Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements
Step-by-Step Configuration and Troubleshooting Best Practices for the NGFW, NGIPS and AMP Technologies A Visual Guide to the Cisco Firepower Threat Defense (FTD)
New Member

Another l2l vpn thread

Hi,

I am trying to setup a l2l VPN between an ASA 5510 (os is 8.0(4)) and a PIX 515E.

Then vpn fails with the following messages :

ASA (initiator):

ASA(config)# Aug 26 11:56:54 [IKEv1]: Group = x.x.x.x, IP = x.x.x.x, construct_ipsec_delete(): No SPI to identify Phase 2 SA!

Aug 26 11:56:54 [IKEv1]: Group = x.x.x.x, IP = x.x.x.x, Removing peer from correlator table failed, no match!

PIX :

onair-gva-ops-fw-01# Aug 26 17:16:20 [IKEv1]: Group = x.x.x.x, IP = x.x.x.x, QM FSM error (P2 struct &0x618a4d0, mess id 0xffe4ece3)!

Aug 26 17:16:20 [IKEv1]: Group = x.x.x.x, IP = x.x.x.x Removing peer from correlator table failed, no match!

Attached are my configs.

Thanks for your help i am starting to scratch my head. . .

1 REPLY
Green

Re: Another l2l vpn thread

You have no isakmp policies set on the ASA.

ex.

isakmp policy 10 authentication pre-share

isakmp policy 10 encryption 3des

isakmp policy 10 group 2

isakmp policy 10 hash md5

126
Views
0
Helpful
1
Replies
CreatePlease to create content