Studying for Cisco Certifications or Just Making Stuff Work!

  • HomeRecent Posts
  • AboutFind out more about me.
  • Contact MeUse this form to contact me.
  • SubscribeWays to follow me.

August 5, 2008
Posted by bcarroll

Hit a Wall- EasyVPN problems

Anyone know what this means?


r3#cry ipsec client ezvpn connect    
r3#
*Mar  2 03:50:02.867: %CRYPTO-4-IKMP_NO_SA: IKE message from
136.8.113.11    has no SA and is not an initialization offer

I have no idea whats going on.

Its a VPN from the R3 seen here to a 3000 series concentrator.  IKEDBG on the concentrator says IKE is successful.  I think its the ipsec SA but not sure.  I guess Ill put some fresh eyes on it tomorrow.

3 Comments

Posted Under CCIE Security IE Labs

3 Comments

stretch
August 6, 2008

Just a shot in the dark, but it could be that the local and remote peers had an ISAKMP SA established at one point and the local peer tore it down uncleanly for whatever reason. The remote peer, thinking it still has an active SA, continues to send ISAKMP traffic to the local peer. So when the local peer receives an ISAKMP packet even though it doesn’t currently have an SA with that peer, it goes “WTF, mate?” and drops it.

Brandon
August 6, 2008

@stretch Thanks for that stretch. I’m gonna jump back on the racks as soon as I get into the office and see what goes. its weird that an IKEDBG shows phase 1 looking ok but absolutley NOTHING for phase 2.

Joey Boyer
August 6, 2008

Stretch is on the right track afaik. If it hasn’t cleared itself by the time you get back to it you may want to shut the tunnels, clear crypto, wait a few and open the tunnels back up. Usually does the trick…

Leave a comment

* = Required

    • Posts
    • Twitter
    • Flickr
     

    Configuring...

    Cisco ASA

     

    Woes with VoIP

    Rants

     

    Roundup of my mind...

    General

    @santinorizzo Usually I use a router as a DNS Server. That i can do!

    follow me on
    twitter

    CCIE Security Students
  • Categories

    • BCMSN
    • BSCI
    • CCIE General
      • Recognition
    • CCIE General
    • CCIE Routing and Switching
    • CCIE Security
      • IE Labs
      • IPExpert Information
    • CCIE Service Provider
    • CCIE Voice
    • CCIE Wireless
    • CCNA Corner
    • CCNP Study
    • CCSP Study
    • CCVP Study
    • CIPT1
    • Cisco ASA
    • CiscoLive
    • CiscoPress
    • Contests
    • General
    • General Information
    • General Training
    • IE ATC-CoD
    • IE Information
    • IPExpert Labs
    • iphone
    • IPv6
    • ISCW
    • Links
    • MacTips
    • MARS
    • News
    • ONT
    • Polls
    • QOS
    • Question for Readers
    • Rants
    • Reading List
    • Scripting
    • Security
      • IPS
    • SNAF
    • SND
    • SNPA
    • SNRS
    • Studies In VPN
    • TipTorials
    • Travel
    • Wireless Zone
  • Archives

    • 2010
      • January
      • February
      • August
      • September
    • 2009
      • January
      • February
      • March
      • April
      • May
      • June
      • July
      • August
      • September
      • October
      • December
    • 2008
      • February
      • March
      • April
      • May
      • June
      • July
      • August
      • September
      • October
      • November
      • December

This site is using the Handgloves WordPress Theme
Designed & Developed by George Wiscombe

Subscribe via RSS