cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
795
Views
0
Helpful
5
Replies

what does this mean?

m.matteson
Level 2
Level 2

the debug below says the pre-shared keys don't match. i believe they do. my group is vpnuser and key is cisco123 on the vpn client and on the router they are also the same. suggestions?

2d09h: ISAKMP (0:9): Checking ISAKMP transform 8 against priority 100 policy

2d09h: ISAKMP: encryption AES-CBC

2d09h: ISAKMP: hash MD5

2d09h: ISAKMP: default group 2

2d09h: ISAKMP: auth pre-share

2d09h: ISAKMP: life type in seconds

2d09h: ISAKMP: life duration (VPI) of 0x0 0x20 0xC4 0x9B

2d09h: ISAKMP: keylength of 128

2d09h: ISAKMP (0:9): Encryption algorithm offered does not match policy!

2d09h: ISAKMP (0:9): atts are not acceptable. Next payload is 3

2d09h: ISAKMP (0:9): Checking ISAKMP transform 9 against priority 100 policy

2d09h: ISAKMP: encryption 3DES-CBC

2d09h: ISAKMP: hash SHA

2d09h: ISAKMP: default group 2

2d09h: ISAKMP: auth XAUTHInitPreShared

2d09h: ISAKMP: life type in seconds

2d09h: ISAKMP: life duration (VPI) of 0x0 0x20 0xC4 0x9B

2d09h: ISAKMP (0:9): Hash algorithm offered does not match policy!

2d09h: ISAKMP (0:9): atts are not acceptable. Next payload is 3

2d09h: ISAKMP (0:9): Checking ISAKMP transform 10 against priority 100 policy

2d09h: ISAKMP: encryption 3DES-CBC

2d09h: ISAKMP: hash MD5

2d09h: ISAKMP: default group 2

2d09h: ISAKMP: auth XAUTHInitPreShared

2d09h: ISAKMP: life type in seconds

2d09h: ISAKMP: life duration (VPI) of 0x0 0x20 0xC4 0x9B

2d09h: ISAKMP (0:9): Xauth authentication by pre-shared key offered but does not

match policy!

5 Replies 5

rjwalani
Cisco Employee
Cisco Employee

Hi,

Could you please post the complete debugs? The messages you are seeing just indicate that the router and the vpn client have not agreed on the phase 1 proposal which they are going to use.

Thanks

Ranjana

2d21h: ISAKMP (0:0): received packet from 172.16.1.107 dport 500 sport 500 Globa

l (N) NEW SA

2d21h: ISAKMP: local port 500, remote port 500

2d21h: ISAKMP: Find a dup sa in the avl tree during calling isadb_insert sa = 82

EBF27C

2d21h: ISAKMP (0:12): processing SA payload. message ID = 0

2d21h: ISAKMP (0:12): processing ID payload. message ID = 0

2d21h: ISAKMP (0:12): peer matches *none* of the profiles

2d21h: ISAKMP (0:12): processing vendor id payload

2d21h: ISAKMP (0:12): vendor ID seems Unity/DPD but major 215 mismatch

2d21h: ISAKMP (0:12): vendor ID is XAUTH

2d21h: ISAKMP (0:12): processing vendor id payload

2d21h: ISAKMP (0:12): vendor ID is DPD

2d21h: ISAKMP (0:12): processing vendor id payload

2d21h: ISAKMP (0:12): vendor ID is Unity

2d21h: ISAKMP : Scanning profiles for xauth ...

2d21h: ISAKMP (0:12): Checking ISAKMP transform 1 against priority 100 policy

2d21h: ISAKMP: encryption AES-CBC

2d21h: ISAKMP: hash SHA

2d21h: ISAKMP: default group 2exe-router#

2d21h: ISAKMP: auth XAUTHInitPreShared

2d21h: ISAKMP: life type in seconds

2d21h: ISAKMP: life duration (VPI) of 0x0 0x20 0xC4 0x9B

2d21h: ISAKMP: keylength of 256

2d21h: ISAKMP (0:12): Encryption algorithm offered does not match policy!

2d21h: ISAKMP (0:12): atts are not acceptable. Next payload is 3

2d21h: ISAKMP (0:12): Checking ISAKMP transform 2 against priority 100 policy

2d21h: ISAKMP: encryption AES-CBC

2d21h: ISAKMP: hash MD5

2d21h: ISAKMP: default group 2

2d21h: ISAKMP: auth XAUTHInitPreShared

2d21h: ISAKMP: life type in seconds

2d21h: ISAKMP: life duration (VPI) of 0x0 0x20 0xC4 0x9B

2d21h: ISAKMP: keylength of 256

2d21h: ISAKMP (0:12): Encryption algorithm offered does not match policy!

2d21h: ISAKMP (0:12): atts are not acceptable. Next payload is 3

2d21h: ISAKMP (0:12): Checking ISAKMP transform 3 against priority 100 policy

2d21h: ISAKMP: encryption AES-CBC

2d21h: ISAKMP: hash SHA

2d21h: ISAKMP: default group 2

2d21h: ISAKMP: auth pre-share

2d21h: ISAKMP: life type in seconds

2d21h: ISAKMP: life duration (VPI) of 0x0 0x20 0xC4 0x9B

2d21h: ISAKMP: keylength of 256

2d21h: ISAKMP (0:12): Encryption algorithm offered does not match policy!

2d21h: ISAKMP (0:12): atts are not acceptable. Next payload is 3

2d21h: ISAKMP (0:12): Checking ISAKMP transform 4 against priority 100 policy

2d21h: ISAKMP: encryption AES-CBC

2d21h: ISAKMP: hash MD5

2d21h: ISAKMP: default group 2

2d21h: ISAKMP: auth pre-share

2d21h: ISAKMP: life type in seconds

2d21h: ISAKMP: life duration (VPI) of 0x0 0x20 0xC4 0x9B

2d21h: ISAKMP: keylength of 256

2d21h: ISAKMP (0:12): Encryption algorithm offered does not match policy!

2d21h: ISAKMP (0:12): atts are not acceptable. Next payload is 3

2d21h: ISAKMP (0:12): Checking ISAKMP transform 5 against priority 100 policy

2d21h: ISAKMP: encryption AES-CBC

2d21h: ISAKMP: hash SHA

2d21h: ISAKMP: default group 2

2d21h: ISAKMP: auth XAUTHInitPreShared

2d21h: ISAKMP: life type in seconds

2d21h: ISAKMP: life duration (VPI) of 0x0 0x20 0xC4 0x9B

2d21h: ISAKMP: keylength of 128

2d21h: ISAKMP (0:12): Encryption algorithm offered does not match policy!

2d21h: ISAKMP (0:12): atts are not acceptable. Next payload is 3

2d21h: ISAKMP (0:12): Checking ISAKMP transform 6 against priority 100 policy

2d21h: ISAKMP: encryption AES-CBC

2d21h: ISAKMP: hash MD5

2d21h: ISAKMP: default group 2

2d21h: ISAKMP: auth XAUTHInitPreShared

2d21h: ISAKMP: life type in seconds

2d21h: ISAKMP: life duration (VPI) of 0x0 0x20 0xC4 0x9B

2d21h: ISAKMP: keylength of 128

2d21h: ISAKMP (0:12): Encryption algorithm offered does not match policy!

2d21h: ISAKMP (0:12): atts are not acceptable. Next payload is 3

2d21h: ISAKMP (0:12): Checking ISAKMP transform 7 against priority 100 policy

2d21h: ISAKMP: encryption AES-CBC

2d21h: ISAKMP: hash SHA

2d21h: ISAKMP: default group 2

2d21h: ISAKMP: auth pre-share

2d21h: ISAKMP: life type in seconds

2d21h: ISAKMP: life duration (VPI) of 0x0 0x20 0xC4 0x9B

2d21h: ISAKMP: keylength of 128

2d21h: ISAKMP (0:12): Encryption algorithm offered does not match policy!

2d21h: ISAKMP (0:12): atts are not acceptable. Next payload is 3

2d21h: ISAKMP (0:12): Checking ISAKMP transform 8 against priority 100 policy

2d21h: ISAKMP: encryption AES-CBC

2d21h: ISAKMP: hash MD5

2d21h: ISAKMP: default group 2

2d21h: ISAKMP: auth pre-share

2d21h: ISAKMP: life type in seconds

2d21h: ISAKMP: life duration (VPI) of 0x0 0x20 0xC4 0x9B

2d21h: ISAKMP: keylength of 128

2d21h: ISAKMP (0:12): Encryption algorithm offered does not match policy!

2d21h: ISAKMP (0:12): atts are not acceptable. Next payload is 3

2d21h: ISAKMP (0:12): Checking ISAKMP transform 9 against priority 100 policy

2d21h: ISAKMP: encryption 3DES-CBC

2d21h: ISAKMP: hash SHA

2d21h: ISAKMP: default group 2

2d21h: ISAKMP: auth XAUTHInitPreShared

2d21h: ISAKMP: life type in seconds

2d21h: ISAKMP: life duration (VPI) of 0x0 0x20 0xC4 0x9B

2d21h: ISAKMP (0:12): Hash algorithm offered does not match policy!

2d21h: ISAKMP (0:12): atts are not acceptable. Next payload is 3

2d21h: ISAKMP (0:12): Checking ISAKMP transform 10 against priority 100 policy

2d21h: ISAKMP: encryption 3DES-CBC

2d21h: ISAKMP: hash MD5

2d21h: ISAKMP: default group 2

2d21h: ISAKMP: auth XAUTHInitPreShared

2d21h: ISAKMP: life type in seconds

2d21h: ISAKMP: life duration (VPI) of 0x0 0x20 0xC4 0x9B

2d21h: ISAKMP (0:12): Xauth authentication by pre-shared key offered but does no

t match policy!

2d21h: ISAKMP (0:12): atts are not acceptable. Next payload is 3

2d21h: ISAKMP (0:12): Checking ISAKMP transform 11 against priority 100 policy

2d21h: ISAKMP: encryption 3DES-CBC

2d21h: ISAKMP: hash SHA

2d21h: ISAKMP: default group 2

2d21h: ISAKMP: auth pre-share

2d21h: ISAKMP: life type in seconds

2d21h: ISAKMP: life duration (VPI) of 0x0 0x20 0xC4 0x9B

2d21h: ISAKMP (0:12): Hash algorithm offered does not match policy!

2d21h: ISAKMP (0:12): atts are not acceptable. Next payload is 3

2d21h: ISAKMP (0:12): Checking ISAKMP transform 12 against priority 100 policy

2d21h: ISAKMP: encryption 3DES-CBC

2d21h: ISAKMP: hash MD5

2d21h: ISAKMP: default group 2

2d21h: ISAKMP: auth pre-share

2d21h: ISAKMP: life type in seconds

2d21h: ISAKMP: life duration (VPI) of 0x0 0x20 0xC4 0x9B

2d21h: ISAKMP (0:12): Preshared authentication offered but does not match policy

!

2d21h: ISAKMP (0:12): atts are not acceptable. Next payload is 3

2d21h: ISAKMP (0:12): Checking ISAKMP transform 13 against priority 100 policy

2d21h: ISAKMP: encryption DES-CBC

2d21h: ISAKMP: hash MD5

2d21h: ISAKMP: default group 2

2d21h: ISAKMP: auth XAUTHInitPreShared

2d21h: ISAKMP: life type in seconds

2d21h: ISAKMP: life duration (VPI) of 0x0 0x20 0xC4 0x9B

2d21h: ISAKMP (0:12): Encryption algorithm offered does not match policy!

2d21h: ISAKMP (0:12): atts are not acceptable. Next payload is 3

2d21h: ISAKMP (0:12): Checking ISAKMP transform 14 against priority 100 policy

2d21h: ISAKMP: encryption DES-CBC

2d21h: ISAKMP: hash MD5

2d21h: ISAKMP: default group 2

2d21h: ISAKMP: auth pre-share

2d21h: ISAKMP: life type in seconds

2d21h: ISAKMP: life duration (VPI) of 0x0 0x20 0xC4 0x9B

2d21h: ISAKMP (0:12): Encryption algorithm offered does not match policy!

2d21h: ISAKMP (0:12): atts are not acceptable. Next payload is 0

2d21h: ISAKMP (0:12): Checking ISAKMP transform 1 against priority 65535 policy

2d21h: ISAKMP: encryption AES-CBC

2d21h: ISAKMP: hash SHA

2d21h: ISAKMP: default group 2

2d21h: ISAKMP: auth XAUTHInitPreShared

2d21h: ISAKMP: life type in seconds

2d21h: ISAKMP: life duration (VPI) of 0x0 0x20 0xC4 0x9B

2d21h: ISAKMP: keylength of 256

2d21h: ISAKMP (0:12): Encryption algorithm offered does not match policy!

2d21h: ISAKMP (0:12): atts are not acceptable. Next payload is 3

2d21h: ISAKMP (0:12): Checking ISAKMP transform 2 against priority 65535 policy

2d21h: ISAKMP: encryption AES-CBC

2d21h: ISAKMP: hash MD5

2d21h: ISAKMP: default group 2

2d21h: ISAKMP: auth XAUTHInitPreShared

2d21h: ISAKMP: life type in seconds

2d21h: ISAKMP: life duration (VPI) of 0x0 0x20 0xC4 0x9B

2d21h: ISAKMP: keylength of 256

2d21h: ISAKMP (0:12): Encryption algorithm offered does not match policy!

2d21h: ISAKMP (0:12): atts are not acceptable. Next payload is 3

2d21h: ISAKMP (0:12): Checking ISAKMP transform 3 against priority 65535 policy

2d21h: ISAKMP: encryption AES-CBC

2d21h: ISAKMP: hash SHA

2d21h: ISAKMP: default group 2

2d21h: ISAKMP: auth pre-share

2d21h: ISAKMP: life type in seconds

2d21h: ISAKMP: life duration (VPI) of 0x0 0x20 0xC4 0x9B

2d21h: ISAKMP: keylength of 256

2d21h: ISAKMP (0:12): Encryption algorithm offered does not match policy!

2d21h: ISAKMP (0:12): atts are not acceptable. Next payload is 3

2d21h: ISAKMP (0:12): Checking ISAKMP transform 4 against priority 65535 policy

2d21h: ISAKMP: encryption AES-CBC

2d21h: ISAKMP: hash MD5

2d21h: ISAKMP: default group 2

2d21h: ISAKMP: auth pre-share

2d21h: ISAKMP: life type in seconds

2d21h: ISAKMP: life duration (VPI) of 0x0 0x20 0xC4 0x9B

2d21h: ISAKMP: keylength of 256

2d21h: ISAKMP (0:12): Encryption algorithm offered does not match policy!

2d21h: ISAKMP (0:12): atts are not acceptable. Next payload is 3

2d21h: ISAKMP (0:12): Checking ISAKMP transform 5 against priority 65535 policy

2d21h: ISAKMP: encryption AES-CBC

2d21h: ISAKMP: hash SHA

2d21h: ISAKMP: default group 2

2d21h: ISAKMP: auth XAUTHInitPreShared

2d21h: ISAKMP: life type in seconds

2d21h: ISAKMP: life duration (VPI) of 0x0 0x20 0xC4 0x9B

2d21h: ISAKMP: keylength of 128

2d21h: ISAKMP (0:12): Encryption algorithm offered does not match policy!

2d21h: ISAKMP (0:12): atts are not acceptable. Next payload is 3

2d21h: ISAKMP (0:12): Checking ISAKMP transform 6 against priority 65535 policy

2d21h: ISAKMP: encryption AES-CBC

2d21h: ISAKMP: hash MD5

2d21h: ISAKMP: default group 2

2d21h: ISAKMP: auth XAUTHInitPreShared

2d21h: ISAKMP: life type in seconds

2d21h: ISAKMP: life duration (VPI) of 0x0 0x20 0xC4 0x9B

2d21h: ISAKMP: keylength of 128

2d21h: ISAKMP (0:12): Encryption algorithm offered does not match policy!

2d21h: ISAKMP (0:12): atts are not acceptable. Next payload is 3

2d21h: ISAKMP (0:12): Checking ISAKMP transform 7 against priority 65535 policy

2d21h: ISAKMP: encryption AES-CBC

2d21h: ISAKMP: hash SHA

2d21h: ISAKMP: default group 2

2d21h: ISAKMP: auth pre-share

2d21h: ISAKMP: life type in seconds

2d21h: ISAKMP: life duration (VPI) of 0x0 0x20 0xC4 0x9B

2d21h: ISAKMP: keylength of 128

2d21h: ISAKMP (0:12): Encryption algorithm offered does not match policy!

2d21h: ISAKMP (0:12): atts are not acceptable. Next payload is 3

2d21h: ISAKMP (0:12): Checking ISAKMP transform 8 against priority 65535 policy

2d21h: ISAKMP: encryption AES-CBC

2d21h: ISAKMP: hash MD5

2d21h: ISAKMP: default group 2

2d21h: ISAKMP: auth pre-share

2d21h: ISAKMP: life type in seconds

2d21h: ISAKMP: life duration (VPI) of 0x0 0x20 0xC4 0x9B

2d21h: ISAKMP: keylength of 128

2d21h: ISAKMP (0:12): Encryption algorithm offered does not match policy!

2d21h: ISAKMP (0:12): atts are not acceptable. Next payload is 3

2d21h: ISAKMP (0:12): Checking ISAKMP transform 9 against priority 65535 policy

2d21h: ISAKMP: encryption 3DES-CBC

2d21h: ISAKMP: hash SHA

2d21h: ISAKMP: default group 2

2d21h: ISAKMP: auth XAUTHInitPreShared

2d21h: ISAKMP: life type in seconds

2d21h: ISAKMP: life duration (VPI) of 0x0 0x20 0xC4 0x9B

2d21h: ISAKMP (0:12): Encryption algorithm offered does not match policy!

2d21h: ISAKMP (0:12): atts are not acceptable. Next payload is 3

2d21h: ISAKMP (0:12): Checking ISAKMP transform 10 against priority 65535 policy

2d21h: ISAKMP: encryption 3DES-CBC

2d21h: ISAKMP: hash MD5

2d21h: ISAKMP: default group 2

2d21h: ISAKMP: auth XAUTHInitPreShared

2d21h: ISAKMP: life type in seconds

2d21h: ISAKMP: life duration (VPI) of 0x0 0x20 0xC4 0x9B

2d21h: ISAKMP (0:12): Encryption algorithm offered does not match policy!

2d21h: ISAKMP (0:12): atts are not acceptable. Next payload is 3

2d21h: ISAKMP (0:12): Checking ISAKMP transform 11 against priority 65535 policy

2d21h: ISAKMP: encryption 3DES-CBC

2d21h: ISAKMP: hash SHA

2d21h: ISAKMP: default group 2

2d21h: ISAKMP: auth pre-share

2d21h: ISAKMP: life type in seconds

2d21h: ISAKMP: life duration (VPI) of 0x0 0x20 0xC4 0x9B

2d21h: ISAKMP (0:12): Encryption algorithm offered does not match policy!

2d21h: ISAKMP (0:12): atts are not acceptable. Next payload is 3

2d21h: ISAKMP (0:12): Checking ISAKMP transform 12 against priority 65535 policy

2d21h: ISAKMP: encryption 3DES-CBC

2d21h: ISAKMP: hash MD5

2d21h: ISAKMP: default group 2

2d21h: ISAKMP: auth pre-share

2d21h: ISAKMP: life type in seconds

2d21h: ISAKMP: life duration (VPI) of 0x0 0x20 0xC4 0x9B

2d21h: ISAKMP (0:12): Encryption algorithm offered does not match policy!

2d21h: ISAKMP (0:12): atts are not acceptable. Next payload is 3

2d21h: ISAKMP (0:12): Checking ISAKMP transform 13 against priority 65535 policy

2d21h: ISAKMP: encryption DES-CBC

2d21h: ISAKMP: hash MD5

2d21h: ISAKMP: default group 2

2d21h: ISAKMP: auth XAUTHInitPreShared

2d21h: ISAKMP: life type in seconds

2d21h: ISAKMP: life duration (VPI) of 0x0 0x20 0xC4 0x9B

2d21h: ISAKMP (0:12): Hash algorithm offered does not match policy!

2d21h: ISAKMP (0:12): atts are not acceptable. Next payload is 3

2d21h: ISAKMP (0:12): Checking ISAKMP transform 14 against priority 65535 policy

2d21h: ISAKMP: encryption DES-CBC

2d21h: ISAKMP: hash MD5

2d21h: ISAKMP: default group 2

2d21h: ISAKMP: auth pre-share

2d21h: ISAKMP: life type in seconds

2d21h: ISAKMP: life duration (VPI) of 0x0 0x20 0xC4 0x9B

2d21h: ISAKMP (0:12): Hash algorithm offered does not match policy!

2d21h: ISAKMP (0:12): atts are not acceptable. Next payload is 0

2d21h: ISAKMP (0:12): no offers accepted!

2d21h: ISAKMP (0:12): phase 1 SA policy not acceptable! (local 68.9.201.218 remo

te 172.16.1.107)

2d21h: ISAKMP (0:12): incrementing error counter on sa: construct_fail_ag_init

2d21h: ISAKMP (0:12): Unknown Input: state = IKE_READY, major, minor = IKE_MESG_

FROM_PEER, IKE_AM_EXCH

2d21h: ISAKMP (0:12): received packet from 172.16.1.107 dport 500 sport 500 Glob

al (R) AG_NO_STATE

2d21h: ISAKMP (0:12): phase 1 packet is a duplicate of a previous packet.

2d21h: ISAKMP (0:12): retransmitting due to retransmit phase 1

2d21h: ISAKMP (0:12): retransmitting phase 1 AG_NO_STATE...

2d21h: ISAKMP (0:12): retransmitting phase 1 AG_NO_STATE...

2d21h: ISAKMP (0:12): incrementing error counter on sa: retransmit phase 1

2d21h: ISAKMP (0:12): retransmitting phase 1 AG_NO_STATE

2d21h: ISAKMP (0:12): sending packet to 172.16.1.107 my_port 500 peer_port 500 (

R) AG_NO_STATE

2d21h: ISAKMP (0:12): received packet from 172.16.1.107 dport 500 sport 500 Glob

al (R) AG_NO_STATE

2d21h: ISAKMP (0:12): phase 1 packet is a duplicate of a previous packet.

2d21h: ISAKMP (0:12): retransmitting due to retransmit phase 1

2d21h: ISAKMP (0:12): retransmitting phase 1 AG_NO_STATE...

2d21h: ISAKMP (0:12): retransmitting phase 1 AG_NO_STATE...

2d21h: ISAKMP (0:12): incrementing error counter on sa: retransmit phase 1

2d21h: ISAKMP (0:12): no outgoing phase 1 packet to retransmit. AG_NO_STATE

2d21h: ISAKMP (0:12): received packet from 172.16.1.107 dport 500 sport 500 Glob

al (R) AG_NO_STATE

2d21h: ISAKMP (0:12): phase 1 packet is a duplicate of a previous packet.

2d21h: ISAKMP (0:12): retransmitting due to retransmit phase 1

2d21h: ISAKMP (0:12): retransmitting phase 1 AG_NO_STATE...

2d21h: ISAKMP (0:12): retransmitting phase 1 AG_NO_STATE...

2d21h: ISAKMP (0:12): incrementing error counter on sa: retransmit phase 1

2d21h: ISAKMP (0:12): no outgoing phase 1 packet to retransmit. AG_NO_STATE

exe-router#

exe-router#

From the details of the logs, it is very clear that the only transform set that is agreed is "Encryption=3DES and Hash=MD5". (See transform 10 and 12) but it is saying that the policy didn't allow to establish the IKE SA. So you can just configure this basic transform set and try creating the IKE tunnel.

thanks i'll give it a try

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: