<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd"
xmlns:rawvoice="http://www.rawvoice.com/rawvoiceRssModule/"
	>
<channel>
	<title>Comments on: Hit a Wall- EasyVPN problems</title>
	<atom:link href="http://globalconfig.net/2008/08/05/hit-a-wall-easyvpn-problems/feed/" rel="self" type="application/rss+xml" />
	<link>http://globalconfig.net/ccie-security/hit-a-wall-easyvpn-problems/</link>
	<description>Studying for Network Certifications</description>
	<lastBuildDate>Thu, 01 Dec 2011 17:41:40 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: Joey Boyer</title>
		<link>http://globalconfig.net/ccie-security/hit-a-wall-easyvpn-problems/#comment-82</link>
		<dc:creator>Joey Boyer</dc:creator>
		<pubDate>Wed, 06 Aug 2008 17:06:28 +0000</pubDate>
		<guid isPermaLink="false">http://cciestudy.brandonjcarroll.com/2008/08/05/hit-a-wall-easyvpn-problems/#comment-82</guid>
		<description>&lt;p&gt;Stretch is on the right track afaik.  If it hasn&#039;t cleared itself by the time you get back to it you may want to shut the tunnels, clear crypto, wait a few and open the tunnels back up.  Usually does the trick...&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>Stretch is on the right track afaik.  If it hasn&#8217;t cleared itself by the time you get back to it you may want to shut the tunnels, clear crypto, wait a few and open the tunnels back up.  Usually does the trick&#8230;</p>]]></content:encoded>
	</item>
	<item>
		<title>By: Brandon</title>
		<link>http://globalconfig.net/ccie-security/hit-a-wall-easyvpn-problems/#comment-81</link>
		<dc:creator>Brandon</dc:creator>
		<pubDate>Wed, 06 Aug 2008 13:24:36 +0000</pubDate>
		<guid isPermaLink="false">http://cciestudy.brandonjcarroll.com/2008/08/05/hit-a-wall-easyvpn-problems/#comment-81</guid>
		<description>&lt;p&gt;@stretch  Thanks for that stretch.  I&#039;m gonna jump back on the racks as soon as I get into the office and see what goes.  its weird that an IKEDBG shows phase 1 looking ok but absolutley NOTHING for phase 2.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>@stretch  Thanks for that stretch.  I&#8217;m gonna jump back on the racks as soon as I get into the office and see what goes.  its weird that an IKEDBG shows phase 1 looking ok but absolutley NOTHING for phase 2.</p>]]></content:encoded>
	</item>
	<item>
		<title>By: stretch</title>
		<link>http://globalconfig.net/ccie-security/hit-a-wall-easyvpn-problems/#comment-80</link>
		<dc:creator>stretch</dc:creator>
		<pubDate>Wed, 06 Aug 2008 08:05:56 +0000</pubDate>
		<guid isPermaLink="false">http://cciestudy.brandonjcarroll.com/2008/08/05/hit-a-wall-easyvpn-problems/#comment-80</guid>
		<description>&lt;p&gt;Just a shot in the dark, but it could be that the local and remote peers had an ISAKMP SA established at one point and the local peer tore it down uncleanly for whatever reason. The remote peer, thinking it still has an active SA, continues to send ISAKMP traffic to the local peer. So when the local peer receives an ISAKMP packet even though it doesn&#039;t currently have an SA with that peer, it goes &quot;WTF, mate?&quot; and drops it.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>Just a shot in the dark, but it could be that the local and remote peers had an ISAKMP SA established at one point and the local peer tore it down uncleanly for whatever reason. The remote peer, thinking it still has an active SA, continues to send ISAKMP traffic to the local peer. So when the local peer receives an ISAKMP packet even though it doesn&#8217;t currently have an SA with that peer, it goes &#8220;WTF, mate?&#8221; and drops it.</p>]]></content:encoded>
	</item>
</channel>
</rss>

