IPSEC VPN betwwwn ASA and ISA server problem

Unanswered Question
Sep 20th, 2010
User Badges:

Hi all, thank u for your help.

I tried to establish Ipsec vpn b/n ASA and ISA server, but i have got the following error:

[IKEv1]: Group = x.x.x.x, IP =
x.x.x.x, Can't find a valid tunnel group, aborting...!
Sep 20 05:56:15 [IKEv1]: Group = x.x.x.x, IP = x.x.x.x, Removing peer
from peer table failed, no match!
Sep 20 05:56:15 [IKEv1]: Group = x.x.x.x, IP = x.x.x.x, Error: Unable
to remove PeerTblEntry
Sep 20 05:56:15 [IKEv1]: IP = x.x.x.x, Header invalid, missing SA payload!
(next payload = 4)

The security life time is the same on both sides.

Any help please

  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
praprama Mon, 09/20/2010 - 06:29
User Badges:
  • Cisco Employee,


It seems like you do not have a tunnel-group configured with the ISA server's public IP address. Please check the output of "show run tunnel-group" from the ASA. If the ISA's IP address is a.b.c.d, you should see the below:

tunnel-group a.b.c.d type ipsec-l2l

tunnel-group a.b.c.d ipsec-attributes

pre-shared-key PSK

Please aste the output here.

Thanks and Regards,


mulugojjam abebe Mon, 09/20/2010 - 07:29
User Badges:

Thank you Prapanch,

Now its working i changed the tunnel-group name with the remote ip address and it works.

previously it was tunnel-group remotevpn, and now i changed tunnel-group a.b.c.d

Thank you fro your help,



This Discussion