Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations dencom on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Issue with pre-shared key...

Status
Not open for further replies.
Apr 17, 2006
27
US
A simple IPSEC tunnel is being set up between a Cisco 7200 router and a Cisco PIX firewall:

While using pre-shared authentication for the ISAKMP SA, this key is used: A3hU!q@Li9f$

The main mode exchange fails at the key exchange, and I receive sanity check failures - which usually points to a key mismatch.

If the key is changed to something simple, say "Key12345" it works okay.

I've double and doublechecked the config to make sure the keys were identical. I had 2 other network engineers confirm to make sure I wasnt hallucinating. Also, there are several other IPSEC tunnels on both peers with fairly complex keys similar to the one tried with.

My question is: are there any known issues with certain special characters that could cause this? has anyone seen this before?

As always, thank you very much.
 

Sounds like a software issue. You could do worse than trawl the Bug Toolkit on the CCO and try and locate a bug that matches the issue you are seeing.

Awhile ago, I saw a simialr issue with encrypted MD5 passwords with special characters establishing over BGP sessions.

If such a bug exists, the bug report will tell you which IOS versions are fixed and allow the use of special characters.
 
KiscoKid, thanks for your reply.

I couldnt find anything on the Buglist online..oh well..
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top