Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

871 easy vpn to 3005

I setup cisco 871 as a vpn client connecting to 3005 concentrator. (the client has a private address). The connection is successful. Right after the tunnel is up I can ping a host on a remote network (behind 871). But when I stop the ping for about 20 seconds I cannot resume it, although the ISAKMP and IPsec SAs are still there (on both router and concentrator).

The log from the concentrator:

PHASE 2 COMPLETED (msgid=8dc50042)

6710 05/19/2006 14:44:09.630 SEV=6 IKE/145 RPT=221


Detected Hardware Client in network extension mode,

adding static route for address:, mask:

6713 05/19/2006 14:44:10.130 SEV=4 IKE/0 RPT=3250

Group ........ User .......

Inconsistent PSK hash size

What does the the last line mean? The authentication has definately been successful and phase 2 is complete.

What can be the problem?

New Member

Re: 871 easy vpn to 3005

I solved the problem with isakmp keepalive 10 periodic command on the router, although I am not happy with the solution. It is normally used for DPD when backup servers are configured. Why do I have to use it in this case?

New Member

Re: 871 easy vpn to 3005


Do you know what was the solution for your problem about "inconsitent PSK hash size".

I have exact the same issue.

Would you please email me at if you can help me with this.


Zahi Zeineddie