ASA 5505, l2tp server and windows XP

Hello,

All config is in local network environment. I've configured l2tp on CISCO ASA5505 but when i trying to connect from windows XP to this ASA and i've got messages:

Jan 07 22:38:19 [IKEv1 DEBUG]: Group = DefaultRAGroup, IP =

192.168.0.201, processing ID payload Jan 07 22:38:19 [IKEv1 DECODE]: Group = DefaultRAGroup, IP = 192.168.0.201, ID_IPV4_ADDR ID received 172.16.18.1 Jan 07 22:38:19 [IKEv1]: Group = DefaultRAGroup, IP = 192.168.0.201, Received local Proxy Host data in ID Payload: Address 172.16.18.1, Protocol 17, Port 1701 Jan 07 22:38:19 [IKEv1]: Group = DefaultRAGroup, IP = 192.168.0.201, L2TP/IPSec session detected. Jan 07 22:38:19 [IKEv1]: Group = DefaultRAGroup, IP = 192.168.0.201, QM IsRekeyed old sa not found by addr Jan 07 22:38:19 [IKEv1]: Group = DefaultRAGroup, IP = 192.168.0.201, IKE Remote Peer configured for crypto map: outside_dyn_map Jan 07 22:38:19 [IKEv1 DEBUG]: Group = DefaultRAGroup, IP = 192.168.0.201, processing IPSec SA payload Jan 07 22:38:19 [IKEv1 DEBUG]: Group = DefaultRAGroup, IP = 192.168.0.201, AH proposal not supported Jan 07 22:38:19 [IKEv1]: Group = DefaultRAGroup, IP = 192.168.0.201, All IPSec SA proposals found unacceptable!

Is there any way to do something with config on ASA or it is normal behaviour of l2tp over IPSec?

Reply to
Lukas
Loading thread data ...

Lukas > a écrit :

You should have these lines :

crypto ipsec transform-set TRANS_ESP_3DES_SHA esp-3des esp-sha-hmac crypto ipsec transform-set TRANS_ESP_3DES_SHA mode transport

..and maybe also the set included here :

crypto dynamic-map SYSTEM_DEFAULT_CRYPTO_MAP 65535 set transform-set TRANS_ESP_3DES_SHA ... ...

Then L2TP/IPSec will work fine. Try also Cisco documentation an guides.

Reply to
Jacques Virchaux

Cabling-Design.com Forums website is not affiliated with any of the manufacturers or service providers discussed here. All logos and trade names are the property of their respective owners.