EasyVPN client issue

Unanswered Question
Jun 2nd, 2010

I've configured my EasyVPN server on an ASA 5505. I've got a PIX firewall acting as the remote client. The client is attempting to connect, however when I do a "sh crypto isakmp sa" on the server I see the state listed as "AM_TM_INIT_XAUTH_V6H". I've been unable to find much help for this on google. Any ideas the meaning of that state? I have 3 other remote clients connected without any problems.


I have this problem too.
0 votes
  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Jennifer Halim Wed, 06/02/2010 - 19:16

You would need to enter in the xauth (extended authentication) manually for this remote site.

Have you configured the following yet:

vpnclient username   password

vpnclient connect

Otherwise, please kindly share config from PIX remote which is not working, and 1 other remote site which works.

Robert Juric Thu, 06/03/2010 - 04:58

Yes I have those lines configured. I've attached the configs from a working PIX and the PIX I'm having problems with.

The PIX I'm having problems with is acting very strange. When I do a 'sh crypto isakmp sa' it says something like "Error: Cannot configure IKE or IPSEC while Easy VPN is enabled."

Jennifer Halim Thu, 06/03/2010 - 05:54

Thanks for that.

The only difference that I can see between the good and the bad PIX is the software version. The good one is running version 6.3.5, while the bad one runs 6.3.4. As far as configuration is concern, both good and bad ones look correct.

You might want to upgrade the bad one to version 6.3.5 as well.

Robert Juric Fri, 06/04/2010 - 07:50

I think this was actually related to the fact that the bad PIX had a restricted license and couldn't comply with the 3DES transform set.

I ended up bypassing by creating a site-to-site tunnel with a single DES transform set and it worked fine. I might go back later and see if I can set multiple transform sets to the dynamic map or if I can have multiple dynamic maps for legacy devices.

Jennifer Halim Sat, 06/05/2010 - 02:56

Good to hear it's working now.

Yes, you can definitely set multiple transform sets and assign it to your dynamic map. That is what most people do.


This Discussion