vpn problem at specific localtion

Jul 17, 2005 7 Replies

My notebook has VPN client 4.6. I 've used it in many place connecting back to my office 9 using c2811 as VPN terminaltor ) without any problem . At a specific location ( at a customer house ), I could not make the connection back to my office , but at the same time I am able to make the connection to another customer VPN concentrator.

The debug shows :

1861024: *Jul 16 15:06:06.865: ISAKMP:(0:295:HW:2):Total payload length: 12 1861025: *Jul 16 15:06:06.865: ISAKMP:(0:295:HW:2): sending packet to 69.22.33.131 my_port 500 peer_port 500 (R) AG_INIT_EXCH 1861026: *Jul 16 15:06:06.865: ISAKMP:(0:295:HW:2):Input = IKE_MESG_FROM_AAA, PRESHARED_KEY_REPLY 1861027: *Jul 16 15:06:06.869: ISAKMP:(0:295:HW:2):Old State = IKE_R_AM_AAA_AWAIT New State = IKE_R_AM2

1861028: *Jul 16 15:06:08.401: ISAKMP:(0:293:HW:2):purging SA., sa=474BE944, delme=474BE944

1861029: *Jul 16 15:06:11.901: ISAKMP (0:268435751): received packet from 69.22.33.131 dport 500 sport 500 Global (R) AG_INIT_EXCH 1861030: *Jul 16 15:06:11.901: ISAKMP:(0:295:HW:2): phase 1 packet is a duplicate of a previous packet. 1861031: *Jul 16 15:06:11.901: ISAKMP:(0:295:HW:2): retransmitting due to retransmit phase 1 1861032: *Jul 16 15:06:11.901: ISAKMP:(0:295:HW:2): retransmitting phase 1 AG_INIT_EXCH... 1861033: *Jul 16 15:06:12.401: ISAKMP:(0:295:HW:2): retransmitting phase 1 AG_INIT_EXCH... 1861034: *Jul 16 15:06:12.401: ISAKMP:(0:295:HW:2):incrementing error counter on sa: retransmit phase 1 1861035: *Jul 16 15:06:12.401: ISAKMP:(0:295:HW:2): retransmitting phase 1 AG_INIT_EXCH 1861036: *Jul 16 15:06:12.401: ISAKMP:(0:295:HW:2): sending packet to 69.22.33.131 my_port 500 peer_port 500 (R) AG_INIT_EXCH 1861037: *Jul 16 15:06:16.901: ISAKMP (0:268435751): received packet from 69.22.33.131 dport 500 sport 500 Global (R) AG_INIT_EXCH 1861038: *Jul 16 15:

Any advice is appreciated.

DT

My notebook has VPN client 4.6. I 've used it in many place connecting back to my office 9 using c2811 as VPN terminaltor ) without any problem . At a specific location ( at a customer house ), I could not make the connection back to my office , but at the same time I am able to make the connection to another customer VPN concentrator.



The debug shows :



1861024: *Jul 16 15:06:06.865: ISAKMP:(0:295:HW:2):Total payload length: 12
1861025: *
Jul 16 15:06:06.865: ISAKMP:(0:295:HW:2): sending packet to
69.22.33.131 my_port 500 peer_port 500 (R) AG_INIT_EXCH
1861026: *Jul 16 15:06:06.865: ISAKMP:(0:295:HW:2):Input = IKE_MESG_FROM_AAA, PRESHARED_KEY_REPLY
1861027: *
Jul 16 15:06:06.869: ISAKMP:(0:295:HW:2):Old State = IKE_R_AM_AAA_AWAIT New State = IKE_R_AM2


1861028: *Jul 16 15:06:08.401: ISAKMP:(0:293:HW:2):purging SA., sa=474BE944, delme=474BE944



1861029: *Jul 16 15:06:11.901: ISAKMP (0:268435751): received packet from 69.22.33.131 dport 500 sport 500 Global (R) AG_INIT_EXCH
1861030: *
Jul 16 15:06:11.901: ISAKMP:(0:295:HW:2): phase 1 packet is a duplicate of a previous packet.
1861031: *Jul 16 15:06:11.901: ISAKMP:(0:295:HW:2): retransmitting due to retransmit phase 1
1861032: *
Jul 16 15:06:11.901: ISAKMP:(0:295:HW:2): retransmitting phase 1 AG_INIT_EXCH...
1861033: *Jul 16 15:06:12.401: ISAKMP:(0:295:HW:2): retransmitting phase 1 AG_INIT_EXCH...
1861034: *
Jul 16 15:06:12.401: ISAKMP:(0:295:HW:2):incrementing error counter on sa: retransmit phase 1
1861035: *Jul 16 15:06:12.401: ISAKMP:(0:295:HW:2): retransmitting phase 1 AG_INIT_EXCH
1861036: *
Jul 16 15:06:12.401: ISAKMP:(0:295:HW:2): sending packet to
69.22.33.131 my_port 500 peer_port 500 (R) AG_INIT_EXCH
1861037: *Jul 16 15:06:16.901: ISAKMP (0:268435751): received packet from 69.22.33.131 dport 500 sport 500 Global (R) AG_INIT_EXCH
1861038: *
Jul 16 15:

Any advice is appreciated.



DT


What IOS version is running on Cisco 2811 ? It should be atleast

12.2(13)T to support Nat Tranparency .

Try connecting to c2811 from behind any NAT device ?

What device customer is using to do the Natting ?

VPN Concentrator supports Nat transparency of 3 kinds - udp , tcp and NAT-T (it's udp 4500)

Router only supports NaT-T (udp 4500)

HTH

Thanks for your reply.

It is 12.4.1a Advanced Enterprise.

Yes, my home network has a Linksys router with NAT and both my PC and notebook can VPN-ly connect to my office router without any problem. My home router does have NAT.

The customer uses some a linksys router with NAT, pretty similar to my home configuration.

MY Cisco client currently has NAT-T udp 4500 and it works almost everywhere until yesterday when I used it at my customer 's house.

Thanks,

DT

If you have enabled Nat transparency (on your client and c2811 )then disable "Ipsec- passthrough feature" on Linksys router .Then try .

HTH SH

Thanks for your reply.

My Linksys router at home has this feature on, and I have no problem connecting to my c2811 router.

DT

the above conversation tells me that there iss some ISP blockage. also the logs tell me the same.I know this may sound weird as you can connect to some other vpn device but please verifu wuth his ISP

Today I had a chance to install the VPN for another person that is next door to the first one, and this time it works fine. These two users are on the same ISP, they use the same logic to connect to the company ( they are the same company ) : notebook - wireless - access point - router - isp.

The only difference is the first user uses a pretty old router ( I was wrong, it is not a Linksys ) with one part of the connection has the wireless as a bridge. Next week I am going to replace her network system by a router similar to the one I just installed today.

Will post the result after that.

DT

Join the Discussion

Have something to add? Share your thoughts — no account required.

Didn't find your answer?

Ask the community — no account required