Reason 412: The remote peer is no longer responding.

Feb 10, 2006 25 Replies

lost the last response!

I can only see the 857 log, I have no text equivalent to copy and paste. It only has 5 info records the last being:

Processing of Quick mode failed with peer at "my pc's ip"

But here is the log of the client with IKE set to medium. I changed the group key on both. Cisco Systems VPN Client Version 4.6.00.0045 Copyright (C) 1998-2004 Cisco Systems, Inc. All Rights Reserved. Client Type(s): Windows, WinNT Running on: 5.1.2600 Service Pack 2

1 16:12:21.348 02/14/06 Sev=Warning/3 GUI/0xE3B00003 GI EnumPPP callback timed out.

Cisco Systems VPN Client Version 4.6.00.0045 Copyright (C) 1998-2004 Cisco Systems, Inc. All Rights Reserved. Client Type(s): Windows, WinNT Running on: 5.1.2600 Service Pack 2 Config file directory: C:\\Program Files\\Cisco Systems\\VPN Client

1 16:14:50.652 02/14/06 Sev=Info/4 IKE/0x63000013 SENDING >>> ISAKMP OAK AG (SA, KE, NON, ID, VID(Xauth), VID(dpd), VID(Nat-T), VID(Frag), VID(Unity)) to 80.177.223.54

2 16:14:50.732 02/14/06 Sev=Info/4 IKE/0x63000014 RECEIVING > ISAKMP OAK AG *(HASH, NOTIFY:STATUS_INITIAL_CONTACT, NAT-D, NAT-D, VID(?), VID(Unity)) to 80.177.223.54

4 16:14:50.742 02/14/06 Sev=Info/4 IKE/0x63000082 IKE Port in use - Local Port = 0x01F4, Remote Port = 0x01F4

5 16:14:50.752 02/14/06 Sev=Info/4 IKE/0x63000014 RECEIVING > ISAKMP OAK TRANS *(HASH, ATTR) to 80.177.223.54

13 16:14:57.222 02/14/06 Sev=Info/4 IKE/0x63000014 RECEIVING > ISAKMP OAK QM *(HASH, SA, NON, ID, ID) to 80.177.223.54

16 16:14:57.542 02/14/06 Sev=Info/4 IKE/0x63000014 RECEIVING > ISAKMP OAK INFO *(HASH, DEL) to 80.177.223.54

18 16:14:57.552 02/14/06 Sev=Info/4 IKE/0x63000048 Discarding IPsec SA negotiation, MsgID=CABD5A7C

19 16:14:57.552 02/14/06 Sev=Info/4 IKE/0x63000017 Marking IKE SA for deletion (I_Cookie=5ED0E3343207D013 R_Cookie=E82601E7412816C6) reason = DEL_REASON_IKE_NEG_FAILED

20 16:15:00.957 02/14/06 Sev=Info/4 IKE/0x6300004A Discarding IKE SA negotiation (I_Cookie=5ED0E3343207D013 R_Cookie=E82601E7412816C6) reason = DEL_REASON_IKE_NEG_FAILED

21 16:15:01.037 02/14/06 Sev=Info/4 IKE/0x63000001 IKE received signal to terminate VPN connection

Try deleting crypto policy 1 and changing the hash on policy 2 from MD5 to sha so that it matches with the transform set.

Do this with the command line interface from the console not any Cisco GUI.

How? I'm not familiar with any CLI and don't know the commands! Sorry. If you could point to the prog that would be great.

To save time I did use the GUI and it seems that DES3 will work because if using DES I get Peer not reponding - don't even get log on option. Changing 2 to sha and DES3 has not changed the error which I think is related to one of the log entries:

NOTIFY:NO_PROPOSAL_CHOSEN

whatever that means! Thanks for perservering.

Going home to try connecting from there, just in case. What is trying to take place that fails? It seems that we have established the security policy as we then move on to establishing the "Securing communications channel" bit - or is this like coding where to fix an error it can often be in the line above?!

Will let you know how I get on tonight... thanks again.

When connecting from home I don't even get offered to enter my username & pwd...

Join the Discussion

Have something to add? Share your thoughts — no account required.

Didn't find your answer?

Ask the community — no account required