help with ipsect tunnel between 1700 routers

Hello I set up my ipsec tunel for some reason only the tunnel with our pix stays alive. all the other tunnels betweek 17xx routers come and go on this router. Can anyone explain what is going on? thanks

00:50:18: ISAKMP (0:5): processing SA payload. message ID = 997939343 00:50:18: ISAKMP (0:5): Checking IPSec proposal 1 00:50:18: ISAKMP: transform 1, ESP_3DES 00:50:18: ISAKMP: attributes in transform: 00:50:18: ISAKMP: encaps is 1 00:50:18: ISAKMP: SA life type in seconds 00:50:18: ISAKMP: SA life duration (basic) of 3600 00:50:18: ISAKMP: SA life type in kilobytes 00:50:18: ISAKMP: SA life duration (VPI) of 0x0 0x46 0x50 0x0 00:50:18: ISAKMP: authenticator is HMAC-MD5 00:50:18: ISAKMP (0:5): atts are acceptable. 00:50:18: ISAKMP (0:5): IPSec policy invalidated proposal 00:50:18: ISAKMP (0:5): phase 2 SA not acceptable! 00:50:18: ISAKMP (0:5): sending packet to x.x.x.x(R) QM_IDLE 00:50:18: ISAKMP (0:5): purging node 775745655 00:50:18: ISAKMP (0:5): Unknown Input for node 997939343: state = IKE_QM_READY, major = 0x00000001, minor = 0x0000000C

00:50:18: %CRYPTO-6-IKMP_MODE_FAILURE: Processing of Quick mode failed with peer at x.x.x.x

Reply to
jcharth
Loading thread data ...

In article , wrote: :Hello I set up my ipsec tunel for some reason only the tunnel with our :pix stays alive. all the other tunnels betweek 17xx routers come and go :on this router. Can anyone explain what is going on?

What happened when you tried my earlier suggestion of switching from MD5 to SHA ?

Reply to
Walter Roberson

I think my tunnel with the pix is the only one working, when i debug ipsec i get

00:41:03: IPSEC(encapsulate): error in encapsulation fs_encap_decap_fail 00:41:08: IPSEC(adjust_mtu): adjusting path mtu from 1500 to 1470, (identity) local= x.x.x.x, remote= x.x.x.x, local_proxy= 10.x.x.0/255.255.255.0/0/0 (type=4), remote_proxy= 10.x.x.0/255.255.255.0/0/0 (type=4)
Reply to
jcharth

Cabling-Design.com Forums website is not affiliated with any of the manufacturers or service providers discussed here. All logos and trade names are the property of their respective owners.