08-06-2015 06:58 AM
Hi,
We're trying to establish vpn with azure's nvgre gateway but vpn is not established. Here is the log files any comments?
Regards.
Firewall# IKEv2-PROTO-1: (4):
IKEv2-PROTO-1: Invalid responder's spiIKEv2-PROTO-1: (4): Detected an invalid value in the packet
IKEv2-PROTO-1: (4):
IKEv2-PROTO-1: (4): A supplied parameter is incorrect
IKEv2-PROTO-1: (4):
IKEv2-PROTO-1: (4): Initial exchange failed
IKEv2-PROTO-1: (4): Initial exchange failed
IKEv2-PLAT-1: Failed to remove peer correlation entry from cikePeerCorrTable. Local Type = 0. Local Address = 0.0.0.0. Remote Type = 0. Remote Address = 0.0.0.0. Correlation Peer Index = 0. IPSEC Tunnel Index = 0.
IKEv2-PROTO-1: (5):
IKEv2-PROTO-1: Invalid responder's spiIKEv2-PROTO-1: (5): Detected an invalid value in the packet
IKEv2-PROTO-1: (5):
IKEv2-PROTO-1: (5): A supplied parameter is incorrect
IKEv2-PROTO-1: (5):
IKEv2-PROTO-1: (5): Initial exchange failed
IKEv2-PROTO-1: (5): Initial exchange failed
IKEv2-PLAT-1: Failed to remove peer correlation entry from cikePeerCorrTable. Local Type = 0. Local Address = 0.0.0.0. Remote Type = 0. Remote Address = 0.0.0.0. Correlation Peer Index = 0. IPSEC Tunnel Index = 0.
IKEv2-PROTO-1: (6):
IKEv2-PROTO-1: Invalid responder's spiIKEv2-PROTO-1: (6): Detected an invalid value in the packet
IKEv2-PROTO-1: (6):
IKEv2-PROTO-1: (6): A supplied parameter is incorrect
IKEv2-PROTO-1: (6):
IKEv2-PROTO-1: (6): Initial exchange failed
IKEv2-PROTO-1: (6): Initial exchange failed
IKEv2-PLAT-1: Failed to remove peer correlation entry from cikePeerCorrTable. Local Type = 0. Local Address = 0.0.0.0. Remote Type = 0. Remote Address = 0.0.0.0. Correlation Peer Index = 0. IPSEC Tunnel Index = 0.
Firewall#
Firewall# IKEv2-PROTO-1: (7):
IKEv2-PROTO-1: Invalid responder's spiIKEv2-PROTO-1: (7): Detected an invalid value in the packet
IKEv2-PROTO-1: (7):
IKEv2-PROTO-1: (7): A supplied parameter is incorrect
IKEv2-PROTO-1: (7):
IKEv2-PROTO-1: (7): Initial exchange failed
IKEv2-PROTO-1: (7): Initial exchange failed
IKEv2-PLAT-1: Failed to remove peer correlation entry from cikePeerCorrTable. Local Type = 0. Local Address = 0.0.0.0. Remote Type = 0. Remote Address = 0.0.0.0. Correlation Peer Index = 0. IPSEC Tunnel Index = 0.
12-20-2015 10:44 AM
Pls note that if on the Microsoft Azure side you are using dynamic routing then it will only try to establish the tunnel with the ASA using ikev2 only, it seems to be the case as per the above log/debug
If you are using Ikev1 on the ASA then you must use Static routing on the Azure side to bring the tunnel up with ikev1 without issues
If you definitely need to use dynamic routing for the site to site tunnel, then using ikev2 is the option.
I hope this helps!
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide