I have got a problem in configuring a vpn from a pix to a router. phase 1 and phase 2 is getting established and after that it is getting deleted. I cannot find anything unusual except a message saying that "throw:aborting runt ".I dont know how runt came into picture up here.Im pasting the debug output.
thanks in advance
Lainc-0014# sh crypto isakmp sa
Total : 1
Embryonic : 0
dst src state pending created
184.108.40.206 220.127.116.11 QM_IDLE 0 0
VPN Peer: ISAKMP: Deleted peer: ip:18.104.22.168 Total VPN peers:0
crypto_isakmp_process_block: src 22.214.171.124, dest 126.96.36.199
VPN Peer: ISAKMP: Added new peer: ip:188.8.131.52 Total VPN Peers:1
I also faced a similar problem couple of days back and found out the solution. Disable any sort of AH or ESP-HMAC from the transform-set and the tunnle will come up with the encryption-decryption of the packets. The issue seems to be with some intermittent devices that are fragmentating the IPSec packets leading to mismatch of the Packet integrity number calculated by the AH at the time of encryption and decryption.
Table of ContentsIntroductionVersion HistoryPossible Future
UpdatesDocuments PurposeNAT Operation in ASA 8.3+ SectionsRule Types
Network Object NATTwice NAT / Manual NATRule Types used per SectionNAT
Types used with Twice NAT / Manual NAT and Network Obje...
Table of Contents Introduction:This document describes details on how
NAT-T works. Background: ESP encrypts all critical information,
encapsulating the entire inner TCP/UDP datagram within an ESP header.
ESP is an IP protocol in the same sense that TCP an...