cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
415
Views
0
Helpful
3
Replies

l2l vpn between cisco pix and vpn concentrator 3030

pklein222
Level 1
Level 1

l2l completes phase 1 but cannot seem to complete phase 2. A portion of the debug from the Pix is attached. Anyone got any ideas?

3 Replies 3

srue
Level 7
Level 7

possible transform set mismatch on phase 2.

in the pix, this will be the command's related to something like:

crypto map VPN 20 set transform-set 3desSHA

in the concentrator, it will be found on the main config page for a L2L setup under:

Encryption and Authentication (not the IKE Proposal setting)

or, in the concentrator

configuration--> policy mgmt -->traffic mgmt - SA's--> find the IPSEC SA for this connection and modify

I am thinking that as well. I have verified a couple of times the config on the concentrator, however, I only have part of what the other Pix has and something is bugging me. He setup his transform-set as IPSEC-3DES-MD5, instead of what I am used to seeing ESP-3DES-MD5. Personally never heard of IPSEC-3DES-MD5, however, I am no expert, just someone with some experience. What's your take on this?

Never mind my last post, it's just the name he gave his transform set. I took a look at his parameters again and he has used esp-3des esp-md5-hmac. Still trying to find the Phase 2 mismatch.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: