IPSEC: reserved not zero on payload message when connecting site-to-site

I finally managed to implement a Site-to-Site tunnel using IPSEC between ISA back-to-back on one site and and a PIX on the other.

When testing I noticed that it takes some time to establish the connection. Debug showed the following message several times during negotiating: "ISAKMP: reserved not zero on payload 8!" "ISAKMP: malformed payload"

This message comes up serveral times and then finally the connection starts working. Cisco stated that this message means that the shared key does not match however, I cheked this (of course) and still the message comes up. Both in the end the tunnel comes up and traffic is allowed and works.

The problem here is the relative long time needed to establish the tunnel causes time-out problems on applications (RDP e.g.)

I already tried to disable PFS and also checked IKE timers etc.

Does anyone know the solution for this.

Reply to
Arjan
Loading thread data ...

Does the hash algorihmn configured for each peer match?

Reply to
Merv

meaning ESP-DES-MD5 for stage one and two? Yes they do, however PIX also has policy for ESP-DES-SHA that is not used at the moment.

Reply to
Arjan

Cabling-Design.com Forums website is not affiliated with any of the manufacturers or service providers discussed here. All logos and trade names are the property of their respective owners.