cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2668
Views
0
Helpful
3
Replies

RA VPN ph2 not working- Removing peer from correlator table failed, no match

Abhishek Nagar
Level 1
Level 1

Dear Colleagues

Please suggest the missing configuration- ASA 5525, 9.1 sw

I am getting below syslog, with debug crypto isakmp

Sep 30 16:17:47 [IKEv1]Group = defaultragroup, Username = myvpn, IP = 213.133.216.168, QM FSM error (P2 struct &0x00007ffecc8423a0, mess id 0x8f389b93)!

Sep 30 16:17:47 [IKEv1]Group = defaultragroup, Username = myvpn, IP = 213.133.216.168, Removing peer from correlator table failed, no match!

Sep 30 16:17:47 [IKEv1]Group = defaultragroup, Username = myvpn, IP = 213.133.216.168, Session is being torn down. Reason: Phase 2 Mismatch

I am attaching

sh run tunnel-group

sh run crypto map

and sh run,

My Access VPN group Policy is defaultragroup

local username is myvpn

ip pool 10.200.41.1-10.200.41.14

1 Accepted Solution

Accepted Solutions

Jouni Forss
VIP Alumni
VIP Alumni

Hi,

You could try adding

crypto dynamic-map RAVPNmap 65534 set ikev1 transform-set ESP-3DES-SHA ESP-3DES-MD5

Though I am not sure why there are multiple "dynamic-map" configuration on your ASA to begin with.

- Jouni

View solution in original post

3 Replies 3

Jouni Forss
VIP Alumni
VIP Alumni

Hi,

You could try adding

crypto dynamic-map RAVPNmap 65534 set ikev1 transform-set ESP-3DES-SHA ESP-3DES-MD5

Though I am not sure why there are multiple "dynamic-map" configuration on your ASA to begin with.

- Jouni

hello

i found the problem and fix it, thanks for reply

zizou6500
Level 1
Level 1

Hello Abhishek,

 

Can you please share the solution?

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card