ASA 5505, l2tp server and windows XP

Jan 07, 2009 1 Replies

Hello,



All config is in local network environment. I've configured l2tp on CISCO ASA5505 but when i trying to connect from windows XP to this ASA and i've got messages:



Jan 07 22:38:19 [IKEv1 DEBUG]: Group = DefaultRAGroup, IP =



192.168.0.201, processing ID payload Jan 07 22:38:19 [IKEv1 DECODE]: Group = DefaultRAGroup, IP =
192.168.0.201, ID_IPV4_ADDR ID received
172.16.18.1 Jan 07 22:38:19 [IKEv1]: Group = DefaultRAGroup, IP = 192.168.0.201, Received local Proxy Host data in ID Payload: Address 172.16.18.1, Protocol 17, Port 1701 Jan 07 22:38:19 [IKEv1]: Group = DefaultRAGroup, IP = 192.168.0.201, L2TP/IPSec session detected. Jan 07 22:38:19 [IKEv1]: Group = DefaultRAGroup, IP = 192.168.0.201, QM IsRekeyed old sa not found by addr Jan 07 22:38:19 [IKEv1]: Group = DefaultRAGroup, IP = 192.168.0.201, IKE Remote Peer configured for crypto map: outside_dyn_map Jan 07 22:38:19 [IKEv1 DEBUG]: Group = DefaultRAGroup, IP =
192.168.0.201, processing IPSec SA payload Jan 07 22:38:19 [IKEv1 DEBUG]: Group = DefaultRAGroup, IP =
192.168.0.201, AH proposal not supported Jan 07 22:38:19 [IKEv1]: Group = DefaultRAGroup, IP = 192.168.0.201, All IPSec SA proposals found unacceptable!

Is there any way to do something with config on ASA or it is normal behaviour of l2tp over IPSec?


Lukas > a écrit :

You should have these lines :

crypto ipsec transform-set TRANS_ESP_3DES_SHA esp-3des esp-sha-hmac crypto ipsec transform-set TRANS_ESP_3DES_SHA mode transport

..and maybe also the set included here :

crypto dynamic-map SYSTEM_DEFAULT_CRYPTO_MAP 65535 set transform-set TRANS_ESP_3DES_SHA ... ...

Then L2TP/IPSec will work fine. Try also Cisco documentation an guides.

Join the Discussion

Have something to add? Share your thoughts — no account required.

Didn't find your answer?

Ask the community — no account required