12-17-2014 06:54 AM - edited 02-21-2020 07:59 PM
Hi all,
We have a tunnel IPSec that not work. I think that Phase 2 is not established but i don't know why.
Add output and log.
Thanks for your help
ASA-VPN-PRI/act/pri# sh crypto isakmp sa
!
13 IKE Peer: 91.209.243.5
Type : L2L Role : responder
Rekey : no State : MM_ACTIVE
!
ASA-VPN-PRI/act/pri# sh crypto isakmp sa | include 91.209.243.5
12 IKE Peer: 91.209.243.5
ASA-VPN-PRI/act/pri#
ASA-VPN-PRI/act/pri# sh crypto ipsec sa | include 91.209.243.5
ASA-VPN-PRI/act/pri#
7|Dec 17 2014|15:40:48|713236|||||IP = 91.209.243.5, IKE_DECODE SENDING Message (msgid=c516994b) with payloads : HDR + HASH (8) + NOTIFY (11) + NONE (0) total length : 84
7|Dec 17 2014|15:40:48|715046|||||Group = 91.209.243.5, IP = 91.209.243.5, constructing qm hash payload
7|Dec 17 2014|15:40:48|715046|||||Group = 91.209.243.5, IP = 91.209.243.5, constructing blank hash payload
7|Dec 17 2014|15:40:48|715036|||||Group = 91.209.243.5, IP = 91.209.243.5, Sending keep-alive of type DPD R-U-THERE-ACK (seq number 0x7d6c)
7|Dec 17 2014|15:40:48|715075|||||Group = 91.209.243.5, IP = 91.209.243.5, Received keep-alive of type DPD R-U-THERE (seq number 0x7d6c)
7|Dec 17 2014|15:40:48|715047|||||Group = 91.209.243.5, IP = 91.209.243.5, processing notify payload
7|Dec 17 2014|15:40:48|715047|||||Group = 91.209.243.5, IP = 91.209.243.5, processing hash payload
7|Dec 17 2014|15:40:48|713236|||||IP = 91.209.243.5, IKE_DECODE RECEIVED Message (msgid=29bf4142) with payloads : HDR + HASH (8) + NOTIFY (11) + NONE (0) total length : 84
7|Dec 17 2014|15:40:43|713236|||||IP = 91.209.243.5, IKE_DECODE SENDING Message (msgid=b72ddf0a) with payloads : HDR + HASH (8) + NOTIFY (11) + NONE (0) total length : 84
7|Dec 17 2014|15:40:43|715046|||||Group = 91.209.243.5, IP = 91.209.243.5, constructing qm hash payload
7|Dec 17 2014|15:40:43|715046|||||Group = 91.209.243.5, IP = 91.209.243.5, constructing blank hash payload
7|Dec 17 2014|15:40:43|715036|||||Group = 91.209.243.5, IP = 91.209.243.5, Sending keep-alive of type DPD R-U-THERE-ACK (seq number 0x7d6b)
7|Dec 17 2014|15:40:43|715075|||||Group = 91.209.243.5, IP = 91.209.243.5, Received keep-alive of type DPD R-U-THERE (seq number 0x7d6b)
7|Dec 17 2014|15:40:43|715047|||||Group = 91.209.243.5, IP = 91.209.243.5, processing notify payload
7|Dec 17 2014|15:40:43|715047|||||Group = 91.209.243.5, IP = 91.209.243.5, processing hash payload
7|Dec 17 2014|15:40:43|713236|||||IP = 91.209.243.5, IKE_DECODE RECEIVED Message (msgid=ae5305df) with payloads : HDR + HASH (8) + NOTIFY (11) + NONE (0) total length : 84
7|Dec 17 2014|15:40:38|713236|||||IP = 91.209.243.5, IKE_DECODE SENDING Message (msgid=b796798d) with payloads : HDR + HASH (8) + NOTIFY (11) + NONE (0) total length : 84
7|Dec 17 2014|15:40:38|715046|||||Group = 91.209.243.5, IP = 91.209.243.5, constructing qm hash payload
7|Dec 17 2014|15:40:38|715046|||||Group = 91.209.243.5, IP = 91.209.243.5, constructing blank hash payload
7|Dec 17 2014|15:40:38|715036|||||Group = 91.209.243.5, IP = 91.209.243.5, Sending keep-alive of type DPD R-U-THERE-ACK (seq number 0x7d6a)
7|Dec 17 2014|15:40:38|715075|||||Group = 91.209.243.5, IP = 91.209.243.5, Received keep-alive of type DPD R-U-THERE (seq number 0x7d6a)
7|Dec 17 2014|15:40:38|715047|||||Group = 91.209.243.5, IP = 91.209.243.5, processing notify payload
7|Dec 17 2014|15:40:38|715047|||||Group = 91.209.243.5, IP = 91.209.243.5, processing hash payload
7|Dec 17 2014|15:40:38|713236|||||IP = 91.209.243.5, IKE_DECODE RECEIVED Message (msgid=98241c63) with payloads : HDR + HASH (8) + NOTIFY (11) + NONE (0) total length : 84
7|Dec 17 2014|15:40:33|713236|||||IP = 91.209.243.5, IKE_DECODE SENDING Message (msgid=e233621d) with payloads : HDR + HASH (8) + NOTIFY (11) + NONE (0) total length : 84
7|Dec 17 2014|15:40:33|715046|||||Group = 91.209.243.5, IP = 91.209.243.5, constructing qm hash payload
7|Dec 17 2014|15:40:33|715046|||||Group = 91.209.243.5, IP = 91.209.243.5, constructing blank hash payload
7|Dec 17 2014|15:40:33|715036|||||Group = 91.209.243.5, IP = 91.209.243.5, Sending keep-alive of type DPD R-U-THERE-ACK (seq number 0x7d69)
7|Dec 17 2014|15:40:33|715075|||||Group = 91.209.243.5, IP = 91.209.243.5, Received keep-alive of type DPD R-U-THERE (seq number 0x7d69)
7|Dec 17 2014|15:40:33|715047|||||Group = 91.209.243.5, IP = 91.209.243.5, processing notify payload
7|Dec 17 2014|15:40:33|715047|||||Group = 91.209.243.5, IP = 91.209.243.5, processing hash payload
7|Dec 17 2014|15:40:33|713236|||||IP = 91.209.243.5, IKE_DECODE RECEIVED Message (msgid=36ecdf6a) with payloads : HDR + HASH (8) + NOTIFY (11) + NONE (0) total length : 84
7|Dec 17 2014|15:40:28|713236|||||IP = 91.209.243.5, IKE_DECODE SENDING Message (msgid=cb1b978d) with payloads : HDR + HASH (8) + NOTIFY (11) + NONE (0) total length : 84
7|Dec 17 2014|15:40:28|715046|||||Group = 91.209.243.5, IP = 91.209.243.5, constructing qm hash payload
7|Dec 17 2014|15:40:28|715046|||||Group = 91.209.243.5, IP = 91.209.243.5, constructing blank hash payload
7|Dec 17 2014|15:40:28|715036|||||Group = 91.209.243.5, IP = 91.209.243.5, Sending keep-alive of type DPD R-U-THERE-ACK (seq number 0x7d68)
7|Dec 17 2014|15:40:28|715075|||||Group = 91.209.243.5, IP = 91.209.243.5, Received keep-alive of type DPD R-U-THERE (seq number 0x7d68)
7|Dec 17 2014|15:40:28|715047|||||Group = 91.209.243.5, IP = 91.209.243.5, processing notify payload
7|Dec 17 2014|15:40:28|715047|||||Group = 91.209.243.5, IP = 91.209.243.5, processing hash payload
7|Dec 17 2014|15:40:28|713236|||||IP = 91.209.243.5, IKE_DECODE RECEIVED Message (msgid=f25bcdb5) with payloads : HDR + HASH (8) + NOTIFY (11) + NONE (0) total length : 84
7|Dec 17 2014|15:40:23|713236|||||IP = 91.209.243.5, IKE_DECODE SENDING Message (msgid=32bca075) with payloads : HDR + HASH (8) + NOTIFY (11) + NONE (0) total length : 84
7|Dec 17 2014|15:40:23|715046|||||Group = 91.209.243.5, IP = 91.209.243.5, constructing qm hash payload
7|Dec 17 2014|15:40:23|715046|||||Group = 91.209.243.5, IP = 91.209.243.5, constructing blank hash payload
7|Dec 17 2014|15:40:23|715036|||||Group = 91.209.243.5, IP = 91.209.243.5, Sending keep-alive of type DPD R-U-THERE-ACK (seq number 0x7d67)
7|Dec 17 2014|15:40:23|715075|||||Group = 91.209.243.5, IP = 91.209.243.5, Received keep-alive of type DPD R-U-THERE (seq number 0x7d67)
7|Dec 17 2014|15:40:23|715047|||||Group = 91.209.243.5, IP = 91.209.243.5, processing notify payload
7|Dec 17 2014|15:40:23|715047|||||Group = 91.209.243.5, IP = 91.209.243.5, processing hash payload
7|Dec 17 2014|15:40:23|713236|||||IP = 91.209.243.5, IKE_DECODE RECEIVED Message (msgid=a3f0e3f9) with payloads : HDR + HASH (8) + NOTIFY (11) + NONE (0) total length : 84
Solved! Go to Solution.
12-17-2014 08:27 AM
Please repeat the debug with "debug crypto isakmp 100". And compare the Phase-2 config of both sides:
12-17-2014 08:27 AM
Please repeat the debug with "debug crypto isakmp 100". And compare the Phase-2 config of both sides:
12-17-2014 11:31 PM
Hi Karsten,
I'll check it. Thanks for your help
Best regards
12-17-2014 11:37 PM
ASA-VPN-PRI/act/pri# debug crypto isakmp 100
ASA-VPN-PRI/act/pri# Dec 18 08:28:23 [IKEv1]: IP = 201.151.149.170, IKE_DECODE RECEIVED Message (msgid=b316f003) with payloads : HDR + HASH (8) + NOTIFY (11) + NONE (0) total length : 84
Dec 18 08:28:23 [IKEv1 DEBUG]: Group = 201.151.149.170, IP = 201.151.149.170, processing hash payload
Dec 18 08:28:23 [IKEv1 DEBUG]: Group = 201.151.149.170, IP = 201.151.149.170, processing notify payload
Dec 18 08:28:23 [IKEv1 DEBUG]: Group = 201.151.149.170, IP = 201.151.149.170, Received keep-alive of type DPD R-U-THERE (seq number 0x25aa4a4a)
Dec 18 08:28:23 [IKEv1 DEBUG]: Group = 201.151.149.170, IP = 201.151.149.170, Sending keep-alive of type DPD R-U-THERE-ACK (seq number 0x25aa4a4a)
Dec 18 08:28:23 [IKEv1 DEBUG]: Group = 201.151.149.170, IP = 201.151.149.170, constructing blank hash payload
Dec 18 08:28:23 [IKEv1 DEBUG]: Group = 201.151.149.170, IP = 201.151.149.170, constructing qm hash payload
Dec 18 08:28:23 [IKEv1]: IP = 201.151.149.170, IKE_DECODE SENDING Message (msgid=ec8ccf3d) with payloads : HDR + HASH (8) + NOTIFY (11) + NONE (0) total length : 84
Dec 18 08:28:23 [IKEv1 DEBUG]: Pitcher: received a key acquire message, spi 0x0
Dec 18 08:28:23 [IKEv1]: IP = 154.126.209.18, Queuing KEY-ACQUIRE messages to be processed when P1 SA is complete.
Dec 18 08:28:23 [IKEv1]: IP = 91.209.243.5, IKE_DECODE RECEIVED Message (msgid=e4e5a591) with payloads : HDR + HASH (8) + NOTIFY (11) + NONE (0) total length : 84
Dec 18 08:28:23 [IKEv1 DEBUG]: Group = 91.209.243.5, IP = 91.209.243.5, processing hash payload
Dec 18 08:28:23 [IKEv1 DEBUG]: Group = 91.209.243.5, IP = 91.209.243.5, processing notify payload
Dec 18 08:28:23 [IKEv1 DEBUG]: Group = 91.209.243.5, IP = 91.209.243.5, Received keep-alive of type DPD R-U-THERE (seq number 0xac81)
Dec 18 08:28:23 [IKEv1 DEBUG]: Group = 91.209.243.5, IP = 91.209.243.5, Sending keep-alive of type DPD R-U-THERE-ACK (seq number 0xac81)
Dec 18 08:28:23 [IKEv1 DEBUG]: Group = 91.209.243.5, IP = 91.209.243.5, constructing blank hash payload
Dec 18 08:28:23 [IKEv1 DEBUG]: Group = 91.209.243.5, IP = 91.209.243.5, constructing qm hash payload
Dec 18 08:28:23 [IKEv1]: IP = 91.209.243.5, IKE_DECODE SENDING Message (msgid=46b0c248) with payloads : HDR + HASH (8) + NOTIFY (11) + NONE (0) total length : 84
Dec 18 08:28:25 [IKEv1]: IP = 154.126.209.17, Header invalid, missing SA payload! (next payload = 4)
12-17-2014 11:47 PM
Can you also debug on the other side? And which versions are you running?
12-18-2014 12:01 AM
Hi Karsten,
this is our version:
ASA-VPN-PRI/act/pri# sh ver
Cisco Adaptive Security Appliance Software Version 8.0(5)9
Device Manager Version 6.2(5)
Compiled on Mon 01-Feb-10 10:36 by builders
System image file is "disk0:/asa805-9-k8.bin"
I am trying to contact a technician on the other side to get their settings and logs.
I hope to receive the information soon and I'll add here.
Thanks for your help
12-18-2014 08:31 AM
Hi Karsten , you were right. It was a mismatch on the transform-set but ASDM not give the correct information.
Thanks a lot
Best regards
12-18-2014 08:35 AM
Thats a problem that exists in many ASDM-versions. Its best to have a crypto ACL with only one line. If there are multiple networks on the remote or local side, then these networks should be put into object-groups. That way, the ASDM typically can display everything correctly.
01-17-2019 04:02 AM
Hello sir,
Can I know what below logs are telling ?
Because there was server which was hosted in our environment but the VPN tunnel went down when I check the logs I see below lines.
When the tunnel was down I see below logs:
Jan 17 2019 06:16:08 ISS-365-ASA-ptp-VPN-1 : %ASA-7-715036: Group = 184.94.160.170, IP = 184.94.160.170, Sending keep-alive of type DPD R-U-THERE (seq number 0x1a96fc07)
Jan 17 2019 06:16:08 ISS-365-ASA-ptp-VPN-1 : %ASA-7-715046: Group = 184.94.160.170, IP = 184.94.160.170, constructing blank hash payload
Jan 17 2019 06:16:08 ISS-365-ASA-ptp-VPN-1 : %ASA-7-715046: Group = 184.94.160.170, IP = 184.94.160.170, constructing qm hash payload
Jan 17 2019 06:16:08 ISS-365-ASA-ptp-VPN-1 : %ASA-7-713236: IP = 184.94.160.170, IKE_DECODE SENDING Message (msgid=1f8cea53) with payloads : HDR + HASH (8) + NOTIFY (11) + NONE (0) total length : 84
Once the tunnel was up I see below logs unfortunately, I didn't see any difference between those two.
Jan 17 2019 06:16:28 ISS-365-ASA-ptp-VPN-1 : %ASA-7-715036: Group = 184.94.160.170, IP = 184.94.160.170, Sending keep-alive of type DPD R-U-THERE (seq number 0x1a96fc09)
Jan 17 2019 06:16:28 ISS-365-ASA-ptp-VPN-1 : %ASA-7-715046: Group = 184.94.160.170, IP = 184.94.160.170, constructing blank hash payload
Jan 17 2019 06:16:28 ISS-365-ASA-ptp-VPN-1 : %ASA-7-715046: Group = 184.94.160.170, IP = 184.94.160.170, constructing qm hash payload
Jan 17 2019 06:16:28 ISS-365-ASA-ptp-VPN-1 : %ASA-7-713236: IP = 184.94.160.170, IKE_DECODE SENDING Message (msgid=49eda39) with payloads : HDR + HASH (8) + NOTIFY (11) + NONE (0) total length : 84
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide