Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations SkipVought on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

515 w/ 6.3(3) Upgrade Now have VPN Problems.

Status
Not open for further replies.

quell

IS-IT--Management
Nov 8, 2002
363
0
0
US
I recently upgraded our 515 from 622 to 633. Now no one can connect to the vpn useing VPN Dialer 3.5.2 (I think) with XP SP2 installed. Here is the debug isakmp log. At the end it says "error, msg not encrypted" I'm not for sure what causes this. Any help in the right direction would help.
Thanks

crypto_isakmp_process_block:src:66.xxx.xxx.61, dest:66.xxx.xxx.60 spt:500 dpt:500
OAK_AG exchange
ISAKMP (0): processing SA payload. message ID = 0

ISAKMP (0): Checking ISAKMP transform 1 against priority 10 policy
ISAKMP: encryption 3DES-CBC
ISAKMP: hash SHA
ISAKMP: default group 2
ISAKMP: extended auth pre-share (init)
ISAKMP: life type in seconds
ISAKMP: life duration (VPI) of 0x0 0x20 0xc4 0x9b
ISAKMP (0): atts are not acceptable. Next payload is 3
ISAKMP (0): Checking ISAKMP transform 2 against priority 10 policy
ISAKMP: encryption 3DES-CBC
ISAKMP: hash MD5
ISAKMP: default group 2
ISAKMP: extended auth pre-share (init)
ISAKMP: life type in seconds
ISAKMP: life duration (VPI) of 0x0 0x20 0xc4 0x9b
ISAKMP (0): atts are acceptable. Next payload is 3
ISAKMP (0): processing KE payload. message ID = 0

ISAKMP (0): processing NONCE payload. message ID = 0

ISAKMP (0): processing ID payload. message ID = 0
ISAKMP (0): processing vendor id payload

ISAKMP (0): received xauth v6 vendor id

ISAKMP (0): processing vendor id payload

ISAKMP (0): remote peer supports dead peer detection

ISAKMP (0): processing vendor id payload

ISAKMP (0): speaking to a Unity client

ISAKMP (0): ID payload
next-payload : 10
type : 1
protocol : 17
port : 500
length : 8
ISAKMP (0): Total payload length: 12
return status is IKMP_NO_ERROR
crypto_isakmp_process_block:src:66.xxx.xxx.61, dest:66.xxx.xxx.60 spt:500 dpt:500
ISAKMP: error, msg not encrypted

I'm not for sure if I need to upgrade the dialer software in order to communicate with the pix upgrade or what.

I would rather have it and not need it, then need it and not have it.
 
Forgot to add that during the upgrade I used the old key. Dunno if that matters or not.
 
Nevermind....upgraded the dialer to 4.0.3 and everything is back to normal.
 
Windows XP Service Pack 2 adds a software firewall to the PCs, so it could affect your vpn software. :-(
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top