cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
433
Views
0
Helpful
1
Replies

Lots of IKE proposals

nazghulin
Level 1
Level 1

Hi,

I'm having problems with a VPN between a Cisco PIX 501 and a Fortinet. It was working 2 days ago but now it doesn't come up. When executing the sh crypto isakmp sa command, a lot of proposals appear for the same VPN, with same source and destination with MM_NO_STATE

        dst               src                       state     pending     created

      192.168.1.2   xx.xx.xx.xx    MM_NO_STATE   0           0

     192.168.1.2    xx.xx.xx.xx    MM_NO_STATE   0           0

     192.168.1.2    xx.xx.xx.xx    MM_NO_STATE   0           0

     192.168.1.2    xx.xx.xx.xx    MM_NO_STATE   0           0

     192.168.1.2    xx.xx.xx.xx    MM_NO_STATE   0           0

     192.168.1.2    xx.xx.xx.xx    MM_NO_STATE   0           0

     192.168.1.2    xx.xx.xx.xx    MM_NO_STATE   0           0

     192.168.1.2    xx.xx.xx.xx    MM_NO_STATE   0           0

     192.168.1.2    xx.xx.xx.xx    MM_NO_STATE   0           0

     192.168.1.2    xx.xx.xx.xx    MM_NO_STATE   0           0

     192.168.1.2    xx.xx.xx.xx    MM_NO_STATE   0           0

     192.168.1.2    xx.xx.xx.xx    MM_NO_STATE   0           0

     192.168.1.2    xx.xx.xx.xx    MM_NO_STATE   0           0

     192.168.1.2    xx.xx.xx.xx    MM_NO_STATE   0           0

     192.168.1.2    xx.xx.xx.xx    MM_NO_STATE   0           0

     192.168.1.2    xx.xx.xx.xx    MM_NO_STATE   0           0

     192.168.1.2    xx.xx.xx.xx    MM_NO_STATE   0           0

     192.168.1.2    xx.xx.xx.xx    MM_NO_STATE   0           0

sh crypto ipsec sa shows a lot of send errors but no packet encapsulated or decapsulated.

Any ideas please?

1 Reply 1

Patrick0711
Level 3
Level 3

Turn the debugs on to see what's going on.

Suspecting that the Fortinet is sending numerous IKE P1 packets with separate cookie values.