cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
5366
Views
0
Helpful
2
Replies

VPN Phase 2 Failing

drikilbride
Level 1
Level 1

Hi

I am trying to set up a new VPN connection between Site A and Site B.

It passes phase one but throws up an error at phase two. I will attach the error message.

Site A's firewall currently has another VPN on it working away fine so I suspect the problem lies on Site B's config.

Thanks in advance

1 Accepted Solution

Accepted Solutions

Jennifer Halim
Cisco Employee
Cisco Employee

PFS is not matching.

Site A: you have "crypto map outside_map 2 set pfs group1"

Site B: you have "crypto map outside_map 4 set pfs" ---> which default to pfs group 2

Change either one to match each other.

Hope that resolves the issue.

View solution in original post

2 Replies 2

Jennifer Halim
Cisco Employee
Cisco Employee

PFS is not matching.

Site A: you have "crypto map outside_map 2 set pfs group1"

Site B: you have "crypto map outside_map 4 set pfs" ---> which default to pfs group 2

Change either one to match each other.

Hope that resolves the issue.

Ah was that all?? That got it working...thanks a mil!