I have set up a site to site VPN between a Cisco 1841 ISR and a Cisco ASA 5520, all appears to be working however I have a couple of questions.
1. I have to explicitly allow all VPN traffic in the ACL on the outside interface of the 1841, is there a router equivilent of "sysopt connection permit-vpn"?
2. Although the VPN comes up and passes traffic I occasionally see the following?
*Jun 22 14:11:52.883: %CRYPTO-6-IKMP_MODE_FAILURE: Processing of Quick mode failed with peer at 18.104.22.168
Can you share the full outputs? Both sides at the same time?
Bottom line I don't think it's normal in 12.4 mainline IOS unless packets are leaking out in clear ;/