Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

ISAKMP: reserved not zero on payload 5

I have a PIX 506, trying to establish a tunnel to a Netscreen Model 50. When trying to bring the tunnel up, Phase 1 comes up fine, but get

ISAKMP: reserved not zero on payload 5

in phase 2. Eventually, the tunnel comes up, after 4 or 5 minutes, and 4 or 5 thousand ping packets. When it's coming up, if you do a "show crypto isakmp sa" it shows additional sa's keep adding for the same peer. They are all in state QM_IDLE. Eventually, the VPN starts to work, but a number of the sa's remain. Typically, around 35 are present by the time the VPN comes up, and 15 to 20 remain after it's up. We are using group 2, 3DES, MD5.

1 REPLY
Bronze

Re: ISAKMP: reserved not zero on payload 5

Please make sure that you have matching pre-shared key on the two sides, and for inter-op issues you can make sure that two sides have one iskamp/ipsec transfor-sets configured, and lifetimes for SAs matches as well.

thanks,

Afaq

530
Views
0
Helpful
1
Replies