03-19-2009 11:07 PM
Hi, I have a number of PIXes across the UK and all have Crypto Tunnels back to 2 central points. One PIX I deployed recently has only come up with 1 tunnel working. This is a template config, so I have absolutely no idea what is wrong :(
Anyway, I've attached a few files. Any help hugely appreciated. Mark
03-20-2009 02:00 AM
Your issues are here - A end:-
Your issue is here:-
crypto_isakmp_process_block:src:10.1.1.1, dest:10.2.1.1 spt:500 dpt:500
VPN Peer:ISAKMP: Peer Info for 10.1.1.1/500 not found - peers:46
ISAKMP: larval sa found
ISAKMP (0): retransmitting phase 1 (1)...
crypto_isakmp_process_block:src:10.1.1.1, dest:10.2.1.1 spt:500 dpt:500
VPN Peer:ISAKMP: Peer Info for 10.1.1.1/500 not found - peers:46
ISAKMP: larval sa found
ISAKMP (0): retransmitting phase 1 (2)...
crypto_isakmp_process_block:src:10.1.1.1, dest:10.2.1.1 spt:500 dpt:500
VPN Peer:ISAKMP: Peer Info for 10.1.1.1/500 not found - peers:46
ISAKMP: larval sa found
ISAKMP (0): retransmitting phase 1 (3)...
crypto_isakmp_process_block:src:10.1.1.1, dest:10.2.1.1 spt:500 dpt:500
VPN Peer:ISAKMP: Peer Info for 10.1.1.1/500 not found - peers:46
B end:-
ISAKMP (0): retransmitting phase 1 (4)...
crypto_isakmp_process_block:src:62.254.26.51, dest:62.253.169.177 spt:500 dpt:500
VPN Peer:ISAKMP: Peer Info for 62.254.26.51/500 not found - peers:46
crypto_isakmp_process_block:src:62.254.26.51, dest:62.253.169.177 spt:500 dpt:500
VPN Peer:ISAKMP: Peer Info for 62.254.26.51/500 not found - peers:46
ISAKMP: larval sa found
ISAKMP (0): retransmitting phase 1 (1)...
crypto_isakmp_process_block:src:62.254.26.51, dest:62.253.169.177 spt:500 dpt:500
VPN Peer:ISAKMP: Peer Info for 62.254.26.51/500 not found - peers:46
ISAKMP: larval sa found
ISAKMP (0): retransmitting phase 1 (2)...
crypto_isakmp_process_block:src:62.254.26.51, dest:62.253.169.177 spt:500 dpt:500
VPN Peer:ISAKMP: Peer Info for 62.254.26.51/500 not found - peers:46
ISAKMP: larval sa found
ISAKMP (0): retransmitting phase 1 (3)...
crypto_isakmp_process_block:src:62.254.26.51, dest:62.253.169.177 spt:500 dpt:500
VPN Peer:ISAKMP: Peer Info for 62.254.26.51/500 not found - peers:46
Either you have configured your Crypto wrong or your ACL's to initiate traffic are incorrect or you are using the wrong ACL to bring up the wrong VPN tunnel.
CHECK YOUR CONFIG.
HTH>
03-20-2009 07:11 AM
Here a good troubleshooting link.
http://www.cisco.com/en/US/products/ps6120/products_tech_note09186a00807e0aca.shtml
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide