IPSec Tunnel Conn-ID Changes Frequently

Unanswered Question
Jul 21st, 2008
User Badges:

Hi NetPro,

I have an IPSec VPN between an IOS router (1841) and ISA. VPN is established and each LAN can access the other. From the end user point of view, no connectivity problems are experienced. But on the IOS router, 'show cryp is sa' shows the conn-id number is increasing frequently. Error message " %CRYPTO-6-IKMP_MODE_FAILURE: Processing of Quick mode failed with peer" and "%CRYPTO-4-IKMP_NO_SA: IKE message from x.x.x.x has no SA and is not an initialization offer" also come up on console.

'debug cry is' is attached.

Any advice is appreciated.


  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 4 (1 ratings)
smahbub Fri, 07/25/2008 - 06:25
User Badges:
  • Silver, 250 points or more

%CRYPTO-6-IKMP_MODE_FAILURE : Processing of [chars] mode failed with peer at [IP_address]

Explanation Negotiation with the remote peer has failed.

Recommended Action If this situation persists, contact the remote peer.

%CRYPTO-4-IKMP_NO_SA: IKE message from x.x.x.x has no SA

If this error message occurs in the IOS Router, the problem is that the SA has either expired or been cleared. The remote tunnel end device does not know that it uses the expired SA to send a packet (not a SA establishment packet). When a new SA has been established, the communication resumes, so initiate the interesting traffic across the tunnel to create a new SA and re-stablish the tunnel.


This Discussion