Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

unable to create a VPN

I'm having issues creating a VPN on my ASA5520. I get the following error message.

Mar 02 21:29:01 [IKEv1]: Group = X.X.X.X, IP = X.X.X.X, Removing peer from correlator table failed, no match!

Any ideas?

2 REPLIES
New Member

Re: unable to create a VPN

debug info....

Re: unable to create a VPN

Hi Joseph,

"Received non-routine Notify message: No proposal chosen (14)"

[IKEv1 DEBUG]: Group = X.X.X.66, IP = X.X.X.66, processing hash payload

[IKEv1 DEBUG]: Group = X.X.X.66, IP = X.X.X.66, processing delete

[IKEv1]: Group = X.X.X.66, IP = X.X.X.66, Connection terminated for peer X.X.X.66. Reason: Peer Terminate Remote Proxy

I looked at your crypto isakmp output and it seems to me the problem may reside in IKE policy so phase-1 complets but re-stars again in a second atempt which fails , I suggest both ends do check within the IKE policies encryption algorythm settings e.i hash, aes-256, dh group types , in other words anything to do with IKE policy do match at each end. Can you confirm the other end do agree with your IKE settings?

Rgds

Jorge

236
Views
0
Helpful
2
Replies