Hi All, When I configured site to site VPN between Cisco ASA 5500 (outside IP address: 1.2.3.4, inside ip: 192.168.0.50) and 1800 router (outside IP address 5.6.7.8, inside ip: 192.168.46.1), I got the following error and can not establish VPN tunnel:
- Error on ASA 5500:
|11:45:35|713904|||IP = 5.6.7.8, Received encrypted packet with no matching SA, dropping |11:45:35|113019|||Group = 5.6.7.8, Username = 5.6.7.8, IP = 5.6.7.8, Session disconnected. Session Type: IPSecLAN2LAN, Duration: 0h:00m:
00s, Bytes xmt: 0, Bytes rcv: 0, Reason: Phase 2 Mismatch |11:45:35|713902|||Group = 5.6.7.8, IP = 5.6.7.8, Removing peer from correlator table failed, no match! |11:45:35|713902|||Group = 5.6.7.8, IP = 5.6.7.8, QM FSM error (P2 struct &0x97f6d50, mess id 0xba4d2406)! |11:45:35|713904|||Group = 5.6.7.8, IP = 5.6.7.8, All IPSec SA proposals found unacceptable! |11:45:35|713119|||Group = 5.6.7.8, IP = 5.6.7.8, PHASE 1 COMPLETED |11:45:35|113009|||AAA retrieved default group policy (LAN-LAN) for user = 5.6.7.8 |11:45:35|713903|||Group = 5.6.7.8, IP = 5.6.7.8, Freeing previously allocated memory for authorization-dn-attributes |11:45:35|713172|||Group = 5.6.7.8, IP = 5.6.7.8, Automatic NAT Detection Status: Remote end is NOT behind a NAT device This end is NOT behind a NAT device
- Debug info on 1800 router:
13:28:50 Local7.Debug 192.168.46.1 2448:
13:28:50 Local7.Debug 192.168.46.1 2447:
*Jan 4 18:29:17.255: ISAKMP: (2018):Old State = IKE_DEST_SA New State = IKE_DEST_SA 13:28:50 Local7.Debug 192.168.46.1 2446: *Jan 4 18:29:17.255: ISAKMP: (2018):Input = IKE_MESG_FROM_PEER, IKE_MM_EXCH 13:28:50 Local7.Debug 192.168.46.1 2445:
*Jan 4 18:29:17.255: crypto_engine: Delete IKE SA 13:28:50 Local7.Debug 192.168.46.1 2444: *Jan 4 18:29:17.251: crypto engine: deleting IKE SA SW:18 13:28:50 Local7.Debug 192.168.46.1 2443:
*Jan 4 18:29:17.251: ISAKMP: (2018):deleting node 853657057 error FALSE reason "IKE deleted" 13:28:49 Local7.Debug 192.168.46.1 2442: *Jan 4 18:29:17.251: ISAKMP: (2018):deleting node -533182858 error FALSE reason "IKE deleted" 13:28:49 Local7.Debug 192.168.46.1 2441:
*Jan 4 18:29:17.251: ISAKMP: (2018):deleting node 28797199 error FALSE reason "IKE deleted" 13:28:49 Local7.Debug 192.168.46.1 2440: *Jan 4 18:29:17.251: ISAKMP: (2018):deleting SA reason "No reason" state (I) QM_IDLE (peer
1.2.3.4) 13:28:49 Local7.Debug 192.168.46.1 2439: 13:28:49 Local7.Debug 192.168.46.1 2438:
*Jan 4 18:29:17.251: ISAKMP: (2018):Old State = IKE_P1_COMPLETE New State = IKE_DEST_SA 13:28:49 Local7.Debug 192.168.46.1 2437: *Jan 4 18:29:17.251: ISAKMP: (2018):Input = IKE_MESG_INTERNAL, IKE_PHASE1_DEL 13:28:49 Local7.Debug 192.168.46.1 2436:
*Jan 4 18:29:17.251: ISAKMP: (2018):purging node -751303044 13:28:49 Local7.Debug 192.168.46.1 2435: *Jan 4 18:29:17.251: ISAKMP: (2018):Sending an IKE IPv4 Packet. 13:28:49 Local7.Debug 192.168.46.1 2434:
*Jan 4 18:29:17.251: ISAKMP: (2018): sending packet to 1.2.3.4 my_port 500 peer_port 500 (I) QM_IDLE 13:28:49 Local7.Debug 192.168.46.1 2433: *Jan 4 18:29:17.251: crypto_engine: Encrypt IKE packet 13:28:49 Local7.Debug 192.168.46.1 2432:
*Jan 4 18:29:17.251: crypto_engine: Generate IKE hash 13:28:49 Local7.Debug 192.168.46.1 2431: *Jan 4 18:29:17.251: ISAKMP: set new node -751303044 to QM_IDLE 13:28:49 Local7.Debug 192.168.46.1 2430:
*Jan 4 18:29:17.251: ISAKMP: (2018):deleting node 853657057 error FALSE reason "Informational (in) state 1" 13:28:49 Local7.Debug 192.168.46.1 2429: *Jan 4 18:29:17.251: ISAKMP: (2018):deleting SA reason "No reason" state (I) QM_IDLE (peer
1.2.3.4) 13:28:49 Local7.Debug 192.168.46.1 2428: 13:28:49 Local7.Debug 192.168.46.1 2427:
*Jan 4 18:29:17.251: ISAKMP: (2018):peer does not do paranoid keepalives. 13:28:49 Local7.Debug 192.168.46.1 2426: *Jan 4 18:29:17.251: ISAKMP: (2018): processing DELETE payload. message ID = 853657057 13:28:49 Local7.Debug 192.168.46.1 2425:
*Jan 4 18:29:17.251: ISAKMP: (2018): processing HASH payload. message ID = 853657057 13:28:49 Local7.Debug 192.168.46.1 2424: *Jan 4 18:29:17.251: crypto_engine: Generate IKE hash 13:28:49 Local7.Debug 192.168.46.1 2423:
*Jan 4 18:29:17.251: crypto_engine: Decrypt IKE packet 13:28:49 Local7.Debug 192.168.46.1 2422: *Jan 4 18:29:17.251: ISAKMP: set new node 853657057 to QM_IDLE 13:28:49 Local7.Debug 192.168.46.1 2421:
*Jan 4 18:29:17.251: ISAKMP (0:2018): received packet from 1.2.3.4 dport 500 sport 500 Global (I) QM_IDLE 13:28:49 Local7.Debug 192.168.46.1 2420: 13:28:49 Local7.Debug 192.168.46.1 2419: *Jan 4 18:29:17.251: ISAKMP: (2018):Old State = IKE_P1_COMPLETE New State = IKE_P1_COMPLETE
13:28:49 Local7.Debug 192.168.46.1 2418:
*Jan 4 18:29:17.251: ISAKMP: (2018):Input = IKE_MESG_FROM_PEER, IKE_INFO_NOTIFY 13:28:49 Local7.Debug 192.168.46.1 2417: *Jan 4 18:29:17.251: ISAKMP: (2018):deleting node -533182858 error FALSE reason "Informational (in) state 1" 13:28:49 Local7.Debug 192.168.46.1 2416: spi 0, message ID =
-533182858, sa = 84B02BB0 13:28:49 Local7.Debug 192.168.46.1 2415: *Jan 4 18:29:17.251: ISAKMP: (2018): processing NOTIFY PROPOSAL_NOT_CHOSEN protocol 3 13:28:49 Local7.Debug 192.168.46.1 2414: *Jan 4 18:29:17.251: ISAKMP: (2018): processing HASH payload. message ID = -533182858 13:28:49 Local7.Debug 192.168.46.1 2413: *Jan 4 18:29:17.251: crypto_engine: Generate IKE hash 13:28:49 Local7.Debug 192.168.46.1 2412: *Jan 4 18:29:17.251: crypto_engine: Decrypt IKE packet 13:28:49 Local7.Debug 192.168.46.1 2411: *Jan 4 18:29:17.247: ISAKMP: set new node -533182858 to QM_IDLE
13:28:49 Local7.Debug 192.168.46.1 2410: *Jan 4 18:29:17.247: ISAKMP (0:2018): received packet from 1.2.3.4 dport 500 sport 500 Global (I) QM_IDLE
I compared IPsec, IKE site to site VPN setting on both end using ASDM/ SDM, I can not find any different, but it still show me the same error messages. I appreciate if some one can help out this.
Thank you, Young