03-31-2003 09:17 AM - edited 02-21-2020 12:26 PM
Hi,
Im trying to establish an ipsec vpn connection from cisco 1720 to a checkpoint firewall.Im not able to establish the conn.From the debug message i understand that the quickmode is failing.Im pasting my debug output.Can anyone help me regardign this.
1w4d: ISAKMP: received ke message (1/1)
1w4d: ISAKMP: local port 500, remote port 500
1w4d: ISAKMP (0:1): beginning Main Mode exchange
1w4d: ISAKMP (0:1): sending packet to 81.144.129.210 (I) MM_NO_STATE.....
Success rate is 0 percent (0/5)
Lainc-0014#
1w4d: ISAKMP (0:1): retransmitting phase 1 MM_NO_STATE...
1w4d: ISAKMP (0:1): incrementing error counter on sa: retransmit phase 1
1w4d: ISAKMP (0:1): retransmitting phase 1 MM_NO_STATE
1w4d: ISAKMP (0:1): sending packet to 81.144.129.210 (I) MM_NO_STATE
1w4d: ISAKMP (0:1): received packet from 81.144.129.210 (I) MM_NO_STATE
1w4d: ISAKMP (0:1): processing SA payload. message ID = 0
1w4d: ISAKMP (0:1): found peer pre-shared key matching 81.144.129.210
1w4d: ISAKMP (0:1): Checking ISAKMP transform 1 against priority 5 policy
1w4d: ISAKMP: encryption DES-CBC
1w4d: ISAKMP: hash MD5
1w4d: ISAKMP: default group 2
1w4d: ISAKMP: auth pre-share
1w4d: ISAKMP (0:1): atts are acceptable. Next payload is 0
1w4d: ISAKMP (0:1): SA is doing pre-shared key authentication using id type ID_F
QDN
1w4d: ISAKMP (0:1): sending packet to 81.144.129.210 (I) MM_SA_SETUP
1w4d: ISAKMP (0:1): received packet from 81.144.129.210 (I) MM_SA_SETUP
1w4d: ISAKMP (0:1): processing KE payload. message ID = 0
1w4d: ISAKMP (0:1): processing NONCE payload. message ID = 0
1w4d: ISAKMP (0:1): found peer pre-shared key matching 81.144.129.210
1w4d: ISAKMP (0:1): SKEYID state generated
1w4d: ISAKMP (1): ID payload
next-payload : 8
type : 2
protocol : 17
port : 500
length : 15
1w4d: ISAKMP (1): Total payload length: 19
1w4d: ISAKMP (0:1): sending packet to 81.144.129.210 (I) MM_KEY_EXCH
1w4d: ISAKMP (0:1): received packet from 81.144.129.210 (I) MM_KEY_EXCH
1w4d: ISAKMP (0:1): processing ID payload. message ID = 0
1w4d: ISAKMP (0:1): processing HASH payload. message ID = 0
1w4d: ISAKMP (0:1): SA has been authenticated with 81.144.129.210
1w4d: ISAKMP (0:1): beginning Quick Mode exchange, M-ID of 1081694018
1w4d: ISAKMP (0:1): sending packet to 81.144.129.210 (I) QM_IDLE
1w4d: ISAKMP (0:1): received packet from 81.144.129.210 (I) QM_IDLE
1w4d: ISAKMP (0:1): phase 1 packet is a duplicate of a previous packet.
1w4d: ISAKMP (0:1): retransmitting due to retransmit phase 1
1w4d: ISAKMP (0:1): retransmitting phase 1 QM_IDLE ...
1w4d: ISAKMP (0:1): received packet from 81.144.129.210 (I) QM_IDLE
1w4d: ISAKMP (0:1): phase 1 packet is a duplicate of a previous packet.
1w4d: ISAKMP (0:1): retransmitting due to retransmit phase 1
1w4d: ISAKMP (0:1): retransmitting phase 1 QM_IDLE ...
1w4d: ISAKMP (0:1): retransmitting phase 1 QM_IDLE ...
1w4d: ISAKMP (0:1): incrementing error counter on sa: retransmit phase 1
1w4d: ISAKMP (0:1): no outgoing phase 1 packet to retransmit. QM_IDLE
1w4d: ISAKMP (0:1): retransmitting phase 2 QM_IDLE 1081694018 ...
1w4d: ISAKMP (0:1): incrementing error counter on sa: retransmit phase 2
1w4d: ISAKMP (0:1): incrementing error counter on sa: retransmit phase 2
1w4d: ISAKMP (0:1): retransmitting phase 2 1081694018 QM_IDLE
1w4d: ISAKMP (0:1): sending packet to 81.144.129.210 (I) QM_IDLE
1w4d: ISAKMP: received ke message (1/1)
1w4d: ISAKMP (0:1): sitting IDLE. Starting QM immediately (QM_IDLE )
1w4d: ISAKMP (0:1): beginning Quick Mode exchange, M-ID of 1198044146
1w4d: ISAKMP (0:1): sending packet to 81.144.129.210 (I) QM_IDLE
1w4d: ISAKMP (0:0): received packet from 81.144.129.210 (N) NEW SA
1w4d: %CRYPTO-4-IKMP_NO_SA: IKE message from 81.144.129.210 has no SA and is no
t an initialization offer
1w4d: ISAKMP (0:1): retransmitting phase 2 QM_IDLE 1081694018 ...
1w4d: ISAKMP (0:1): incrementing error counter on sa: retransmit phase 2
1w4d: ISAKMP (0:1): incrementing error counter on sa: retransmit phase 2
1w4d: ISAKMP (0:1): retransmitting phase 2 1081694018 QM_IDLE
1w4d: ISAKMP (0:1): sending packet to 81.144.129.210 (I) QM_IDLE
1w4d: ISAKMP (0:1): retransmitting phase 2 QM_IDLE 1198044146 ...
1w4d: ISAKMP (0:1): deleting SA reason "death by retransmission P2" state (I) QM
_IDLE (peer 81.144.129.210) input queue 0
1w4d: ISAKMP (0:1): sending packet to 81.144.129.210 (I) MM_NO_STATE
1w4d: ISAKMP (0:1): purging node 2003855092
1w4d: ISAKMP (0:1): deleting node 1081694018 error TRUE reason "death by retrans
mission P2"
1w4d: ISAKMP (0:1): deleting node 1198044146 error TRUE reason "death by retrans
mission P2"
1w4d: ISAKMP: received ke message (3/1)
1w4d: ISAKMP: ignoring request to send delete notify (no ISAKMP sa) src 195.229.
115.65 dst 81.144.129.210 for SPI 0x0
03-31-2003 01:09 PM
Hi,
Seems like pix is proceeding with the IKE Phase II (QM), but chekpoint is still sending IKE I messages, and pix complaining that its a duplicated packet.
Try re-entering the preshared key on the two sides once more.
Thanks
Afaq
03-31-2003 06:35 PM
Thanks Afaq for replying. Im using a router with 12.5(4) instead of router.U have asked me to enter the preshared key once more.But if the preshared key is wrong it wouldnt come till this stage.In the debug message i can see a line saying that found preshared key matching.Is there any other possibiliy why this is happneing.
thanks and regards
syam
03-31-2003 02:26 PM
From these debugs the router is transmitting alot. It appears to get through phase I fine and then kill over at II. Is the ISP blocking ESP? What does the checkpoint box say? Does the checkpoint say that phase I is up or down? Does it show that it is transmitting with out any replies?
Robert Raver
03-31-2003 06:42 PM
thanks Robert for replying.
I dont think that the ISP is trying to block the ESP.
Already i have got a vpn running between two sites having the same transform through the same ISP. Somethign else is happening.Im trying to get the log output from the checkpoint firewall.Once i get the log output i would be posting it.
thanks
Syam
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide