Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations SkipVought on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

ISAKMP error

Status
Not open for further replies.

kasser

Technical User
Jul 31, 2007
18
0
0
GB
Hi all, A working VPN is now not working, i think the problem is ISAKMP setting mismatch but the other side deny this. Below is the error I get can someone shed some more light on this.

crypto_isakmp_process_block:src:171.192.4.30, dest:195.224.52.2 spt:500 dpt:500
ISAKMP: phase 2 packet is a duplicate of a previous packet
ISAKMP: resending last response
crypto_isakmp_process_block:src:171.192.4.30, dest:195.224.52.2 spt:500 dpt:500
ISAKMP: phase 2 packet is a duplicate of a previous packeten
Password:
ISAKMP (0): retransmitting phase 2 (0/0)... mess_id 0x3278f95a
ISAKMP (0): retransmitting phase 2 (1/0)... mess_id 0x3278f95a
crypto_isakmp_process_block:src:171.192.4.30, dest:195.224.52.2 spt:500 dpt:500
ISAKMP (0): processing DELETE payload. message ID = 4210254529, spi size = 16
ISAKMP (0): deleting SA: src 171.192.4.30, dst 195.224.52.2
return status is IKMP_NO_ERR_NO_TRANS
ISADB: reaper checking SA 0x3d0c19c, conn_id = 0 DELETE IT!

VPN Peer: ISAKMP: Peer ip:171.192.4.30/500 Ref cnt decremented to:0 Total VPN Pe
ers:1
VPN Peer: ISAKMP: Deleted peer: ip:171.192.4.30/500 Total VPN peers:0IPSEC(key_e
ngine): got a queue event...
IPSEC(key_engine_delete_sas): rec'd delete notify from ISAKMP
IPSEC(key_engine_delete_sas): delete all SAs shared with 171.192.4.30
 
I have checked all settings and renetered the settings but still getting the same error. not sure why this is happening all of a sudden. From other checks the only one that I am concerned about is show crypto ipsec sa command this doesnt come up with anything and im not sure why? can some one help me please?
 
Can you post the configs of both ends? (Take out passwords and mask the middle 2 octets of the public IPs.)


Brent
Systems Engineer / Consultant
CCNP, CCSP
 
What type of firewall is on the other end? Cisco, Checkpoint?
Can you post a "debug crypto isakmp". Need to see the connection setup/negotiation.

 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top