cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
737
Views
0
Helpful
3
Replies

Vpn PIX 7.0 + Drayteck v2600vi: Duplicate Phase 2 packet detected

e.deangelis
Level 1
Level 1

Hi,

i would connect a tunnel vpn beetwen two site with pix and draytec but connection not work.

my pix config is attacch.

This my debug crypto isak... output:

Pix# Dec 03 15:43:45 [IKEv1]: IP = 11.11.11.11, Connection landed on tunnel_group 11.11.11.11

Dec 03 15:43:46 [IKEv1]: Group = 11.11.11.11, IP = 11.11.11.11, PHASE 1 COMPLETED

Dec 03 15:43:46 [IKEv1]: IP = 11.11.11.11, Keep-alive type for this connection: None

Dec 03 15:43:46 [IKEv1]: IP = 11.11.11.11, Keep-alives configured on but peer does not support keep-alives (type = None)

Dec 03 15:43:46 [IKEv1]: Group = 11.11.11.11, IP = 11.11.11.11, Received remote IP Proxy Subnet data in ID Payload: Address 192.168.1.0, Mask 255.255.255.0, Protocol 0, Port 0

Dec 03 15:43:46 [IKEv1]: Group = 11.11.11.11, IP = 11.11.11.11, Received local IP Proxy Subnet data in ID Payload: Address 192.168.149.1, Mask 255.255.255.0, Protocol 0, Port 0

Dec 03 15:43:46 [IKEv1]: QM IsRekeyed old sa not found by addr

Dec 03 15:43:46 [IKEv1]: Group = 11.11.11.11, IP = 11.11.11.11, IKE Remote Peer configured for SA: lantolan

Dec 03 15:43:46 [IKEv1]: Group = 11.11.11.11, IP = 11.11.11.11, IKE: requesting SPI!

Dec 03 15:43:49 [IKEv1]: Group = 11.11.11.11, IP = 11.11.11.11, Duplicate Phase 2 packet detected. Retransmitting last packet.

Dec 03 15:43:55 [IKEv1]: Group = 11.11.11.11, IP = 11.11.11.11, Duplicate Phase 2 packet detected. Retransmitting last packet.

Dec 03 15:43:58 [IKEv1]: Group = 11.11.11.11, IP = 11.11.11.11, Connection terminated for peer 11.11.11.11. Reason: Peer Terminate Remote Proxy N/A, Local Proxy N/A

Dec 03 15:43:58 [IKEv1]: Group = 11.11.11.11, IP = 11.11.11.11, Removing peer from correlator table failed, no match!

Thanks.

3 Replies 3

e.deangelis
Level 1
Level 1

Hi,

anyone can help me? Please

Thanks

blue-networks
Level 1
Level 1

Hi,

did you find a solution for that problem? I have the same problem with on of my VPN tunnels.

Thanks

Peer

Disable keep alive, and ensure all SA's are matching exact value on both peers.