cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
532
Views
0
Helpful
1
Replies

please help me

ccvp_cicso
Level 1
Level 1

VPN setup this my log

gmcauh#ping 10.1.1.1 source 10.1.3.1 repeat 100

Type escape sequence to abort.

Sending 100, 100-byte ICMP Echos to 10.1.1.1, timeout is 2 seconds:

Packet sent with a source address of 10.1.3.1

005081: Oct  1 05:23:00.704: IPSEC: Peer gmcdxb.zapto.org's addr (2.50.6.200) is stale, triggering DNS

005082: Oct  1 05:23:00.704: IPSEC: Peer has the (DNS cached) address 2.50.6.200..

005083: Oct  1 05:23:05.512: IPSEC(key_engine): request timer fired: count = 1,

  (identity) local= 129.151.111.254:0, remote= 129.104.255.108:0,

    local_proxy= 10.1.3.0/255.255.255.0/0/0 (type=4),

    remote_proxy= 10.1.1.0/255.255.255.0/0/0 (type=4)

005084: Oct  1 05:23:05.512: IPSEC(sa_request): ,

  (key eng. msg.) OUTBOUND local= 129.151.111.254:500, remote= 129.104.255.108:500,

    local_proxy= 10.1.3.0/255.255.255.0/0/0 (type=4),

    remote_proxy= 10.1.1.0/255.255.255.0/0/0 (type=4),

    protocol= ESP, transform= esp-3des esp-md5-hmac  (Tunnel),

    lifedur= 3600s and 460800kb,

    spi= 0x0(0), conn_id= 0, keysize= 0, flags= 0x0

005085: Oct  1 05:23:05.512: ISAKMP:(0): SA request profile is (NULL)

005086: Oct  1 05:23:05.512: ISAKMP: Created a peer struct for , peer port 500

005087: Oct  1 05:23:05.512: ISAKMP: New peer created peer = 0x88F85518 peer_handle = 0x80000101

005088: Oct  1 05:23:05.512: ISAKMP: Locking peer struct 0x88F85518, refcount 1 for isakmp_initiator

005089: Oct  1 05:23:05.512: ISAKMP: local port 500, remote port 500

005090: Oct  1 05:23:05.512: ISAKMP: set new node 0 to QM_IDLE     

005091: Oct  1 05:23:05.512: ISAKMP:(0):insert sa successfully sa = 8ADD2884

005092: Oct  1 05:23:05.512: ISAKMP:(0):Can not start Aggressive mode, trying Main mode.

005093: Oct  1 05:23:05.512: ISAKMP:(0):No pre-shared key with !

005094: Oct  1 05:23:05.512: ISAKMP:(0): No Cert or pre-shared address key.

005095: Oct  1 05:23:05.512: ISAKMP:(0): construct_initial_message: Can not start Main mode

005096: Oct  1 05:23:05.512: ISAKMP: Unlocking peer struct 0x88F85518 for isadb_unlock_peer_delete_sa(), count 0

005097: Oct  1 05:23:05.512: ISAKMP: Deleting peer node by peer_reap for : 88F85518

005098: Oct  1 05:23:05.512: ISAKMP:(0):purging SA., sa=8ADD2884, delme=8ADD2884

005099: Oct  1 05:23:05.512: ISAKMP:(0):purging node -1655831586

005100: Oct  1 05:23:05.512: ISAKMP: Error while processing SA request: Failed to initialize SA.

005101: Oct  1 05:23:05.512: ISAKMP: Error while processing KMI message 0, error 2.

005102: Oct  1 05:23:05.512: IPSEC(key_engine): got a queue event with 1 KMI message(s)..............

005103: Oct  1 05:23:35.512: IPSEC(key_engine): request timer fired: count = 2,

  (identity) local= 129.151.111.254:0, remote= 129.104.255.108:0,

    local_proxy= 10.1.3.0/255.255.255.0/0/0 (type=4),

    remote_proxy= 10.1.1.0/255.255.255.0/0/0 (type=4).

005104: Oct  1 05:23:36.704: IPSEC(sa_request): ,

  (key eng. msg.) OUTBOUND local= 129.151.111.254:500, remote= 129.104.255.108:500,

    local_proxy= 10.1.3.0/255.255.255.0/0/0 (type=4),

    remote_proxy= 10.1.1.0/255.255.255.0/0/0 (type=4),

    protocol= ESP, transform= esp-3des esp-md5-hmac  (Tunnel),

    lifedur= 3600s and 460800kb,

    spi= 0x0(0), conn_id= 0, keysize= 0, flags= 0x0

005105: Oct  1 05:23:36.704: ISAKMP:(0): SA request profile is (NULL)

005106: Oct  1 05:23:36.704: ISAKMP: Created a peer struct for , peer port 500

005107: Oct  1 05:23:36.704: ISAKMP: New peer created peer = 0x8ADD3C64 peer_handle = 0x80000102

005108: Oct  1 05:23:36.704: ISAKMP: Locking peer struct 0x8ADD3C64, refcount 1 for isakmp_initiator

005109: Oct  1 05:23:36.704: ISAKMP: local port 500, remote port 500

005110: Oct  1 05:23:36.704: ISAKMP: set new node 0 to QM_IDLE     

005111: Oct  1 05:23:36.704: ISAKMP:(0):insert sa successfully sa = 86699FD8

005112: Oct  1 05:23:36.704: ISAKMP:(0):Can not start Aggressive mode, trying Main mode.

005113: Oct  1 05:23:36.704: ISAKMP:(0):No pre-shared key with !

005114: Oct  1 05:23:36.704: ISAKMP:(0): No Cert or pre-shared address key.

005115: Oct  1 05:23:36.704: ISAKMP:(0): construct_initial_message: Can not start Main mode.

005116: Oct  1 05:23:36.704: ISAKMP: Unlocking peer struct 0x8ADD3C64 for isadb_unlock_peer_delete_sa(), count 0

005117: Oct  1 05:23:36.704: ISAKMP: Deleting peer node by peer_reap for : 8ADD3C64

005118: Oct  1 05:23:36.708: ISAKMP:(0):purging SA., sa=86699FD8, delme=86699FD8

005119: Oct  1 05:23:36.708: ISAKMP:(0):purging node -310028337

005120: Oct  1 05:23:36.708: ISAKMP: Error while processing SA request: Failed to initialize SA

005121: Oct  1 05:23:36.708: ISAKMP: Error while processing KMI message 0, error 2.

005122: Oct  1 05:23:36.708: IPSEC(key_engine): got a queue event with 1 KMI message(s).

005123: Oct  1 05:23:40.704: IPSEC: Peer gmcdxb.zapto.org's addr (2.50.6.200) is stale, triggering DNS

005124: Oct  1 05:23:41.088: IPSEC: Peer gmcdxb.zapto.org has been DNS resolved to 2.50.6.200, expires in 00:00:40...

1 Reply 1

andrew.prince
Level 10
Level 10

Your issue is here>

005093: Oct  1 05:23:05.512: ISAKMP:(0):No pre-shared key with !

&

005113: Oct  1 05:23:36.704: ISAKMP:(0):No pre-shared key with !

Your configuration is missing a pre-shared key, re-configure and test again.