VPN conncetion via PIX 501

Unanswered Question
Feb 2nd, 2007

Hello,

I got a problem with a Cisco PIX 501.

The network equipment changed (Modem) and also the IP Addresses.

I changed the IP Addresses on the PIX and on our concentrator where the vpn tunnel will be terminated.

So the modem/router is configured with 2 offical IP Addresses - one on the outside and one on the inside connection.

he pix also got an offical IP Address from the same network.

Internet is working - I can ping from the pix to any offical IP?s.

When the pix tries to establish the vpn connection, I got this error message on the concentrator:

13180 02/02/2007 14:05:09.620 SEV=4 IKEDBG/65 RPT=22091 <IP OF THE PIX>

IKE MM Initiator FSM error history (struct &0x3badffc)

<state>, <event>:

MM_DONE, EV_ERROR

MM_WAIT_MSG2, EV_RETRY

MM_WAIT_MSG2, EV_TIMEOUT

MM_WAIT_MSG2, NullEvent

What can be the problem ?

I?ll try to reach the pix via telnet and I will then post the output of crypto ipsec

Best regards

Kai

I have this problem too.
0 votes
  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Loading.
ggilbert Fri, 02/02/2007 - 10:11

Kai,

Complete debugs/config from the concentrator the PIX would be a start in the right direction

deb cry isa

deb cry ipsec

Thanks

Gilbert

Actions

This Discussion