11-21-2014 12:30 AM
Dear All,
i have a ASA-5505 configuring as VPN site to site and i have created vpn connection for connect site, befor i have finished connection and was worked but from today moring it has been down & unable to establised again i got error when i use command "show run crypto isakmp" nothing showed for any policy that i had configured befor, it make me deffical to identify the problem when i run debug command it show like mismatch with crypto isakmp policy, any one know about this please help me for key idea. I have attached my COnfig file for your refference
warm regard,
VIkrant
11-21-2014 04:25 AM
Hi Vikrant,
Please take a packet tracer output.
packet-tracer input inside icmp 192.168.0.1 8 0 192.168.20.1 detailed
Use "debug crypto ikev1 200" and "debug crypto ipsec 200" output.
Please attach the output and I will analyze the same.
11-21-2014 04:30 AM
11-21-2014 04:48 AM
Hi Vikram,
According to the packet tracer output the traffic is not even hitting the encryption engine.
Could you please provide me some logs and debugs when you initiate some real traffic ?
the file you attached didn't have any debugs as expected because the traffic didn't hit the encryption engine.
Regards,
Aditya
11-21-2014 05:00 AM
Hi Aaditya,
I got some error please see
>Nov 20 20:15:25 [IKEv1]Group = XX.XX.XX210, IP = XX.XX.XX210, QM FSM error (P2 struct &0xd8f4a210, mess id 0xa2efbbb5)!
Nov 20 20:15:25 [IKEv1]Group = XX.XX.XX210, IP = XX.XX.XX210, Removing peer from correlator table failed, no match!
Nov 20 20:15:25 [IKEv1]Group = XX.XX.XX210, IP = XX.XX.XX210, Session is being torn down. Reason: crypto map policy not found
Nov 20 20:15:30 [IKEv1]Group = XX.XX.XX210, IP = XX.XX.XX210, QM FSM error (P2 struct &0xd8f4a210, mess id 0x52a2db01)!
Nov 20 20:15:30 [IKEv1]Group = XX.XX.XX210, IP = XX.XX.XX210, Removing peer from correlator table failed, no match!
Nov 20 20:15:30 [IKEv1]Group = XX.XX.XX210, IP = XX.XX.XX210, Session is being torn down. Reason: crypto map policy not found
Nov 20 20:15:35 [IKEv1]Group = XX.XX.XX210, IP = XX.XX.XX210, QM FSM error (P2 struct &0xd8f4a210, mess id 0xbd378969)!
Nov 20 20:15:35 [IKEv1]Group = XX.XX.XX210, IP = XX.XX.XX210, Removing peer from correlator table failed, no match!
Nov 20 20:15:35 [IKEv1]Group = XX.XX.XX210, IP = XX.XX.XX210, Session is being torn down. Reason: crypto map policy not found
Nov 20 20:15:40 [IKEv1]Group = XX.XX.XX210, IP = XX.XX.XX210, QM FSM error (P2 struct &0xd8f4a210, mess id 0xf693c2e4)!
Nov 20 20:15:40 [IKEv1]Group = XX.XX.XX210, IP = XX.XX.XX210, Removing peer from correlator table failed, no match!
Nov 20 20:15:40 [IKEv1]Group = XX.XX.XX210, IP = XX.XX.XX210, Session is being torn down. Reason: crypto map policy not found
Nov 20 20:43:17 [IKEv1]Group = XX.XX.XX210, IP = XX.XX.XX210, QM FSM error (P2 struct &0xd69c2378, mess id 0xe9e0c725)!
Nov 20 20:43:17 [IKEv1]Group = XX.XX.XX210, IP = XX.XX.XX210, Removing peer from correlator table failed, no match!
Nov 20 20:43:17 [IKEv1]Group = XX.XX.XX210, IP = XX.XX.XX210, Session is being torn down. Reason: crypto map policy not found
Nov 20 20:43:21 [IKEv1]Group = XX.XX.XX210, IP = XX.XX.XX210, QM FSM error (P2 struct &0xd8f4a210, mess id 0x9faba3c4)!
Nov 20 20:43:21 [IKEv1]Group = XX.XX.XX210, IP = XX.XX.XX210, Removing peer from correlator table failed, no match!
Nov 20 20:43:21 [IKEv1]Group = XX.XX.XX210, IP = XX.XX.XX210, Session is being torn down. Reason: crypto map policy not found
Nov 20 20:43:26 [IKEv1]Group = XX.XX.XX210, IP = XX.XX.XX210, QM FSM error ( P2 struct &0xd8f4a210, mess id 0x49c2fd1e)!
Nov 20 20:43:26 [IKEv1]Group = XX.XX.XX210, IP = XX.XX.XX210, Removing peer from correlator table failed, no match!
11-21-2014 06:24 AM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide