPSEC/0x6370000C
Key deleted by SPI 0xb5205369
131 17:07:22.986 12/16/04 Sev=Info/4 IKE/0x6300004A
Discarding IKE SA negotiation (I_Cookie=BAF3D743B1D25DD6 R_Cookie=ED5BAEF920BA3244) reason = DEL_REASON_PEER_NOT_RESPONDING
132 17:07:22.986 12/16/04 Sev=Info/4 CM/0x63100013
Phase 1 SA deleted cause by DEL_REASON_PEER_NOT_RESPONDING. 0 Phase 1 SA currently in the system
133 17:07:22.996 12/16/04 Sev=Info/5 CM/0x63100025
Initializing CVPNDrv
134 17:07:23.106 12/16/04 Sev=Info/6 CM/0x63100031
Tunnel to headend device 218.xxx.xxx.161 disconnected: duration: 0 days 0:16:44
135 17:07:23.286 12/16/04 Sev=Info/4 IKE/0x63000001
IKE received signal to terminate VPN connection
138 17:07:23.316 12/16/04 Sev=Info/6 CM/0x63100037
The routing table was returned to orginal state prior to Virtual Adapter
139 17:07:25.649 12/16/04 Sev=Info/4 CM/0x63100035
The Virtual Adapter was disabled
140 17:07:25.699 12/16/04 Sev=Info/4 IKE/0x63000085
Microsoft IPSec Policy Agent service started successfully
141 17:07:25.699 12/16/04 Sev=Info/4 IPSEC/0x63700014
Deleted all keys
142 17:07:25.699 12/16/04 Sev=Info/4 IPSEC/0x63700014
Deleted all keys
143 17:07:25.699 12/16/04 Sev=Info/4 IPSEC/0x63700014
Deleted all keys
144 17:07:25.699 12/16/04 Sev=Info/4 IPSEC/0x6370000A
IPSec driver successfully stopped
thanks
Tonny
Solved! Go to Solution.
12-16-2004 12:07 PM
12-16-2004 12:07 PM
Enter the following command in your PIX:
isakmp nat-traversal
12-16-2004 06:10 PM
Hello man...
thanks for your help, i've never realized that the solution is just only one CLI command, sometimes the hardest is just the easiest, a trillion gigabyte thanks to you.
don't worry be happy ;)
Tonny
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide