Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

LAN2LAN between 3005 and 831.

I used this link (http://www.cisco.com/en/US/customer/tech/tk583/tk372/technologies_configuration_example09186a008009482e.shtml) as template to setup a tunnel between 3005 and 831 router, it was not working.

Is there anything that is this sample I need to modify?

The debug ISAKMP was showing SA has been authenticated with 3005, after processing HASH payload, I got the following message:

ISAKMP (0:1): processing DELETE_WITH_REASON payload, message ID = -1950007301, reason: Unknown delete reason!

ISAKMP (0:1): peer does not do paranoid keepalives.

ISAKMP (0:1): deleting SA reason "P1 delete notify (in)" state (I) QM_IDLE (peer 65.119.203.102) input queue 0

ISAKMP (0:1): deleting node -1950007301 error FALSE reason "informational (in) state 1"

ISAKMP (0:1): Input = IKE_MESG_FROM_PEER, IKE_INFO_DELETE

ISAKMP (0:1): Old State = IKE_P1_COMPLETE New State = IKE_P1_COMPLETE

ISAKMP (0:1): Input = IKE_MESG_INTERNAL, IKE_PHASE1_DEL

ISAKMP (0:1): Old State = IKE_P1_COMPLETE New State = IKE_DEST_SA

ISAKMP (0:1): deleting SA reason "" state (I) QM_IDLE (peer 65.119.203.102) input queue 0

ISAKMP (0:1): deleting node 2027920145 error FALSE reason ""

ISAKMP (0:1): Input = IKE_MESG_FROM_PEER, IKE_MM_EXCH

ISAKMP (0:1): Old State = IKE_DEST_SA New State = IKE_DEST_SA

How do I troubleshoot from here?

1 REPLY
New Member

Re: LAN2LAN between 3005 and 831.

I see that document is complete. I had a similar problem but when I added a static route in one of the pix, the problem got solved, which means, most probably, there is no route at all to an important subnet in your network. you can check that.

262
Views
0
Helpful
1
Replies