Hi folks
I have a problem. I try connect Cisco 3620 and Linksys RV042 by site-to-site VPN and I can't establish 1 phase of ISAKMP.
This is output from debug of isakmp error:
router#
4d07h: ISAKMP (0:0): received packet from 83.17.159.254 dport 500 sport 500 Glob
al (N) NEW SA
4d07h: ISAKMP: Created a peer struct for 83.17.159.254, peer port 500
4d07h: ISAKMP: Locking peer struct 0x630776D4, IKE refcount 1 for crypto_ikmp_co
nfig_initialize_sa
4d07h: ISAKMP (0:0): Setting client config settings 62C50FF0
4d07h: ISAKMP: local port 500, remote port 500
4d07h: ISAKMP: Find a dup sa in the avl tree during calling isadb_insert sa = 62
A55DF0
4d07h: ISAKMP (0:4): Input = IKE_MESG_FROM_PEER, IKE_MM_EXCH
4d07h: ISAKMP (0:4): Old State = IKE_READY New State = IKE_R_MM1
4d07h: ISAKMP (0:4): processing SA payload. message ID = 0
4d07h: ISAKMP (0:4): processing vendor id payload
4d07h: ISAKMP (0:4): vendor ID is DPD
4d07h: ISAKMP: Looking for a matching key for 83.17.159.254 in default : success
4d07h: ISAKMP (0:4): found peer pre-shared key matching 83.17.159.254
4d07h: ISAKMP (0:4) local preshared key found
4d07h: ISAKMP : Scanning profiles for xauth ...
4d07h: ISAKMP (0:4): Checking ISAKMP transform 0 against priority 3 policy
4d07h: ISAKMP: life type in seconds
4d07h: ISAKMP: life duration (basic) of 28800
4d07h: ISAKMP: encryption DES-CBC
4d07h: ISAKMP: hash SHA
4d07h: ISAKMP: auth pre-share
4d07h: ISAKMP: default group 2
4d07h: ISAKMP (0:4): atts are acceptable. Next payload is 0
4d07h: ISAKMP (0:4): processing vendor id payload
4d07h: ISAKMP (0:4): vendor ID is DPD
4d07h: ISAKMP (0:4): Input = IKE_MESG_INTERNAL, IKE_PROCESS_MAIN_MODE
4d07h: ISAKMP (0:4): Old State = IKE_R_MM1 New State = IKE_R_MM1
4d07h: ISAKMP: Error: payload length of VENDOR 0 < 4
4d07h: ISAKMP (0:4): sending packet to 83.17.159.254 my_port 500 peer_port 500 (
R) MM_SA_SETUP
4d07h: ISAKMP (0:4): Input = IKE_MESG_INTERNAL, IKE_PROCESS_COMPLETE
4d07h: ISAKMP (0:4): Old State = IKE_R_MM1 New State = IKE_R_MM2
4d07h: ISAKMP (0:4): received packet from 83.17.159.254 dport 500 sport 500 Glob
al (R) MM_SA_SETUP
4d07h: ISAKMP (0:4): phase 1 packet is a duplicate of a previous packet.
4d07h: ISAKMP (0:4): retransmitting due to retransmit phase 1
4d07h: ISAKMP (0:4): retransmitting phase 1 MM_SA_SETUP...
4d07h: ISAKMP (0:4): retransmitting phase 1 MM_SA_SETUP...
4d07h: ISAKMP (0:4): incrementing error counter on sa: retransmit phase 1
4d07h: ISAKMP (0:4): retransmitting phase 1 MM_SA_SETUP
4d07h: ISAKMP (0:4): sending packet to 83.17.159.254 my_port 500 peer_port 500 (
R) MM_SA_SETUP
4d07h: ISAKMP (0:4): retransmitting phase 1 MM_SA_SETUP...
4d07h: ISAKMP (0:4): incrementing error counter on sa: retransmit phase 1
4d07h: ISAKMP (0:4): retransmitting phase 1 MM_SA_SETUP
4d07h: ISAKMP (0:4): sending packet to 83.17.159.254 my_port 500 peer_port 500 (
R) MM_SA_SETUP
4d07h: ISAKMP (0:4): retransmitting phase 1 MM_SA_SETUP...
4d07h: ISAKMP (0:4): incrementing error counter on sa: retransmit phase 1
4d07h: ISAKMP (0:4): retransmitting phase 1 MM_SA_SETUP
4d07h: ISAKMP (0:4): sending packet to 83.17.159.254 my_port 500 peer_port 500 (
R) MM_SA_SETUP
4d07h: ISAKMP (0:4): received packet from 83.17.159.254 dport 500 sport 500 Glob
everything is well until this line:
4d07h: ISAKMP: Error: payload length of VENDOR 0 < 4
I search many site but i can't find any explain of this error.
thanks for any help
regards
Mac foxx
I have a problem. I try connect Cisco 3620 and Linksys RV042 by site-to-site VPN and I can't establish 1 phase of ISAKMP.
This is output from debug of isakmp error:
router#
4d07h: ISAKMP (0:0): received packet from 83.17.159.254 dport 500 sport 500 Glob
al (N) NEW SA
4d07h: ISAKMP: Created a peer struct for 83.17.159.254, peer port 500
4d07h: ISAKMP: Locking peer struct 0x630776D4, IKE refcount 1 for crypto_ikmp_co
nfig_initialize_sa
4d07h: ISAKMP (0:0): Setting client config settings 62C50FF0
4d07h: ISAKMP: local port 500, remote port 500
4d07h: ISAKMP: Find a dup sa in the avl tree during calling isadb_insert sa = 62
A55DF0
4d07h: ISAKMP (0:4): Input = IKE_MESG_FROM_PEER, IKE_MM_EXCH
4d07h: ISAKMP (0:4): Old State = IKE_READY New State = IKE_R_MM1
4d07h: ISAKMP (0:4): processing SA payload. message ID = 0
4d07h: ISAKMP (0:4): processing vendor id payload
4d07h: ISAKMP (0:4): vendor ID is DPD
4d07h: ISAKMP: Looking for a matching key for 83.17.159.254 in default : success
4d07h: ISAKMP (0:4): found peer pre-shared key matching 83.17.159.254
4d07h: ISAKMP (0:4) local preshared key found
4d07h: ISAKMP : Scanning profiles for xauth ...
4d07h: ISAKMP (0:4): Checking ISAKMP transform 0 against priority 3 policy
4d07h: ISAKMP: life type in seconds
4d07h: ISAKMP: life duration (basic) of 28800
4d07h: ISAKMP: encryption DES-CBC
4d07h: ISAKMP: hash SHA
4d07h: ISAKMP: auth pre-share
4d07h: ISAKMP: default group 2
4d07h: ISAKMP (0:4): atts are acceptable. Next payload is 0
4d07h: ISAKMP (0:4): processing vendor id payload
4d07h: ISAKMP (0:4): vendor ID is DPD
4d07h: ISAKMP (0:4): Input = IKE_MESG_INTERNAL, IKE_PROCESS_MAIN_MODE
4d07h: ISAKMP (0:4): Old State = IKE_R_MM1 New State = IKE_R_MM1
4d07h: ISAKMP: Error: payload length of VENDOR 0 < 4
4d07h: ISAKMP (0:4): sending packet to 83.17.159.254 my_port 500 peer_port 500 (
R) MM_SA_SETUP
4d07h: ISAKMP (0:4): Input = IKE_MESG_INTERNAL, IKE_PROCESS_COMPLETE
4d07h: ISAKMP (0:4): Old State = IKE_R_MM1 New State = IKE_R_MM2
4d07h: ISAKMP (0:4): received packet from 83.17.159.254 dport 500 sport 500 Glob
al (R) MM_SA_SETUP
4d07h: ISAKMP (0:4): phase 1 packet is a duplicate of a previous packet.
4d07h: ISAKMP (0:4): retransmitting due to retransmit phase 1
4d07h: ISAKMP (0:4): retransmitting phase 1 MM_SA_SETUP...
4d07h: ISAKMP (0:4): retransmitting phase 1 MM_SA_SETUP...
4d07h: ISAKMP (0:4): incrementing error counter on sa: retransmit phase 1
4d07h: ISAKMP (0:4): retransmitting phase 1 MM_SA_SETUP
4d07h: ISAKMP (0:4): sending packet to 83.17.159.254 my_port 500 peer_port 500 (
R) MM_SA_SETUP
4d07h: ISAKMP (0:4): retransmitting phase 1 MM_SA_SETUP...
4d07h: ISAKMP (0:4): incrementing error counter on sa: retransmit phase 1
4d07h: ISAKMP (0:4): retransmitting phase 1 MM_SA_SETUP
4d07h: ISAKMP (0:4): sending packet to 83.17.159.254 my_port 500 peer_port 500 (
R) MM_SA_SETUP
4d07h: ISAKMP (0:4): retransmitting phase 1 MM_SA_SETUP...
4d07h: ISAKMP (0:4): incrementing error counter on sa: retransmit phase 1
4d07h: ISAKMP (0:4): retransmitting phase 1 MM_SA_SETUP
4d07h: ISAKMP (0:4): sending packet to 83.17.159.254 my_port 500 peer_port 500 (
R) MM_SA_SETUP
4d07h: ISAKMP (0:4): received packet from 83.17.159.254 dport 500 sport 500 Glob
everything is well until this line:
4d07h: ISAKMP: Error: payload length of VENDOR 0 < 4
I search many site but i can't find any explain of this error.
thanks for any help
regards
Mac foxx