cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
4049
Views
0
Helpful
8
Replies

Tunnel IPSec not work

emilio1973
Level 1
Level 1

Hi all,

 

We have a tunnel IPSec that not work. I think that Phase 2 is not established but i don't know why.

Add output and log.

 

Thanks for your help

 

 

 

ASA-VPN-PRI/act/pri# sh crypto isakmp sa
!
13  IKE Peer: 91.209.243.5
    Type    : L2L             Role    : responder
    Rekey   : no              State   : MM_ACTIVE

!

ASA-VPN-PRI/act/pri# sh crypto isakmp sa | include 91.209.243.5
12  IKE Peer: 91.209.243.5
ASA-VPN-PRI/act/pri#

 


ASA-VPN-PRI/act/pri# sh crypto ipsec sa | include 91.209.243.5
ASA-VPN-PRI/act/pri#

 

 

7|Dec 17 2014|15:40:48|713236|||||IP = 91.209.243.5, IKE_DECODE SENDING Message (msgid=c516994b) with payloads : HDR + HASH (8) + NOTIFY (11) + NONE (0) total length : 84
7|Dec 17 2014|15:40:48|715046|||||Group = 91.209.243.5, IP = 91.209.243.5, constructing qm hash payload
7|Dec 17 2014|15:40:48|715046|||||Group = 91.209.243.5, IP = 91.209.243.5, constructing blank hash payload
7|Dec 17 2014|15:40:48|715036|||||Group = 91.209.243.5, IP = 91.209.243.5, Sending keep-alive of type DPD R-U-THERE-ACK (seq number 0x7d6c)
7|Dec 17 2014|15:40:48|715075|||||Group = 91.209.243.5, IP = 91.209.243.5, Received keep-alive of type DPD R-U-THERE (seq number 0x7d6c)
7|Dec 17 2014|15:40:48|715047|||||Group = 91.209.243.5, IP = 91.209.243.5, processing notify payload
7|Dec 17 2014|15:40:48|715047|||||Group = 91.209.243.5, IP = 91.209.243.5, processing hash payload
7|Dec 17 2014|15:40:48|713236|||||IP = 91.209.243.5, IKE_DECODE RECEIVED Message (msgid=29bf4142) with payloads : HDR + HASH (8) + NOTIFY (11) + NONE (0) total length : 84
7|Dec 17 2014|15:40:43|713236|||||IP = 91.209.243.5, IKE_DECODE SENDING Message (msgid=b72ddf0a) with payloads : HDR + HASH (8) + NOTIFY (11) + NONE (0) total length : 84
7|Dec 17 2014|15:40:43|715046|||||Group = 91.209.243.5, IP = 91.209.243.5, constructing qm hash payload
7|Dec 17 2014|15:40:43|715046|||||Group = 91.209.243.5, IP = 91.209.243.5, constructing blank hash payload
7|Dec 17 2014|15:40:43|715036|||||Group = 91.209.243.5, IP = 91.209.243.5, Sending keep-alive of type DPD R-U-THERE-ACK (seq number 0x7d6b)
7|Dec 17 2014|15:40:43|715075|||||Group = 91.209.243.5, IP = 91.209.243.5, Received keep-alive of type DPD R-U-THERE (seq number 0x7d6b)
7|Dec 17 2014|15:40:43|715047|||||Group = 91.209.243.5, IP = 91.209.243.5, processing notify payload
7|Dec 17 2014|15:40:43|715047|||||Group = 91.209.243.5, IP = 91.209.243.5, processing hash payload
7|Dec 17 2014|15:40:43|713236|||||IP = 91.209.243.5, IKE_DECODE RECEIVED Message (msgid=ae5305df) with payloads : HDR + HASH (8) + NOTIFY (11) + NONE (0) total length : 84
7|Dec 17 2014|15:40:38|713236|||||IP = 91.209.243.5, IKE_DECODE SENDING Message (msgid=b796798d) with payloads : HDR + HASH (8) + NOTIFY (11) + NONE (0) total length : 84
7|Dec 17 2014|15:40:38|715046|||||Group = 91.209.243.5, IP = 91.209.243.5, constructing qm hash payload
7|Dec 17 2014|15:40:38|715046|||||Group = 91.209.243.5, IP = 91.209.243.5, constructing blank hash payload
7|Dec 17 2014|15:40:38|715036|||||Group = 91.209.243.5, IP = 91.209.243.5, Sending keep-alive of type DPD R-U-THERE-ACK (seq number 0x7d6a)
7|Dec 17 2014|15:40:38|715075|||||Group = 91.209.243.5, IP = 91.209.243.5, Received keep-alive of type DPD R-U-THERE (seq number 0x7d6a)
