cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2436
Views
0
Helpful
5
Replies

vpn client issue

Roberto Kippins
Level 1
Level 1

I need help with my vpn connection, I have ipsec vpn setup on an asa5505 at one of my office locations but when I try to log in to the vpn with the vpn client it just dont work but I have a Linux laptop with vpnc loaded and that connects just fine no problems there any ideas???? by the way on my windows system i Have vpn client 5.0.07 asa5505 8.0.(4) asdm 6.1.(3)

5 Replies 5

Jennifer Halim
Cisco Employee
Cisco Employee

which version of Windows OS are you running? and also do you connect both the windows and linux to the vpn at the same time from the same location and you have the issue, or, even if you have the linux laptop not connected, and just try to connect with the windows, the windows machine can't connect?

what error logs are you getting on the windows machine? pls enable the logs to see what could have been the issue.

I tried it on both windows 7 and xp and from 5 different locations my linux laptop connects through all 5 locations but not windows and there is no firewall or network issue with my windows machines i will go through the log files and post my findings later on.

Thanks

I collected the logs here you go

Cisco Systems VPN Client Version 5.0.07.0410

Copyright (C) 1998-2010 Cisco Systems, Inc. All Rights Reserved.

Client Type(s): Windows, WinNT

Running on: 5.1.2600 Service Pack 3

3      09:10:40.140  12/15/12  Sev=Warning/2    IKE/0xE300009B

Invalid SPI size (PayloadNotify:116)

4      09:10:40.140  12/15/12  Sev=Warning/3    IKE/0xA3000058

Received malformed message or negotiation no longer active (message id: 0x00000000)

5      09:10:45.171  12/15/12  Sev=Warning/2    IKE/0xE300009B

Fragmented msg rcvd with no associated SA (PacketReceiver:133)

6      09:10:45.171  12/15/12  Sev=Warning/2    IKE/0xE300009B

Fragmented msg rcvd with no associated SA (PacketReceiver:133)

7      09:10:50.171  12/15/12  Sev=Warning/2    IKE/0xE300009B

Fragmented msg rcvd with no associated SA (PacketReceiver:133)

8      09:10:50.171  12/15/12  Sev=Warning/2    IKE/0xE300009B

Fragmented msg rcvd with no associated SA (PacketReceiver:133)

9      09:10:55.187  12/15/12  Sev=Warning/2    IKE/0xE300009B

Fragmented msg rcvd with no associated SA (PacketReceiver:133)

10     09:10:55.203  12/15/12  Sev=Warning/2    IKE/0xE300009B

Fragmented msg rcvd with no associated SA (PacketReceiver:133)

Looks like there is a lot of fragmentation happening hence it won't be able to connect as the fragmented packet is unreadable.

Try to lower the MTU to 1300 on the VPN Client. Use the "Set MTU" application on the Windows machine. Go to Start --> All Programs --> Cisco Systems VPN Client --> set MTU

Thanks I will try this and give feedback