Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

Easy VPN remote (837 to VPN 3000)

I am attempting to connect a Cisco 837 in Network Extension mode to a VPN 3000 at our main office. I cant even get past phase 1. I need assistance configuring the VPN remote please.

The following is from the log:

Oct 1 15:29:38.807: ISAKMP:(0:19:HW:2): beginning Aggressive Mode exchange

Oct 1 15:29:38.815: ISAKMP:(0:19:HW:2): sending packet to xx.xx.xx.xx my_port

500 peer_port 500 (I) AG_INIT_EXCH

Oct 1 15:29:38.815: ISAKMP: received ke message (1/1)

Oct 1 15:29:38.815: ISAKMP:(0:19:HW:2):SA is still budding. Attached new ipsec

request to it. (local xx.xx.xx.xx, remote xx.xx.xx.xx)

Oct 1 15:29:48.815: ISAKMP:(0:19:HW:2): retransmitting phase 1 AG_INIT_EXCH...

Oct 1 15:29:48.815: ISAKMP:(0:19:HW:2):incrementing error counter on sa: retran

smit phase 1

Oct 1 15:29:48.815: ISAKMP:(0:19:HW:2): retransmitting phase 1 AG_INIT_EXCH

Oct 1 15:29:48.815: ISAKMP:(0:19:HW:2): sending packet to XX.XX.XX.XX my_port

500 peer_port 500 (I) AG_INIT_EXCH

6 REPLIES

Re: Easy VPN remote (837 to VPN 3000)

Hi

This device is trying to start phase1 but the other device is not responding. I guest the other device is the VPN3000. Is the VPN3000 accepting vpnclient at present time or is this a new installation. If the 3000 is working, please post relevant config of the 837.

Might help to have the vpn3000 log too!

New Member

Re: Easy VPN remote (837 to VPN 3000)

thanks for your post

I will look into that. I was wondering if this could be due to an access list (should be on 837)that needs to allow UDP and ESP as some of the configs suggest? None of the EZVPN configs suggest this, but the L2L do.

New Member

Re: Easy VPN remote (837 to VPN 3000)

Here are the logs for the 837 as well as the VPN 3000. Hope this makes things clearer.

Thanks for your assistance

Marty

New Member

Re: Easy VPN remote (837 to VPN 3000)

I am having the exact same problem. However if I take the config and place it on a 1700 or 1800 series router, using the same group configuration on the VPN 3015 it works.

New Member

Re: Easy VPN remote (837 to VPN 3000)

I have about 15 soho 91 routers(equivalent to 831) connecting this same way with no problem. The are two differences I see in your config compared to mine, maybe it is just because I am using 12.4 not sure.

On the client under the ezvpn config I have

xauth userid mode local

I have that username configured on the local router.

And my nat statement is referencing my route-map

ip nat inside source route-map EZVPN interface overload

!

access-list 177 deny ip any

route-map EZVPN permit 10

match ip address 177

Not sure if that will help but it is working for me.

Re: Easy VPN remote (837 to VPN 3000)

Hi

After reviewing the log, your first problem is that the router is not receiving the concentrator packet.

Oct 1 15:29:48.815: ISAKMP:(0:19:HW:2): retransmitting phase 1 AG_INIT_EXCH

Oct 1 15:29:48.815: ISAKMP:(0:19:HW:2): sending packet to XX.XX.XX.XX my_port

500 peer_port 500 (I) AG_INIT_EXCH

Look at these line, you ll fing in your VPN3000 log file something like this

23874 10/02/2006 12:21:43.740 SEV=6 IKE/202 RPT=6774 **Router 837 IP Address**

Duplicate first packet detected. Ignoring packet.

This tells you that the vpn3000 is receiving packet but the 800 router is not receivign the 3000 packets. Fisrt step is to find out if the 3000 can reach the 800 using ICMP. Second, try to open up ACL for UDP port 500. My guess is that the 800 router is droping the inbound isakmp packet.

490
Views
0
Helpful
6
Replies
CreatePlease login to create content