anthavpn in PDA try to connect with a 1701 router

Unanswered Question

Hi, I trying to use a PDA with the anthavpn software to connect IPSec with a 1701 router. The clients work fine with the cisco vpn client in a PC, but I can't manage to work with the anthavpn.

I get this output wiht the debug crypto isakmp command but I don't understand it:

*May 16 00:00:56.746: ISAKMP:(0:0:N/A:0):Checking ISAKMP transform 7 against pri

ority 1 policy

*May 16 00:00:56.746: ISAKMP: encryption 3DES-CBC

*May 16 00:00:56.746: ISAKMP: hash SHA

*May 16 00:00:56.746: ISAKMP: default group 2

*May 16 00:00:56.746: ISAKMP: auth XAUTHInitPreShared

*May 16 00:00:56.746: ISAKMP: life type in seconds

*May 16 00:00:56.746: ISAKMP: life duration (basic) of 3600

*May 16 00:00:56.746: ISAKMP:(0:0:N/A:0):atts are acceptable. Next payload is 3

*May 16 00:00:56.966: ISAKMP:(0:2:SW:1): processing KE payload. message ID = 0

*May 16 00:00:57.238: ISAKMP:(0:2:SW:1): processing NONCE payload. message ID =

0

*May 16 00:00:57.238: ISAKMP:(0:2:SW:1): vendor ID is NAT-T v2

*May 16 00:00:57.242: ISAKMP:(0:2:SW:1):Input = IKE_MESG_FROM_PEER, IKE_AM_EXCH

*May 16 00:00:57.242: ISAKMP:(0:2:SW:1):Old State = IKE_READY New State = IKE_R

_AM_AAA_AWAIT

*May 16 00:00:57.246: ISAKMP:(0:2:SW:1):SKEYID state generated

*May 16 00:00:57.250: ISAKMP:(0:2:SW:1): constructed NAT-T vendor-02 ID

*May 16 00:00:57.250: ISAKMP:(0:2:SW:1):SA is doing pre-shared key authenticatio

n plus XAUTH using id type ID_IPV4_ADDR

*May 16 00:00:57.250: ISAKMP (0:134217730): ID payload

next-payload : 10

type : 1

address : 217.127.66.92

protocol : 17

port : 0

length : 12

*May 16 00:00:57.250: ISAKMP:(0:2:SW:1):Total payload length: 12

*May 16 00:00:57.250: ISAKMP:(0:2:SW:1): sending packet to 212.81.207.2 my_port

500 peer_port 54865 (R) AG_INIT_EXCH

*May 16 00:00:57.254: ISAKMP:(0:2:SW:1):Input = IKE_MESG_FROM_AAA, PRESHARED_KEY

_REPLY

*May 16 00:00:57.254: ISAKMP:(0:2:SW:1):Old State = IKE_R_AM_AAA_AWAIT New Stat

e = IKE_R_AM2

*May 16 00:01:02.138: ISAKMP (0:134217730): received packet from 212.81.207.2 dp

ort 500 sport 54865 Global (R) AG_INIT_EXCH

*May 16 00:01:02.138: ISAKMP:(0:2:SW:1): phase 1 packet is a duplicate of a prev

ious packet.

*May 16 00:01:02.142: ISAKMP:(0:2:SW:1): retransmitting due to retransmit phase

1

*May 16 00:01:02.142: ISAKMP:(0:2:SW:1): retransmitting phase 1 AG_INIT_EXCH...

*May 16 00:01:02.642: ISAKMP:(0:2:SW:1): retransmitting phase 1 AG_INIT_EXCH...

*May 16 00:01:02.642: ISAKMP:(0:2:SW:1):incrementing error counter on sa: retran

smit phase 1

*May 16 00:01:02.642: ISAKMP:(0:2:SW:1): retransmitting phase 1 AG_INIT_EXCH

*May 16 00:01:02.642: ISAKMP:(0:2:SW:1): sending packet to 212.81.207.2 my_port

500 peer_port 54865 (R) AG_INIT_EXCH

*May 16 00:01:07.650: ISAKMP (0:134217730): received packet from 212.81.207.2 dp

ort 500 sport 54865 Global (R) AG_INIT_EXCH

*May 16 00:01:07.654: ISAKMP:(0:2:SW:1): phase 1 packet is a duplicate of a prev

ious packet.

*May 16 00:01:07.654: ISAKMP:(0:2:SW:1): retransmitting due to retransmit phase

1

*May 16 00:01:07.654: ISAKMP:(0:2:SW:1): retransmitting phase 1 AG_INIT_EXCH...

*May 16 00:01:08.258: ISAKMP:(0:2:SW:1): retransmitting phase 1 AG_INIT_EXCH...

*May 16 00:01:08.258: ISAKMP:(0:2:SW:1):incrementing error counter on sa: retran

smit phase 1

*May 16 00:01:08.258: ISAKMP:(0:2:SW:1): retransmitting phase 1 AG_INIT_EXCH

*May 16 00:01:08.262: ISAKMP:(0:2:SW:1): sending packet to 212.81.207.2 my_port

500 peer_port 54865 (R) AG_INIT_EXCH

*May 16 00:01:12.974: ISAKMP (0:134217730): received packet from 212.81.207.2 dp

ort 500 sport 54865 Global (R) AG_INIT_EXCH

*May 16 00:01:12.974: ISAKMP:(0:2:SW:1): phase 1 packet is a duplicate of a prev

ious packet.

*May 16 00:01:12.978: ISAKMP:(0:2:SW:1): retransmitting due to retransmit phase

1

*May 16 00:01:12.978: ISAKMP:(0:2:SW:1): retransmitting phase 1 AG_INIT_EXCH...

Can anybody help me?

Thanks

I have this problem too.
0 votes
  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Loading.
smahbub Thu, 05/24/2007 - 10:55

Check for router IOS version as earlier versions had some bugs which may cause this problem. Upgrading the router to version 12.4(4)T and above may resolve this issue. Following links may help you

http://www.cisco.com/en/US/tech/tk583/tk372/technologies_configuration_example09186a0080095106.shtml

http://www.cisco.com/en/US/tech/tk583/tk372/technologies_configuration_example09186a00800945cf.shtml

Actions

This Discussion