cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1421
Views
0
Helpful
2
Replies

site to site vpn asa and checkpoint

melatisariindah
Level 1
Level 1

I have already configured vpn site to site asa and checkpoint. If I show isakmp sa, the state is active. But everytime packet is delivered, there is some message from asa :

Sep 03 11:37:00 [IKEv1]: Group = <IP Checkpoint>, IP = <IP Checkpoint>, QM FSM error (P2 struct &0xc93a87c8, mess id 0x9c4ac0f)!

Sep 03 11:37:00 [IKEv1]: Group = <IP Checkpoint>, IP = <IP Checkpoint>, Removing peer from correlator table failed, no match!

Can anyone tell me what the meaning of that message error?

Thx,

msi

2 Replies 2

grant.maynard
Level 4
Level 4

From http://www.cisco.com/en/US/tech/tk583/tk372/technologies_tech_note09186a00800949c5.shtml#qms:

One possible reason is the proxy identities, such as interesting traffic, Access Control List (ACL) or crypto ACL, do not match on both the ends. Check the configuration on both the devices, and make sure that the crypto ACLs match.

This is an IKE phase 1 error, you need to check what the remote end is using as identity, IP Address or Certifate.

Also check what you are using for your IKE identity.

HTH>

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: