Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

Site-to-Site VPN with SA 540 and SA 520

Hi everybody,

I've been attempting to create a site-to-site VPN between a pair of SA 540 and SA 520 device both running the 1.1.42 firmware.

Because the SA 540 is being used at our main office, we had a dedicated internet connection installed just to handle the VPN connection.

The current configuration looks like this:

Main Office:

WAN Port: a.a.a.a

Optional Port: b.b.b.b

LAN Port: c.c.c.c

Remote Office:

WAN Port: d.d.d.d

LAN Port: e.e.e.e

I used the VPN wizard to create a site-to-site VPN connection as per the documentation, and I set the optional port mode to load-balance the connections at the main office, with all the typical services we use explicitly bound to the WAN Port.  However, this was causing frequent short outages for general internet use at the office and I had to disable it for the interim.

While it was configured, neither of the devices would initiate a connection with the following log entries on both sides (this is from the remote office):

2010-06-22 15:57:33: INFO:  Using IPsec SA configuration: e.e.e.e/24<->c.c.c.c/24

2010-06-22 15:57:33: INFO:  Configuration found for b.b.b.b.

2010-06-22 15:57:33: INFO:  Initiating new phase 1 negotiation: d.d.d.d[500]<=>b.b.b.b[500]

2010-06-22 15:57:33: INFO:  Beginning Identity Protection mode.

2010-06-22 15:57:33: INFO:   [ident_i1send:180]: XXX: NUMNATTVENDORIDS: 3

2010-06-22 15:57:33: INFO:   [ident_i1send:184]: XXX: setting vendorid: 4

2010-06-22 15:57:33: INFO:   [ident_i1send:184]: XXX: setting vendorid: 8

2010-06-22 15:57:33: INFO:   [ident_i1send:184]: XXX: setting vendorid: 9

2010-06-22 15:58:04: ERROR:  Phase 2 negotiation failed due to time up waiting for phase1. ESP b.b.b.b->d.d.d.d

2010-06-22 15:58:33: ERROR:  Phase 1 negotiation failed due to time up for b.b.b.b[500]. 03469abbb83fc0ac:0000000000000000

2010-06-22 16:00:53: INFO:  Using IPsec SA configuration: e.e.e.e/24<->c.c.c.c/24

2010-06-22 16:00:53: INFO:  Configuration found for b.b.b.b.

2010-06-22 16:00:53: INFO:  Initiating new phase 1 negotiation: d.d.d.d[500]<=>b.b.b.b[500]

2010-06-22 16:00:53: INFO:  Beginning Identity Protection mode.

2010-06-22 16:00:53: INFO:   [ident_i1send:180]: XXX: NUMNATTVENDORIDS: 3

2010-06-22 16:00:53: INFO:   [ident_i1send:184]: XXX: setting vendorid: 4

2010-06-22 16:00:53: INFO:   [ident_i1send:184]: XXX: setting vendorid: 8

2010-06-22 16:00:53: INFO:   [ident_i1send:184]: XXX: setting vendorid: 9

2010-06-22 16:01:24: ERROR:  Phase 2 negotiation failed due to time up waiting for phase1. ESP b.b.b.b->d.d.d.d

Has anyone been able to get this kind of configuration working between two SA devices?  I have read several posts regarding the above log and the units needing to be power-cycled to connect successfully, but I'm not sure if that still applies to the 1.1.42 firmware and it didn't help to resolve my issue at all.

Any input would be greatly appreciated!

Everyone's tags (6)
6 REPLIES
New Member

Re: Site-to-Site VPN with SA 540 and SA 520

Hi Ian,

This is regarding your site-ot-site VPN connection. With the description posted on the support community we are unable to reproduce the issue you are seeing. Can you please send us the router configurations so that we can try them in our labs - you can send directly to me. Please change your passwords before sending to us.

Thanks,

Nitin Manglik

New Member

Re: Site-to-Site VPN with SA 540 and SA 520

Hi

I've got th same problem between:


1) Two SA 540 devices

2) Both SA 540 and a 520 device

What do you need more ?

SA Lifetime: 600 seconds

Encrypt: AES-256

Integr Alg.: SHA-512

PFS Key Group: Yes

DH Group 2 (1024 bit)

New Member

Re: Site-to-Site VPN with SA 540 and SA 520

Hi Stephane,

We ran the test for few hours with setup details you provided, and we are not seeing any disruption in traffic.

Is it possible for you to send the dbglogs from both the devices. To collect dbglogs, please log into SA500 web UI and in the URL type 

https://IP_address_of_SA500/scgi-bin/dbglog.cgi

Please save the file and send it to us. Please note this file will contain your passwords in clear text, so please change them before sending it over. Also you can send over to me through private email / message if you are not comfortable posting it here.

Please do send the network topology - this is just to make sure that we do the exact setup as yours.

Thanks,

Nitin.

New Member

Re: Site-to-Site VPN with SA 540 and SA 520

Hi,

Here are the files, I'll sent you a private message for zip password.

Both SA540 are connected to Internet using a XDSL modem.

Regards

New Member

Re: Site-to-Site VPN with SA 540 and SA 520

Up

Any idea ? This VPN should work fine quickly and I've got no solution :-(

New Member

Site-to-Site VPN with SA 540 and SA 520

So - did anyone ever answer this? I need to try exactly this setup over the upcoming weekend.

Thanks in advance!

Clay Jackson

clayj@nwlink.com

3916
Views
0
Helpful
6
Replies
CreatePlease to create content