Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

site-to-site vpn with digital certificate

Two 2811 routers get the certificates from CA server(Windows2003 Enterprise Server,192.168.22.167).But when they try to setup ipsec vpn tunnnel,they can not authenticate with each other by digital certificate successfully.Attachment is configuration of routers and debug information.

I can not find the reason.what could i do next?

Thanks a lot

Martin

3 REPLIES
New Member

Re: site-to-site vpn with digital certificate

I have reinstall the CA Server.But the same issue still exists.What could i do next.Who can give me a successfully case.

Thanks a lot.

Cisco Employee

Re: site-to-site vpn with digital certificate

Martin,

According to the debugs, "phase 1 packet is a duplicate of a previous packet" means that Caclient1 router is sending the same Phase 1 packet eventhough Caclient2 router processed the first packet and sent a response.

1. Caclient1 router sends IKE packet #1 to initiate a tunnel

2. Caclient2 router receives it, processes it, and sends a reply which is IKE packet #2

3. Caclient1 router never receives packet #2 and can't proceed with sending #3, so it resends

packet #1

4. Caclient2 router sees this as a duplicate first packet and resends packet #2

Caclient2 router is sending a UDP 500 packet to Caclient1 but this packet is not getting to Caclient1.

Based upon your IP Addressing, Caclient1 and Caclient2 are on the same network, so there is no question for L3 Firewalling and UDP 500 getting blocked. Are there any L2 Firewalls and are they filtering UDP500.

Also, could you make sure there are no duplicate IP Addresses in your network.

Also, remove the crypto map on both the routers, clear the routes, arp entries and then try to bring up the tunnel again and see what happens.

Let me know if it helps.

Regards,

Arul

New Member

Re: site-to-site vpn with digital certificate

Arul:

Thank you very much for your suggestion.

I am sure that no L3 or L2 Firewall and filter existed because of directly connection of two routers with a switch.I redo the entire process several times.But the same issue also occured.I can get identical debug information from two routers.It almost made me crazy.

I can see only below information about error:

vendor ID seems Unity/DPD but major 245 mismatch

But I can not know whether it is a critical issue and what reason make it report that.Is there any necessary factor I should know ?

253
Views
0
Helpful
3
Replies