Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

EasyVPN with VPN-Concentrator 3020 and 876w Router

I tried to configure EasyVPN with VPN-Concentrator 3020 (4.7) and 876w Router (IOS 12.4(4)T).

I followed the example "Configuring the Cisco EzVPN Client on Cisco IOS with the VPN 3000 Concentrator " at http://www.cisco.com/en/US/tech/tk583/tk372/technologies_configuration_example09186a00800945cf.shtml

we are getting Phase1 up but Phase2 is not established...

on the Router I see :

5d16h: ISAKMP (0:9): retransmitting phase 1 AG_INIT_EXCH

5d16h: ISAKMP (0:9): sending packet to 10.48.66.115 (I) AG_INIT_EXCH

as mentiond in the Document i checked the IKE-Proposals and the sa, but they are configured with Xauth......

What goes wrong ????

Thanks for any indea.

1 REPLY
Cisco Employee

Re: EasyVPN with VPN-Concentrator 3020 and 876w Router

Hi,

Router is getting stuck in Aggressive Mode Initialization Exchange.

Can you please get the concentrator debugs of IKE, IKEDBG, IPSEC & IPSECDBG for severities 1-13 and along with the full debugs of "deb cry isa" & "deb cry ipsec"

Thanks

Gilbert

139
Views
0
Helpful
1
Replies