Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations strongm on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

ISAKMP error message

Status
Not open for further replies.

sunyasee

ISP
Apr 8, 2002
94
GB
Hi,

I am trying to setup a VPN configuration from a Pix 515 to another VPN device. I receive the following error message..

crypto_isakmp_process_block:src:1xx.xxx.xxx.123, dest:2xx.xxx.xxx.125 spt:500 dpt:500
ISAKMP: phase 2 packet is a duplicate of a previous packet
ISAKMP: resending last response
crypto_isakmp_process_block:src:1xx.xxx.xxx.123, dest:2xx.xxx.xxx.125 spt:500 dpt:500
ISAKMP: sa not found for ike msg

Is this error refering to my end or the other device? I am 100% sure my config is correct, there are other VPNs configured on the PIX that are working fine.

Sometimes the tunnel is negotiated, and I can see an entry when I do a 'show crypto isakmp sa' but the tunnel is dropped after a few minutes. Any ideas what this error could mean?

Thanks

----

Sunyasee
 
My initial guess: It's not in ISAKMP but in IPSEC. Tht would explain why a "show isakmp sa" looks good temporarily, then drops. Perhaps your IPSEC security association attributes are not matching up between the two devices, or the network lists on both ends do not match?
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top