12-13-2012 03:49 PM
I need help with my vpn connection, I have ipsec vpn setup on an asa5505 at one of my office locations but when I try to log in to the vpn with the vpn client it just dont work but I have a Linux laptop with vpnc loaded and that connects just fine no problems there any ideas???? by the way on my windows system i Have vpn client 5.0.07 asa5505 8.0.(4) asdm 6.1.(3)
12-13-2012 08:51 PM
which version of Windows OS are you running? and also do you connect both the windows and linux to the vpn at the same time from the same location and you have the issue, or, even if you have the linux laptop not connected, and just try to connect with the windows, the windows machine can't connect?
what error logs are you getting on the windows machine? pls enable the logs to see what could have been the issue.
12-14-2012 05:44 AM
I tried it on both windows 7 and xp and from 5 different locations my linux laptop connects through all 5 locations but not windows and there is no firewall or network issue with my windows machines i will go through the log files and post my findings later on.
Thanks
12-15-2012 05:28 AM
I collected the logs here you go
Cisco Systems VPN Client Version 5.0.07.0410
Copyright (C) 1998-2010 Cisco Systems, Inc. All Rights Reserved.
Client Type(s): Windows, WinNT
Running on: 5.1.2600 Service Pack 3
3 09:10:40.140 12/15/12 Sev=Warning/2 IKE/0xE300009B
Invalid SPI size (PayloadNotify:116)
4 09:10:40.140 12/15/12 Sev=Warning/3 IKE/0xA3000058
Received malformed message or negotiation no longer active (message id: 0x00000000)
5 09:10:45.171 12/15/12 Sev=Warning/2 IKE/0xE300009B
Fragmented msg rcvd with no associated SA (PacketReceiver:133)
6 09:10:45.171 12/15/12 Sev=Warning/2 IKE/0xE300009B
Fragmented msg rcvd with no associated SA (PacketReceiver:133)
7 09:10:50.171 12/15/12 Sev=Warning/2 IKE/0xE300009B
Fragmented msg rcvd with no associated SA (PacketReceiver:133)
8 09:10:50.171 12/15/12 Sev=Warning/2 IKE/0xE300009B
Fragmented msg rcvd with no associated SA (PacketReceiver:133)
9 09:10:55.187 12/15/12 Sev=Warning/2 IKE/0xE300009B
Fragmented msg rcvd with no associated SA (PacketReceiver:133)
10 09:10:55.203 12/15/12 Sev=Warning/2 IKE/0xE300009B
Fragmented msg rcvd with no associated SA (PacketReceiver:133)
12-17-2012 09:12 PM
Looks like there is a lot of fragmentation happening hence it won't be able to connect as the fragmented packet is unreadable.
Try to lower the MTU to 1300 on the VPN Client. Use the "Set MTU" application on the Windows machine. Go to Start --> All Programs --> Cisco Systems VPN Client --> set MTU
12-18-2012 05:09 AM
Thanks I will try this and give feedback
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide