ā07-04-2013 10:59 PM - edited ā03-04-2019 08:23 PM
I have created two tunnels between 2 remote location:
one of them working pretty well but not the other:
here are the logs:
Jul 5 05:49:47.844: ISAKMP:(0): retransmitting phase 1 MM_NO_STATE...
Jul 5 05:49:47.844: ISAKMP (0): incrementing error counter on sa, attempt 4 of 5: retransmit phase 1
Jul 5 05:49:47.844: ISAKMP:(0): retransmitting phase 1 MM_NO_STATE
Jul 5 05:49:47.844: ISAKMP:(0): sending packet to 186.226.214.10 my_port 500 peer_port 500 (I) MM_NO_STATE
Jul 5 05:49:47.844: ISAKMP:(0):Sending an IKE IPv4 Packet.
Jul 5 05:49:57.660: ISAKMP:(0):purging node -1742526512
Jul 5 05:49:57.660: ISAKMP:(0):purging node -955876125
Jul 5 05:49:57.844: ISAKMP:(0): retransmitting phase 1 MM_NO_STATE...
Jul 5 05:49:57.844: ISAKMP (0): incrementing error counter on sa, attempt 5 of 5: retransmit phase 1
Jul 5 05:49:57.844: ISAKMP:(0): retransmitting phase 1 MM_NO_STATE
Jul 5 05:49:57.844: ISAKMP:(0): sending packet to 186.226.214.10 my_port 500 peer_port 500 (I) MM_NO_STATE
Jul 5 05:49:57.844: ISAKMP:(0):Sending an IKE IPv4 Packet.
Jul 5 05:50:07.660: ISAKMP:(0):purging SA., sa=280BABE0, delme=280BABE0
Jul 5 05:50:07.844: ISAKMP:(0): retransmitting phase 1 MM_NO_STATE...
Jul 5 05:50:07.844: ISAKMP:(0):peer does not do paranoid keepalives.
Jul 5 05:50:07.844: ISAKMP:(0):deleting SA reason "Death by retransmission P1" state (I) MM_NO_STATE (peer 186.226.214.10)
Jul 5 05:50:07.844: ISAKMP:(0):deleting SA reason "Death by retransmission P1" state (I) MM_NO_STATE (peer 186.226.214.10)
Jul 5 05:50:07.844: ISAKMP: Unlocking peer struct 0x3085CCF0 for isadb_mark_sa_deleted(), count 0
Jul 5 05:50:07.844: ISAKMP: Deleting peer node by peer_reap for 186.226.214.10: 3085CCF0
Jul 5 05:50:07.844: ISAKMP:(0):deleting node 601382680 error FALSE reason "IKE deleted"
Jul 5 05:50:07.844: ISAKMP:(0):deleting node -2075971693 error FALSE reason "IKE deleted"
Jul 5 05:50:07.844: ISAKMP:(0):Input = IKE_MESG_INTERNAL, IKE_PHASE1_DEL
Jul 5 05:50:07.844: ISAKMP:(0):Old State = IKE_I_MM1 New State = IKE_DEST_SA
Jul 5 05:50:12.288: ISAKMP:(0): SA request profile is (NULL)
Jul 5 05:50:12.288: ISAKMP: Created a peer struct for 186.226.214.10, peer port 500
Jul 5 05:50:12.288: ISAKMP: New peer created peer = 0x3085CCF0 peer_handle = 0x8000057B
Jul 5 05:50:12.288: ISAKMP: Locking peer struct 0x3085CCF0, refcount 1 for isakmp_initiator
Jul 5 05:50:12.288: ISAKMP: local port 500, remote port 500
Jul 5 05:50:12.288: ISAKMP: set new node 0 to QM_IDLE
Jul 5 05:50:12.288: ISAKMP: Find a dup sa in the avl tree during calling isadb_insert sa = 29128FD0
Jul 5 05:50:12.288: ISAKMP:(0):Can not start Aggressive mode, trying Main mode.
Jul 5 05:50:12.288: ISAKMP:(0):found peer pre-shared key matching 186.226.214.10
Jul 5 05:50:12.288: ISAKMP:(0): constructed NAT-T vendor-rfc3947 ID
Jul 5 05:50:12.288: ISAKMP:(0): constructed NAT-T vendor-07 ID
Jul 5 05:50:12.288: ISAKMP:(0): constructed NAT-T vendor-03 ID
Jul 5 05:50:12.288: ISAKMP:(0): constructed NAT-T vendor-02 ID
Jul 5 05:50:12.288: ISAKMP:(0):Input = IKE_MESG_FROM_IPSEC, IKE_SA_REQ_MM
Jul 5 05:50:12.288: ISAKMP:(0):Old State = IKE_READY New State = IKE_I_MM1
Jul 5 05:50:12.288: ISAKMP:(0): beginning Main Mode exchange
Jul 5 05:50:12.288: ISAKMP:(0): sending packet to 186.226.214.10 my_port 500 peer_port 500 (I) MM_NO_STATE
Jul 5 05:50:12.288: ISAKMP:(0):Sending an IKE IPv4 Packet.
Jul 5 05:50:22.288: ISAKMP:(0): retransmitting phase 1 MM_NO_STATE...
Jul 5 05:50:22.288: ISAKMP (0): incrementing error counter on sa, attempt 1 of 5: retransmit phase 1
Jul 5 05:50:22.288: ISAKMP:(0): retransmitting phase 1 MM_NO_STATE
Jul 5 05:50:22.288: ISAKMP:(0): sending packet to 186.226.214.10 my_port 500 peer_port 500 (I) MM_NO_STATE
Jul 5 05:50:22.288: ISAKMP:(0):Sending an IKE IPv4 Packet.
Jul 5 05:50:32.288: ISAKMP:(0): retransmitting phase 1 MM_NO_STATE...
Jul 5 05:50:32.288: ISAKMP (0): incrementing error counter on sa, attempt 2 of 5: retransmit phase 1
Jul 5 05:50:32.288: ISAKMP:(0): retransmitting phase 1 MM_NO_STATE
Jul 5 05:50:32.288: ISAKMP:(0): sending packet to 186.226.214.10 my_port 500 peer_port 500 (I) MM_NO_STATE
Jul 5 05:50:32.288: ISAKMP:(0):Sending an IKE IPv4 Packet.
Jul 5 05:50:42.288: ISAKMP:(0): retransmitting phase 1 MM_NO_STATE...
Jul 5 05:50:42.288: ISAKMP (0): incrementing error counter on sa, attempt 3 of 5: retransmit phase 1
Jul 5 05:50:42.288: ISAKMP:(0): retransmitting phase 1 MM_NO_STATE
Jul 5 05:50:42.288: ISAKMP:(0): sending packet to 186.226.214.10 my_port 500 peer_port 500 (I) MM_NO_STATE
Jul 5 05:50:42.288: ISAKMP:(0):Sending an IKE IPv4 Packet.
Jul 5 05:50:42.288: ISAKMP: set new node 0 to QM_IDLE
Jul 5 05:50:42.288: ISAKMP:(0):SA is still budding. Attached new ipsec request to it. (local 200.168.205.109, remote 186.226.214.10)
Jul 5 05:50:42.288: ISAKMP: Error while processing SA request: Failed to initialize SA
Jul 5 05:50:42.288: ISAKMP: Error while processing KMI message 0, error 2.
Jul 5 05:50:52.288: ISAKMP:(0): retransmitting phase 1 MM_NO_STATE...
Jul 5 05:50:52.288: ISAKMP (0): incrementing error counter on sa, attempt 4 of 5: retransmit phase 1
Jul 5 05:50:52.288: ISAKMP:(0): retransmitting phase 1 MM_NO_STATE
Jul 5 05:50:52.288: ISAKMP:(0): sending packet to 186.226.214.10 my_port 500 peer_port 500 (I) MM_NO_STATE
Jul 5 05:50:52.288: ISAKMP:(0):Sending an IKE IPv4 Packet.
Jul 5 05:50:57.844: ISAKMP:(0):purging node 601382680
Jul 5 05:50:57.844: ISAKMP:(0):purging node -2075971693
Jul 5 05:51:02.288: ISAKMP:(0): retransmitting phase 1 MM_NO_STATE...
Jul 5 05:51:02.288: ISAKMP (0): incrementing error counter on sa, attempt 5 of 5: retransmit phase 1
Jul 5 05:51:02.288: ISAKMP:(0): retransmitting phase 1 MM_NO_STATE
Jul 5 05:51:02.288: ISAKMP:(0): sending packet to 186.226.214.10 my_port 500 peer_port 500 (I) MM_NO_STATE
Jul 5 05:51:02.288: ISAKMP:(0):Sending an IKE IPv4 Packet.
Jul 5 05:51:07.844: ISAKMP:(0):purging SA., sa=290F5018, delme=290F5018
Jul 5 05:51:12.288: ISAKMP:(0): retransmitting phase 1 MM_NO_STATE...
Jul 5 05:51:12.288: ISAKMP:(0):peer does not do paranoid keepalives.
Jul 5 05:51:12.288: ISAKMP:(0):deleting SA reason "Death by retransmission P1" state (I) MM_NO_STATE (peer 186.226.214.10)
Jul 5 05:51:12.288: ISAKMP:(0):deleting SA reason "Death by retransmission P1" state (I) MM_NO_STATE (peer 186.226.214.10)
Jul 5 05:51:12.288: ISAKMP: Unlocking peer struct 0x3085CCF0 for isadb_mark_sa_deleted(), count 0
Jul 5 05:51:12.288: ISAKMP: Deleting peer node by peer_reap for 186.226.214.10: 3085CCF0
Jul 5 05:51:12.288: ISAKMP:(0):deleting node -128482521 error FALSE reason "IKE deleted"
Jul 5 05:51:12.288: ISAKMP:(0):deleting node -893189840 error FALSE reason "IKE deleted"
Jul 5 05:51:12.288: ISAKMP:(0):Input = IKE_MESG_INTERNAL, IKE_PHASE1_DEL
Jul 5 05:51:12.288: ISAKMP:(0):Old State = IKE_I_MM1 New State = IKE_DEST_SA
Jul 5 05:51:13.500: ISAKMP:(0): SA request profile is (NULL)
Jul 5 05:51:13.500: ISAKMP: Created a peer struct for 186.226.214.10, peer port 500
Jul 5 05:51:13.500: ISAKMP: New peer created peer = 0x3085CCF0 peer_handle = 0x8000057D
Jul 5 05:51:13.500: ISAKMP: Locking peer struct 0x3085CCF0, refcount 1 for isakmp_initiator
Jul 5 05:51:13.500: ISAKMP: local port 500, remote port 500
Jul 5 05:51:13.500: ISAKMP: set new node 0 to QM_IDLE
Jul 5 05:51:13.500: ISAKMP: Find a dup sa in the avl tree during calling isadb_insert sa = 280BABE0
Jul 5 05:51:13.500: ISAKMP:(0):Can not start Aggressive mode, trying Main mode.
Jul 5 05:51:13.500: ISAKMP:(0):found peer pre-shared key matching 186.226.214.10
Jul 5 05:51:13.500: ISAKMP:(0): constructed NAT-T vendor-rfc3947 ID
Jul 5 05:51:13.500: ISAKMP:(0): constructed NAT-T vendor-07 ID
Jul 5 05:51:13.500: ISAKMP:(0): constructed NAT-T vendor-03 ID
Jul 5 05:51:13.500: ISAKMP:(0): constructed NAT-T vendor-02 ID
Jul 5 05:51:13.500: ISAKMP:(0):Input = IKE_MESG_FROM_IPSEC, IKE_SA_REQ_MM
Jul 5 05:51:13.500: ISAKMP:(0):Old State = IKE_READY New State = IKE_I_MM1
Jul 5 05:51:13.500: ISAKMP:(0): beginning Main Mode exchange
Jul 5 05:51:13.500: ISAKMP:(0): sending packet to 186.226.214.10 my_port 500 peer_port 500 (I) MM_NO_STATE
Jul 5 05:51:13.500: ISAKMP:(0):Sending an IKE IPv4 Packet.
Jul 5 05:51:23.500: ISAKMP:(0): retransmitting phase 1 MM_NO_STATE...
Jul 5 05:51:23.500: ISAKMP (0): incrementing error counter on sa, attempt 1 of 5: retransmit phase 1
Jul 5 05:51:23.500: ISAKMP:(0): retransmitting phase 1 MM_NO_STATE
Jul 5 05:51:23.500: ISAKMP:(0): sending packet to 186.226.214.10 my_port 500 peer_port 500 (I) MM_NO_STATE
Jul 5 05:51:23.500: ISAKMP:(0):Sending an IKE IPv4 Packet.
Regards
ā07-04-2013 11:29 PM
Could post the config of both sides? As well as a diagram?
ā07-04-2013 11:37 PM - edited ā04-05-2018 12:34 AM
here is the config : for VPN4
here the layout:
ā07-04-2013 11:59 PM
If you have an ISP providing the link, your "tunnel destination" should be your ISP's interface.
Normally, I would set the Loopback IP address as my "tunnel source".
ā07-05-2013 12:04 AM
I have the tunnel destination : ip from from ISP interface.
I never used loopback interface for tunnels.
here are my debug logggs:
Jul 5 05:41:22.373: ISAKMP: life duration (VPI) of 0x0 0x1 0x51 0x80
Jul 5 05:41:22.373: ISAKMP:(0):atts are acceptable. Next payload is 0
Jul 5 05:41:22.373: ISAKMP:(0):Acceptable atts:actual life: 0
Jul 5 05:41:22.373: ISAKMP:(0):Acceptable atts:life: 0
Jul 5 05:41:22.373: ISAKMP:(0):Fill atts in sa vpi_length:4
Jul 5 05:41:22.373: ISAKMP:(0):Fill atts in sa life_in_seconds:86400
Jul 5 05:41:22.373: ISAKMP:(0):Returning Actual lifetime: 86400
Jul 5 05:41:22.373: ISAKMP:(0)::Started lifetime timer: 86400.
Jul 5 05:41:22.373: ISAKMP:(0): processing vendor id payload
Jul 5 05:41:22.373: ISAKMP:(0): vendor ID seems Unity/DPD but major 69 mismatch
Jul 5 05:41:22.373: ISAKMP (0): vendor ID is NAT-T RFC 3947
Jul 5 05:41:22.373: ISAKMP:(0): processing vendor id payload
Jul 5 05:41:22.373: ISAKMP:(0): vendor ID seems Unity/DPD but major 245 mismatch
Jul 5 05:41:22.373: ISAKMP (0): vendor ID is NAT-T v7
Jul 5 05:41:22.373: ISAKMP:(0): processing vendor id payload
Jul 5 05:41:22.373: ISAKMP:(0): vendor ID seems Unity/DPD but major 157 mismatch
Jul 5 05:41:22.373: ISAKMP:(0): vendor ID is NAT-T v3
Jul 5 05:41:22.373: ISAKMP:(0): processing vendor id payload
Jul 5 05:41:22.373: ISAKMP:(0): vendor ID seems Unity/DPD but major 123 mismatch
Jul 5 05:41:22.373: ISAKMP:(0): vendor ID is NAT-T v2
Jul 5 05:41:22.373: ISAKMP:(0):Input = IKE_MESG_INTERNAL, IKE_PROCESS_MAIN_MODE
Jul 5 05:41:22.373: ISAKMP:(0):Old State = IKE_R_MM1 New State = IKE_R_MM1
Jul 5 05:41:22.373: ISAKMP:(0): constructed NAT-T vendor-rfc3947 ID
Jul 5 05:41:22.373: ISAKMP:(0): sending packet to 200.168.205.109 my_port 500 peer_port 500 (R) MM_SA_SETUP
Jul 5 05:41:22.373: ISAKMP:(0):Sending an IKE IPv4 Packet.
Jul 5 05:41:22.373: ISAKMP:(0):Input = IKE_MESG_INTERNAL, IKE_PROCESS_COMPLETE
Jul 5 05:41:22.373: ISAKMP:(0):Old State = IKE_R_MM1 New State = IKE_R_MM2
Jul 5 05:41:22.837: ISAKMP:(0): retransmitting phase 1 MM_SA_SETUP...
Jul 5 05:41:22.837: ISAKMP:(0):peer does not do paranoid keepalives.
Jul 5 05:41:22.837: ISAKMP:(0):deleting SA reason "Death by retransmission P1" state (R) MM_SA_SETUP (peer 200.168.205.109)
Jul 5 05:41:22.837: ISAKMP:(0):deleting SA reason "Death by retransmission P1" state (R) MM_SA_SETUP (peer 200.168.205.109)
Jul 5 05:41:22.837: ISAKMP: Unlocking peer struct 0x291AF64C for isadb_mark_sa_deleted(), count 0
Jul 5 05:41:22.837: ISAKMP: Deleting peer node by peer_reap for 200.168.205.109: 291AF64C
Jul 5 05:41:22.837: ISAKMP:(0):Input = IKE_MESG_INTERNAL, IKE_PHASE1_DEL
Jul 5 05:41:22.837: ISAKMP:(0):Old State = IKE_R_MM2 New State = IKE_DEST_SA
Jul 5 05:41:24.973: ISAKMP:(0): retransmitting phase 1 MM_NO_STATE...
Jul 5 05:41:24.973: ISAKMP (0): incrementing error counter on sa, attempt 1 of 5: retransmit phase 1
Jul 5 05:41:24.973: ISAKMP:(0): retransmitting phase 1 MM_NO_STATE
Jul 5 05:41:24.973: ISAKMP:(0): sending packet to 200.168.205.109 my_port 500 peer_port 500 (I) MM_NO_STATE
Jul 5 05:41:24.973: ISAKMP:(0):Sending an IKE IPv4 Packet.
Jul 5 05:41:32.369: ISAKMP (0): received packet from 200.168.205.109 dport 500 sport 500 Global (R) MM_SA_SETUP
Jul 5 05:41:32.369: ISAKMP:(0): phase 1 packet is a duplicate of a previous packet.
Jul 5 05:41:32.369: ISAKMP:(0): retransmitting due to retransmit phase 1
Jul 5 05:41:32.869: ISAKMP:(0): retransmitting phase 1 MM_SA_SETUP...
Jul 5 05:41:32.869: ISAKMP (0): incrementing error counter on sa, attempt 1 of 5: retransmit phase 1
Jul 5 05:41:32.869: ISAKMP:(0): retransmitting phase 1 MM_SA_SETUP
Jul 5 05:41:32.869: ISAKMP:(0): sending packet to 200.168.205.109 my_port 500 peer_port 500 (R) MM_SA_SETUP
Jul 5 05:41:32.869: ISAKMP:(0):Sending an IKE IPv4 Packet.
Jul 5 05:41:34.973: ISAKMP:(0): retransmitting phase 1 MM_NO_STATE...
Jul 5 05:41:34.973: ISAKMP (0): incrementing error counter on sa, attempt 2 of 5: retransmit phase 1
Jul 5 05:41:34.973: ISAKMP:(0): retransmitting phase 1 MM_NO_STATE
Jul 5 05:41:34.973: ISAKMP:(0): sending packet to 200.168.205.109 my_port 500 peer_port 500 (I) MM_NO_STATE
Jul 5 05:41:34.973: ISAKMP:(0):Sending an IKE IPv4 Packet.
Jul 5 05:41:42.377: ISAKMP (0): received packet from 200.168.205.109 dport 500 sport 500 Global (R) MM_SA_SETUP
Jul 5 05:41:42.377: ISAKMP:(0): phase 1 packet is a duplicate of a previous packet.
Jul 5 05:41:42.377: ISAKMP:(0): retransmitting due to retransmit phase 1
Jul 5 05:41:42.877: ISAKMP:(0): retransmitting phase 1 MM_SA_SETUP...
Jul 5 05:41:42.877: ISAKMP (0): incrementing error counter on sa, attempt 2 of 5: retransmit phase 1
Jul 5 05:41:42.877: ISAKMP:(0): retransmitting phase 1 MM_SA_SETUP
Jul 5 05:41:42.877: ISAKMP:(0): sending packet to 200.168.205.109 my_port 500 peer_port 500 (R) MM_SA_SETUP
Jul 5 05:41:42.877: ISAKMP:(0):Sending an IKE IPv4 Packet.
Jul 5 05:41:44.973: ISAKMP: set new node 0 to QM_IDLE
Jul 5 05:41:44.973: ISAKMP:(0):SA is still budding. Attached new ipsec request to it. (local 186.226.214.10, remote 200.168.205.109)
Jul 5 05:41:44.973: ISAKMP: Error while processing SA request: Failed to initialize SA
Jul 5 05:41:44.973: ISAKMP: Error while processing KMI message 0, error 2.
Jul 5 05:41:44.973: ISAKMP:(0): retransmitting phase 1 MM_NO_STATE...
Jul 5 05:41:44.973: ISAKMP (0): incrementing error counter on sa, attempt 3 of 5: retransmit phase 1
Jul 5 05:41:44.973: ISAKMP:(0): retransmitting phase 1 MM_NO_STATE
Jul 5 05:41:44.973: ISAKMP:(0): sending packet to 200.168.205.109 my_port 500 peer_port 500 (I) MM_NO_STATE
Jul 5 05:41:44.973: ISAKMP:(0):Sending an IKE IPv4 Packet.
Jul 5 05:41:52.365: ISAKMP (0): received packet from 200.168.205.109 dport 500 sport 500 Global (R) MM_SA_SETUP
Jul 5 05:41:52.365: ISAKMP:(0): phase 1 packet is a duplicate of a previous packet.
Jul 5 05:41:52.365: ISAKMP:(0): retransmitting due to retransmit phase 1
Jul 5 05:41:52.865: ISAKMP:(0): retransmitting phase 1 MM_SA_SETUP...
Jul 5 05:41:52.865: ISAKMP (0): incrementing error counter on sa, attempt 3 of 5: retransmit phase 1
Jul 5 05:41:52.865: ISAKMP:(0): retransmitting phase 1 MM_SA_SETUP
Jul 5 05:41:52.865: ISAKMP:(0): sending packet to 200.168.205.109 my_port 500 peer_port 500 (R) MM_SA_SETUP
Jul 5 05:41:52.865: ISAKMP:(0):Sending an IKE IPv4 Packet.
Jul 5 05:41:54.973: ISAKMP:(0): retransmitting phase 1 MM_NO_STATE...
Jul 5 05:41:54.973: ISAKMP (0): incrementing error counter on sa, attempt 4 of 5: retransmit phase 1
Jul 5 05:41:54.973: ISAKMP:(0): retransmitting phase 1 MM_NO_STATE
Jul 5 05:41:54.973: ISAKMP:(0): sending packet to 200.168.205.109 my_port 500 peer_port 500 (I) MM_NO_STATE
Jul 5 05:41:54.973: ISAKMP:(0):Sending an IKE IPv4 Packet.
Jul 5 05:42:00.729: ISAKMP:(0):purging node -1455087230
Jul 5 05:42:00.729: ISAKMP:(0):purging node -880088908
I dont know ahy is its bloking phase 1 on port 500.
Regards
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide