Hi intelwizrd,
I have a Cisco 1812 with Easy VPN server configures, and everything works fine with Cisco VPN Client on windows, but I cant connect with Iphone/Ipad. It pops up with user credentials, but whatever I type it fails.
Is there anything Im missing ?
Debug crypto isakmp gives me this, when a Iphone tries to connect:
*Oct 13 12:55:42.705: ISAKMP (0): received packet from 109.57.11.247 dport 500 sport 500 Global (N) NEW SA
*Oct 13 12:55:42.705: ISAKMP: Created a peer struct for 109.57.11.247, peer port 500
*Oct 13 12:55:42.705: ISAKMP: New peer created peer = 0x8814ED04 peer_handle = 0x80000026
*Oct 13 12:55:42.705: ISAKMP: Locking peer struct 0x8814ED04, refcount 1 for crypto_isakmp_process_block
*Oct 13 12:55:42.705: ISAKMP: local port 500, remote port 500
*Oct 13 12:55:42.705: ISAKMP

0):insert sa successfully sa = 85B764D4
*Oct 13 12:55:42.705: ISAKMP

0): processing SA payload. message ID = 0
*Oct 13 12:55:42.705: ISAKMP

0): processing ID payload. message ID = 0
*Oct 13 12:55:42.705: ISAKMP (0): ID payload
next-payload : 13
type : 11
group id : Sindby
protocol : 0
port : 0
length : 14
*Oct 13 12:55:42.705: ISAKMP

0):: peer matches sdm-ike-profile-1 profile
*Oct 13 12:55:42.705: ISAKMP

0):Setting client config settings 86DAF750
*Oct 13 12:55:42.705: ISAKMP

0)

Re)Setting client xauth list and state
*Oct 13 12:55:42.705: ISAKMP/xauth: initializing AAA request
*Oct 13 12:55:42.705: ISAKMP

0): processing vendor id payload
*Oct 13 12:55:42.705: ISAKMP

0): vendor ID seems Unity/DPD but major 69 mismatch
*Oct 13 12:55:42.705: ISAKMP (0): vendor ID is NAT-T RFC 3947
*Oct 13 12:55:42.705: ISAKMP

0): processing vendor id payload
*Oct 13 12:55:42.705: ISAKMP

0): vendor ID seems Unity/DPD but major 198 mismatch
*Oct 13 12:55:42.705: ISAKMP

0): processing vendor id payload
*Oct 13 12:55:42.705: ISAKMP

0): vendor ID seems Unity/DPD but major 29 mismatch
*Oct 13 12:55:42.705: ISAKMP

0): processing vendor id payload
*Oct 13 12:55:42.705: ISAKMP

0): vendor ID seems Unity/DPD but major 245 mismatch
*Oct 13 12:55:42.705: ISAKMP (0): vendor ID is NAT-T v7
*Oct 13 12:55:42.705: ISAKMP

0): processing vendor id payload
*Oct 13 12:55:42.705: ISAKMP

0): vendor ID seems Unity/DPD but major 114 mismatch
*Oct 13 12:55:42.705: ISAKMP

0): processing vendor id payload
*Oct 13 12:55:42.705: ISAKMP

0): vendor ID seems Unity/DPD but major 227 mismatch
*Oct 13 12:55:42.705: ISAKMP

0): processing vendor id payload
*Oct 13 12:55:42.705: ISAKMP

0): vendor ID seems Unity/DPD but major 250 mismatch
*Oct 13 12:55:42.705: ISAKMP

0): processing vendor id payload
*Oct 13 12:55:42.705: ISAKMP

0): vendor ID seems Unity/DPD but major 157 mismatch
*Oct 13 12:55:42.705: ISAKMP

0): vendor ID is NAT-T v3
*Oct 13 12:55:42.705: ISAKMP

0): processing vendor id payload
*Oct 13 12:55:42.705: ISAKMP

0): vendor ID seems Unity/DPD but major 164 mismatch
*Oct 13 12:55:42.705: ISAKMP

0): processing vendor id payload
*Oct 13 12:55:42.705: ISAKMP

0): vendor ID seems Unity/DPD but major 123 mismatch
*Oct 13 12:55:42.705: ISAKMP

0): vendor ID is NAT-T v2
*Oct 13 12:55:42.705: ISAKMP

0): processing vendor id payload
*Oct 13 12:55:42.705: ISAKMP

0): vendor ID seems Unity/DPD but major 242 mismatch
*Oct 13 12:55:42.705: ISAKMP

0): vendor ID is XAUTH
*Oct 13 12:55:42.705: ISAKMP

0): processing vendor id payload
*Oct 13 12:55:42.705: ISAKMP

0): vendor ID is Unity
*Oct 13 12:55:42.705: ISAKMP

0): processing vendor id payload
*Oct 13 12:55:42.705: ISAKMP

0): vendor ID is DPD
*Oct 13 12:55:42.705: ISAKMP

0): Authentication by xauth preshared
*Oct 13 12:55:42.705: ISAKMP

0):Checking ISAKMP transform 1 against priority 1 policy
*Oct 13 12:55:42.705: ISAKMP: life type in seconds
*Oct 13 12:55:42.705: ISAKMP: life duration (basic) of 3600
*Oct 13 12:55:42.705: ISAKMP: encryption AES-CBC
*Oct 13 12:55:42.705: ISAKMP: keylength of 256
*Oct 13 12:55:42.705: ISAKMP: auth XAUTHInitPreShared
*Oct 13 12:55:42.705: ISAKMP: hash SHA
*Oct 13 12:55:42.705: ISAKMP: default group 2
*Oct 13 12:55:42.705: ISAKMP

0):Encryption algorithm offered does not match policy!
*Oct 13 12:55:42.705: ISAKMP

0):atts are not acceptable. Next payload is 3
*Oct 13 12:55:42.705: ISAKMP

0):Checking ISAKMP transform 2 against priority 1 policy
*Oct 13 12:55:42.705: ISAKMP: life type in seconds
*Oct 13 12:55:42.705: ISAKMP: life duration (basic) of 3600
*Oct 13 12:55:42.705: ISAKMP: encryption AES-CBC
*Oct 13 12:55:42.705: ISAKMP: keylength of 128
*Oct 13 12:55:42.705: ISAKMP: auth XAUTHInitPreShared
*Oct 13 12:55:42.705: ISAKMP: hash SHA
*Oct 13 12:55:42.705: ISAKMP: default group 2
*Oct 13 12:55:42.705: ISAKMP

0):Encryption algorithm offered does not match policy!
*Oct 13 12:55:42.705: ISAKMP

0):atts are not acceptable. Next payload is 3
*Oct 13 12:55:42.705: ISAKMP

0):Checking ISAKMP transform 3 against priority 1 policy
*Oct 13 12:55:42.705: ISAKMP: life type in seconds
*Oct 13 12:55:42.705: ISAKMP: life duration (basic) of 3600
*Oct 13 12:55:42.705: ISAKMP: encryption AES-CBC
*Oct 13 12:55:42.705: ISAKMP: keylength of 256
*Oct 13 12:55:42.705: ISAKMP: auth XAUTHInitPreShared
*Oct 13 12:55:42.705: ISAKMP: hash MD5
*Oct 13 12:55:42.705: ISAKMP: default group 2
*Oct 13 12:55:42.709: ISAKMP

0):Encryption algorithm offered does not match policy!
*Oct 13 12:55:42.709: ISAKMP

0):atts are not acceptable. Next payload is 3
*Oct 13 12:55:42.709: ISAKMP

0):Checking ISAKMP transform 4 against priority 1 policy
*Oct 13 12:55:42.709: ISAKMP: life type in seconds
*Oct 13 12:55:42.709: ISAKMP: life duration (basic) of 3600
*Oct 13 12:55:42.709: ISAKMP: encryption AES-CBC
*Oct 13 12:55:42.709: ISAKMP: keylength of 128
*Oct 13 12:55:42.709: ISAKMP: auth XAUTHInitPreShared
*Oct 13 12:55:42.709: ISAKMP: hash MD5
*Oct 13 12:55:42.709: ISAKMP: default group 2
*Oct 13 12:55:42.709: ISAKMP

0):Encryption algorithm offered does not match policy!
*Oct 13 12:55:42.709: ISAKMP

0):atts are not acceptable. Next payload is 3
*Oct 13 12:55:42.709: ISAKMP

0):Checking ISAKMP transform 5 against priority 1 policy
*Oct 13 12:55:42.709: ISAKMP: life type in seconds
*Oct 13 12:55:42.709: ISAKMP: life duration (basic) of 3600
*Oct 13 12:55:42.709: ISAKMP: encryption 3DES-CBC
*Oct 13 12:55:42.709: ISAKMP: auth XAUTHInitPreShared
*Oct 13 12:55:42.709: ISAKMP: hash SHA
*Oct 13 12:55:42.709: ISAKMP: default group 2
*Oct 13 12:55:42.709: ISAKMP

0):atts are acceptable. Next payload is 3
*Oct 13 12:55:42.709: ISAKMP

0):Acceptable atts:actual life: 86400
*Oct 13 12:55:42.709: ISAKMP

0):Acceptable atts:life: 0
*Oct 13 12:55:42.709: ISAKMP

0):Basic life_in_seconds:3600
*Oct 13 12:55:42.709: ISAKMP

0):Returning Actual lifetime: 3600
*Oct 13 12:55:42.709: ISAKMP

0)::Started lifetime timer: 3600.
*Oct 13 12:55:42.709: ISAKMP

0): processing KE payload. message ID = 0
*Oct 13 12:55:42.733: ISAKMP

0): processing NONCE payload. message ID = 0
*Oct 13 12:55:42.733: ISAKMP (0): vendor ID is NAT-T RFC 3947
*Oct 13 12:55:42.733: ISAKMP (0): vendor ID is NAT-T v7
*Oct 13 12:55:42.733: ISAKMP

0): vendor ID is NAT-T v3
*Oct 13 12:55:42.733: ISAKMP

0): vendor ID is NAT-T v2
*Oct 13 12:55:42.733: ISAKMP

0):Input = IKE_MESG_FROM_PEER, IKE_AM_EXCH
*Oct 13 12:55:42.733: ISAKMP

0):Old State = IKE_READY New State = IKE_R_AM_AAA_AWAIT
*Oct 13 12:55:42.733: ISAKMP

2026): constructed NAT-T vendor-rfc3947 ID
*Oct 13 12:55:42.733: ISAKMP

2026):SA is doing pre-shared key authentication plus XAUTH using id type ID_IPV4_ADDR
*Oct 13 12:55:42.733: ISAKMP (2026): ID payload
next-payload : 10
type : 1
address : xx.xxx.xx.xx
protocol : 0
port : 0
length : 12
*Oct 13 12:55:42.733: ISAKMP

2026):Total payload length: 12
*Oct 13 12:55:42.737: ISAKMP

2026): sending packet to 109.57.11.247 my_port 500 peer_port 500 (R) AG_INIT_EXCH
*Oct 13 12:55:42.737: ISAKMP

2026):Sending an IKE IPv4 Packet.
*Oct 13 12:55:42.737: ISAKMP

2026):Input = IKE_MESG_FROM_AAA, PRESHARED_KEY_REPLY
*Oct 13 12:55:42.737: ISAKMP

2026):Old State = IKE_R_AM_AAA_AWAIT New State = IKE_R_AM2
*Oct 13 12:55:43.537: ISAKMP (2026): received packet from 109.57.11.247 dport 500 sport 500 Global (R) AG_INIT_EXCH
*Oct 13 12:55:43.537: ISAKMP

2026): processing HASH payload. message ID = 0
*Oct 13 12:55:43.537: ISAKMP:received payload type 20
*Oct 13 12:55:43.537: ISAKMP (2026): His hash no match - this node outside NAT
*Oct 13 12:55:43.537: ISAKMP:received payload type 20
*Oct 13 12:55:43.537: ISAKMP (2026): No NAT Found for self or peer
*Oct 13 12:55:43.537: ISAKMP

2026): processing NOTIFY INITIAL_CONTACT protocol 1
spi 0, message ID = 0, sa = 0x85B764D4
*Oct 13 12:55:43.537: ISAKMP

2026):SA authentication status:
authenticated
*Oct 13 12:55:43.537: ISAKMP

2026):SA has been authenticated with 109.57.11.247
*Oct 13 12:55:43.537: ISAKMP

2026):SA authentication status:
authenticated
*Oct 13 12:55:43.537: ISAKMP

2026): Process initial contact,
bring down existing phase 1 and 2 SA's with local xx.xxx.xx.xx remote 109.57.11.247 remote port 500
*Oct 13 12:55:43.541: ISAKMP

2026):returning IP addr to the address pool
*Oct 13 12:55:43.541: ISAKMP: Trying to insert a peer xx.xxx.xx.xx/109.57.11.247/500/, and inserted successfully 8814ED04.
*Oct 13 12:55:43.541: ISAKMP

2026):Returning Actual lifetime: 3600
*Oct 13 12:55:43.541: ISAKMP: set new node -1870316501 to CONF_XAUTH
*Oct 13 12:55:43.541: ISAKMP

2026):Sending NOTIFY RESPONDER_LIFETIME protocol 1
spi 2255271000, message ID = -1870316501
*Oct 13 12:55:43.541: ISAKMP

2026): sending packet to 109.57.11.247 my_port 500 peer_port 500 (R) QM_IDLE
*Oct 13 12:55:43.541: ISAKMP

2026):Sending an IKE IPv4 Packet.
*Oct 13 12:55:43.541: ISAKMP

2026)

urging node -1870316501
*Oct 13 12:55:43.541: ISAKMP: Sending phase 1 responder lifetime 3600
*Oct 13 12:55:43.541: ISAKMP

2026):Input = IKE_MESG_FROM_PEER, IKE_AM_EXCH
*Oct 13 12:55:43.541: ISAKMP

2026):Old State = IKE_R_AM2 New State = IKE_P1_COMPLETE
*Oct 13 12:55:43.541: ISAKMP

2026):Need XAUTH
*Oct 13 12:55:43.541: ISAKMP: set new node -1846708170 to CONF_XAUTH
*Oct 13 12:55:43.541: ISAKMP/xauth: request attribute XAUTH_TYPE_V2
*Oct 13 12:55:43.541: ISAKMP/xauth: request attribute XAUTH_USER_NAME_V2
*Oct 13 12:55:43.541: ISAKMP/xauth: request attribute XAUTH_DOMAIN_V2
*Oct 13 12:55:43.541: ISAKMP/xauth: request attribute XAUTH_USER_PASSWORD_V2
*Oct 13 12:55:43.541: ISAKMP

2026): initiating peer config to 109.57.11.247. ID = -1846708170
*Oct 13 12:55:43.541: ISAKMP

2026): sending packet to 109.57.11.247 my_port 500 peer_port 500 (R) CONF_XAUTH
*Oct 13 12:55:43.541: ISAKMP

2026):Sending an IKE IPv4 Packet.
*Oct 13 12:55:43.541: ISAKMP

2026):Input = IKE_MESG_INTERNAL, IKE_PHASE1_COMPLETE
*Oct 13 12:55:43.541: ISAKMP

2026):Old State = IKE_P1_COMPLETE New State = IKE_XAUTH_REQ_SENT
*Oct 13 12:55:52.237: ISAKMP (2026): received packet from 109.57.11.247 dport 500 sport 500 Global (R) CONF_XAUTH
*Oct 13 12:55:52.237: ISAKMP: set new node -935085502 to CONF_XAUTH
*Oct 13 12:55:52.237: ISAKMP

2026): processing HASH payload. message ID = -935085502
*Oct 13 12:55:52.237: ISAKMP

2026): processing DELETE payload. message ID = -935085502
*Oct 13 12:55:52.237: ISAKMP

2026)

eer does not do paranoid keepalives.
*Oct 13 12:55:52.237: ISAKMP

2026)

eer does not do paranoid keepalives.
*Oct 13 12:55:52.237: ISAKMP

2026):deleting SA reason "No reason" state (R) CONF_XAUTH (peer 109.57.11.247)
*Oct 13 12:55:52.237: ISAKMP

2026):deleting node -935085502 error FALSE reason "Informational (in) state 1"
*Oct 13 12:55:52.237: ISAKMP: set new node 1554826523 to CONF_XAUTH
*Oct 13 12:55:52.237: ISAKMP

2026): sending packet to 109.57.11.247 my_port 500 peer_port 500 (R) CONF_XAUTH
*Oct 13 12:55:52.237: ISAKMP

2026):Sending an IKE IPv4 Packet.
*Oct 13 12:55:52.237: ISAKMP

2026)

urging node 1554826523
*Oct 13 12:55:52.237: ISAKMP

2026):Input = IKE_MESG_INTERNAL, IKE_PHASE1_DEL
*Oct 13 12:55:52.237: ISAKMP

2026):Old State = IKE_XAUTH_REQ_SENT New State = IKE_DEST_SA
*Oct 13 12:55:52.241: ISAKMP

2026):deleting SA reason "No reason" state (R) CONF_XAUTH (peer 109.57.11.247)
*Oct 13 12:55:52.241: ISAKMP

0):Can't decrement IKE Call Admission Control stat incoming_active since it's already 0.
*Oct 13 12:55:52.241: ISAKMP: Unlocking peer struct 0x8814ED04 for isadb_mark_sa_deleted(), count 0
*Oct 13 12:55:52.241: ISAKMP: Deleting peer node by peer_reap for 109.57.11.247: 8814ED04
*Oct 13 12:55:52.241: ISAKMP

2026):deleting node -1846708170 error FALSE reason "IKE deleted"
*Oct 13 12:55:52.241: ISAKMP

2026):Input = IKE_MESG_FROM_PEER, IKE_MM_EXCH
*Oct 13 12:55:52.241: ISAKMP

2026):Old State = IKE_DEST_SA New State = IKE_DEST_SA
/Jesper