7|Dec 17 2014|15:40:38|715047|||||Group = 91.209.243.5, IP = 91.209.243.5, processing notify payload
7|Dec 17 2014|15:40:38|715047|||||Group = 91.209.243.5, IP = 91.209.243.5, processing hash payload
7|Dec 17 2014|15:40:38|713236|||||IP = 91.209.243.5, IKE_DECODE RECEIVED Message (msgid=98241c63) with payloads : HDR + HASH (8) + NOTIFY (11) + NONE (0) total length : 84
7|Dec 17 2014|15:40:33|713236|||||IP = 91.209.243.5, IKE_DECODE SENDING Message (msgid=e233621d) with payloads : HDR + HASH (8) + NOTIFY (11) + NONE (0) total length : 84
7|Dec 17 2014|15:40:33|715046|||||Group = 91.209.243.5, IP = 91.209.243.5, constructing qm hash payload
7|Dec 17 2014|15:40:33|715046|||||Group = 91.209.243.5, IP = 91.209.243.5, constructing blank hash payload
7|Dec 17 2014|15:40:33|715036|||||Group = 91.209.243.5, IP = 91.209.243.5, Sending keep-alive of type DPD R-U-THERE-ACK (seq number 0x7d69)
7|Dec 17 2014|15:40:33|715075|||||Group = 91.209.243.5, IP = 91.209.243.5, Received keep-alive of type DPD R-U-THERE (seq number 0x7d69)
7|Dec 17 2014|15:40:33|715047|||||Group = 91.209.243.5, IP = 91.209.243.5, processing notify payload
7|Dec 17 2014|15:40:33|715047|||||Group = 91.209.243.5, IP = 91.209.243.5, processing hash payload
7|Dec 17 2014|15:40:33|713236|||||IP = 91.209.243.5, IKE_DECODE RECEIVED Message (msgid=36ecdf6a) with payloads : HDR + HASH (8) + NOTIFY (11) + NONE (0) total length : 84
7|Dec 17 2014|15:40:28|713236|||||IP = 91.209.243.5, IKE_DECODE SENDING Message (msgid=cb1b978d) with payloads : HDR + HASH (8) + NOTIFY (11) + NONE (0) total length : 84
7|Dec 17 2014|15:40:28|715046|||||Group = 91.209.243.5, IP = 91.209.243.5, constructing qm hash payload
7|Dec 17 2014|15:40:28|715046|||||Group = 91.209.243.5, IP = 91.209.243.5, constructing blank hash payload
7|Dec 17 2014|15:40:28|715036|||||Group = 91.209.243.5, IP = 91.209.243.5, Sending keep-alive of type DPD R-U-THERE-ACK (seq number 0x7d68)
7|Dec 17 2014|15:40:28|715075|||||Group = 91.209.243.5, IP = 91.209.243.5, Received keep-alive of type DPD R-U-THERE (seq number 0x7d68)
7|Dec 17 2014|15:40:28|715047|||||Group = 91.209.243.5, IP = 91.209.243.5, processing notify payload
7|Dec 17 2014|15:40:28|715047|||||Group = 91.209.243.5, IP = 91.209.243.5, processing hash payload
7|Dec 17 2014|15:40:28|713236|||||IP = 91.209.243.5, IKE_DECODE RECEIVED Message (msgid=f25bcdb5) with payloads : HDR + HASH (8) + NOTIFY (11) + NONE (0) total length : 84
7|Dec 17 2014|15:40:23|713236|||||IP = 91.209.243.5, IKE_DECODE SENDING Message (msgid=32bca075) with payloads : HDR + HASH (8) + NOTIFY (11) + NONE (0) total length : 84
7|Dec 17 2014|15:40:23|715046|||||Group = 91.209.243.5, IP = 91.209.243.5, constructing qm hash payload
7|Dec 17 2014|15:40:23|715046|||||Group = 91.209.243.5, IP = 91.209.243.5, constructing blank hash payload
7|Dec 17 2014|15:40:23|715036|||||Group = 91.209.243.5, IP = 91.209.243.5, Sending keep-alive of type DPD R-U-THERE-ACK (seq number 0x7d67)
7|Dec 17 2014|15:40:23|715075|||||Group = 91.209.243.5, IP = 91.209.243.5, Received keep-alive of type DPD R-U-THERE (seq number 0x7d67)
7|Dec 17 2014|15:40:23|715047|||||Group = 91.209.243.5, IP = 91.209.243.5, processing notify payload
7|Dec 17 2014|15:40:23|715047|||||Group = 91.209.243.5, IP = 91.209.243.5, processing hash payload
7|Dec 17 2014|15:40:23|713236|||||IP = 91.209.243.5, IKE_DECODE RECEIVED Message (msgid=a3f0e3f9) with payloads : HDR + HASH (8) + NOTIFY (11) + NONE (0) total length : 84
 

 

 

 

 

1 Accepted Solution

Accepted Solutions

Please repeat the debug with "debug crypto isakmp 100". And compare the Phase-2 config of both sides:

  1. Is the crypto ACL exactly mirrored on both sides?
  2. Do your transform-sets include exactly the same algorithms?

View solution in original post

8 Replies 8

Please repeat the debug with "debug crypto isakmp 100". And compare the Phase-2 config of both sides:

  1. Is the crypto ACL exactly mirrored on both sides?
  2. Do your transform-sets include exactly the same algorithms?

Hi Karsten,

 

I'll check it. Thanks for your help

 

Best regards

ASA-VPN-PRI/act/pri# debug crypto isakmp 100   
ASA-VPN-PRI/act/pri# Dec 18 08:28:23 [IKEv1]: IP = 201.151.149.170, IKE_DECODE RECEIVED Message (msgid=b316f003) with payloads : HDR + HASH (8) + NOTIFY (11) + NONE (0) total length : 84
Dec 18 08:28:23 [IKEv1 DEBUG]: Group = 201.151.149.170, IP = 201.151.149.170, processing hash payload
Dec 18 08:28:23 [IKEv1 DEBUG]: Group = 201.151.149.170, IP = 201.151.149.170, processing notify payload
Dec 18 08:28:23 [IKEv1 DEBUG]: Group = 201.151.149.170, IP = 201.151.149.170, Received keep-alive of type DPD R-U-THERE (seq number 0x25aa4a4a)
Dec 18 08:28:23 [IKEv1 DEBUG]: Group = 201.151.149.170, IP = 201.151.149.170, Sending keep-alive of type DPD R-U-THERE-ACK (seq number 0x25aa4a4a)
Dec 18 08:28:23 [IKEv1 DEBUG]: Group = 201.151.149.170, IP = 201.151.149.170, constructing blank hash payload
Dec 18 08:28:23 [IKEv1 DEBUG]: Group = 201.151.149.170, IP = 201.151.149.170, constructing qm hash payload
Dec 18 08:28:23 [IKEv1]: IP = 201.151.149.170, IKE_DECODE SENDING Message (msgid=ec8ccf3d) with payloads : HDR + HASH (8) + NOTIFY (11) + NONE (0) total length : 84
Dec 18 08:28:23 [IKEv1 DEBUG]: Pitcher: received a key acquire message, spi 0x0
Dec 18 08:28:23 [IKEv1]: IP = 154.126.209.18, Queuing KEY-ACQUIRE messages to be processed when P1 SA is complete.
Dec 18 08:28:23 [IKEv1]: IP = 91.209.243.5, IKE_DECODE RECEIVED Message (msgid=e4e5a591) with payloads : HDR + HASH (8) + NOTIFY (11) + NONE (0) total length : 84
Dec 18 08:28:23 [IKEv1 DEBUG]: Group = 91.209.243.5, IP = 91.209.243.5, processing hash payload
Dec 18 08:28:23 [IKEv1 DEBUG]: Group = 91.209.243.5, IP = 91.209.243.5, processing notify payload
Dec 18 08:28:23 [IKEv1 DEBUG]: Group = 91.209.243.5, IP = 91.209.243.5, Received keep-alive of type DPD R-U-THERE (seq number 0xac81)
Dec 18 08:28:23 [IKEv1 DEBUG]: Group = 91.209.243.5, IP = 91.209.243.5, Sending keep-alive of type DPD R-U-THERE-ACK (seq number 0xac81)
Dec 18 08:28:23 [IKEv1 DEBUG]: Group = 91.209.243.5, IP = 91.209.243.5, constructing blank hash payload
Dec 18 08:28:23 [IKEv1 DEBUG]: Group = 91.209.243.5, IP = 91.209.243.5, constructing qm hash payload
Dec 18 08:28:23 [IKEv1]: IP = 91.209.243.5, IKE_DECODE SENDING Message (msgid=46b0c248) with payloads : HDR + HASH (8) + NOTIFY (11) + NONE (0) total length : 84

Dec 18 08:28:25 [IKEv1]: IP = 154.126.209.17, Header invalid, missing SA payload! (next payload = 4)

Can you also debug on the other side? And which versions are you running?

Hi Karsten,

this is our version:

ASA-VPN-PRI/act/pri# sh ver

Cisco Adaptive Security Appliance Software Version 8.0(5)9
Device Manager Version 6.2(5)

Compiled on Mon 01-Feb-10 10:36 by builders
System image file is "disk0:/asa805-9-k8.bin"

 

I am trying to contact a technician on the other side to get their settings and logs.

 

I hope to receive the information soon and I'll add here.

 

Thanks for your help

 

 

Hi Karsten , you were right. It was a mismatch on the transform-set but ASDM not give the correct information.

 

Thanks a lot

 

Best regards

Thats a problem that exists in many ASDM-versions. Its best to have a crypto ACL with only one line. If there are multiple networks on the remote or local side, then these networks should be put into object-groups. That way, the ASDM typically can display everything correctly.

Hello sir,

 

Can I know what below logs are telling ?

 

Because there was server which was hosted in our environment but the VPN tunnel went down when I check the logs I see below lines.

 

When the tunnel was down I see below logs:

 


Jan 17 2019 06:16:08 ISS-365-ASA-ptp-VPN-1 : %ASA-7-715036: Group = 184.94.160.170, IP = 184.94.160.170, Sending keep-alive of type DPD R-U-THERE (seq number 0x1a96fc07)
Jan 17 2019 06:16:08 ISS-365-ASA-ptp-VPN-1 : %ASA-7-715046: Group = 184.94.160.170, IP = 184.94.160.170, constructing blank hash payload
Jan 17 2019 06:16:08 ISS-365-ASA-ptp-VPN-1 : %ASA-7-715046: Group = 184.94.160.170, IP = 184.94.160.170, constructing qm hash payload
Jan 17 2019 06:16:08 ISS-365-ASA-ptp-VPN-1 : %ASA-7-713236: IP = 184.94.160.170, IKE_DECODE SENDING Message (msgid=1f8cea53) with payloads : HDR + HASH (8) + NOTIFY (11) + NONE (0) total length : 84

 

Once the tunnel was up I see below logs unfortunately, I didn't see any difference between those two. 

 

Jan 17 2019 06:16:28 ISS-365-ASA-ptp-VPN-1 : %ASA-7-715036: Group = 184.94.160.170, IP = 184.94.160.170, Sending keep-alive of type DPD R-U-THERE (seq number 0x1a96fc09)
Jan 17 2019 06:16:28 ISS-365-ASA-ptp-VPN-1 : %ASA-7-715046: Group = 184.94.160.170, IP = 184.94.160.170, constructing blank hash payload
Jan 17 2019 06:16:28 ISS-365-ASA-ptp-VPN-1 : %ASA-7-715046: Group = 184.94.160.170, IP = 184.94.160.170, constructing qm hash payload
Jan 17 2019 06:16:28 ISS-365-ASA-ptp-VPN-1 : %ASA-7-713236: IP = 184.94.160.170, IKE_DECODE SENDING Message (msgid=49eda39) with payloads : HDR + HASH (8) + NOTIFY (11) + NONE (0) total length : 84

 

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: