2 ASA 5505's All Sorts of VPN Problems

Unanswered Question
Sep 3rd, 2009
User Badges:

I have ASA 5505's up until yesterday they had a working VPN for months. Yesterday we had to change the public IP's for both 5505's. The first ASA #1 has about a dozen VPN's configured on it and is having no other issues except for this particular VPN. The other ASA #2 also had it's IP changed yesterday it has had problems with 2 of 5 different VPN's. One of the two VPN's is connecting to #1. When you try to initiate the connection from #1 I get tons of errors:

5 Sep 03 2009 21:36:00 713257 Phase 1 failure: Mismatched attribute types for class Group Description: Rcv'd: Group 2 Cfg'd: Group 1

Dozen's of these before the VPN finally connects. I can't for the life of me find any different settings between the two of them. If they are set to use aggressive mode the VPN will still get all the errors but will not come up. I've deleted it on both sides and re-created it, still doesn't work right.

  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
networker99 Fri, 09/04/2009 - 06:02
User Badges:

I presume that you have multiple ISAKMP policies configured?. Are the ISAKMP policies listed in the same order on both sides? as the initiating side will send its proposal and compare against the peers first, and then the second if no match is found..

nmooremvsc Fri, 09/04/2009 - 06:04
User Badges:

Yes, the first policies on both match, the final policies on both match as well.

networker99 Fri, 09/04/2009 - 06:07
User Badges:

There is some inconsistancy with the ISAKMP policy.. can you post the config as well as the output from "debug crypto isakmp 8"

networker99 Fri, 09/04/2009 - 07:03
User Badges:

oh,.,. just realized I have had this before. In the end I had to completely delete and rebuild the ISAKMP and Crypto Map statement. Used the same settings

nmooremvsc Fri, 09/04/2009 - 07:12
User Badges:

Delete the entire crypto map statement or just that numbered section?

networker99 Fri, 09/04/2009 - 07:21
User Badges:

You could try that first. I believe it was in the name so I would create a brand new one (just copy and paste the old changing the name) and apply it to the interface


This Discussion