<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>[Config] Client VPN problems on Cisco 1720 in Cisco</title>
<link>http://www.dslreports.com/forum/r20760708</link>
<description></description>
<language>en</language>
<pubDate>Wed, 03 Dec 2008 02:42:23 EDT</pubDate>
<lastBuildDate>Wed, 03 Dec 2008 02:42:23 EDT</lastBuildDate>

<item>
<title>Re: [Config] Client VPN problems on Cisco 1720</title>
<link>http://www.dslreports.com/forum/remark,20789597</link>
<description><![CDATA[<A HREF="/useremail/u/1499752"><b>kamikatze</b></A> : Make sure the dynamic crypto map has the lowest priority of all.<br><br>Something like this<br>crypto map map-static-1 1139 ipsec-isakmp<br>crypto map map-static-1 1140 ipsec-isakmp<br>crypto map map-static-1 1144 ipsec-isakmp<br>crypto map map-vpnclient-1 3000 ipsec-isakmp dynamic vpn_client]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20789597</guid>
<pubDate>Mon, 14 Jul 2008 14:07:13 EDT</pubDate>
</item>

<item>
<title>Re: [Config] Client VPN problems on Cisco 1720</title>
<link>http://www.dslreports.com/forum/remark,20788087</link>
<description><![CDATA[<A HREF="/useremail/u/1464423"><b>kubaff</b></A> : <br> Am not sure if it's picking from <br><br>1. crypto map cm-cryptomap isakmp authorization list groupauthor  <br><br>or<br><br>2. crypto isakmp client configuration group VPNclient  <br>   key folco123]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20788087</guid>
<pubDate>Mon, 14 Jul 2008 09:11:23 EDT</pubDate>
</item>

<item>
<title>Re: [Config] Client VPN problems on Cisco 1720</title>
<link>http://www.dslreports.com/forum/remark,20787996</link>
<description><![CDATA[<A HREF="/useremail/u/1464423"><b>kubaff</b></A> : Based on the link below, you might try and confirm the pre-shared keys on both sides.<br><br>&raquo;<A HREF="http://www.cisco.com/en/US/tech/tk583/tk372/technologies_configuration_example09186a0080094525.shtml" >www.cisco.com/en/US/tech/tk583/t&middot;&middot;&middot;25.shtml</A>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20787996</guid>
<pubDate>Mon, 14 Jul 2008 08:43:13 EDT</pubDate>
</item>

<item>
<title>Re: [Config] Client VPN problems on Cisco 1720</title>
<link>http://www.dslreports.com/forum/remark,20777226</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : Scratch that, it is only working from one network, not from any others.  From tho customer PC we get:<br>[code]<br>###.###.###.81   ###.###.###.144  AG_INIT_EXCH         1    0<br>...<br>So different, but still not connecting.<br><br>Back to square one.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20777226</guid>
<pubDate>Fri, 11 Jul 2008 18:56:17 EDT</pubDate>
</item>

<item>
<title>Re: [Config] Client VPN problems on Cisco 1720</title>
<link>http://www.dslreports.com/forum/remark,20775809</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : So after this was reviewed by everyone in our company who know even a smidge about Cisco's we decided to test from a different network.  This time it worked without issue.<br><br>I'm not sure why this isn't working from our DSL test lab; we have other connections that work without trouble from there.  If anyone has any theories I would love to know.  I am no longer seeking a solution at this point though.<br><br>Thank you all for your assistance.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20775809</guid>
<pubDate>Fri, 11 Jul 2008 13:57:13 EDT</pubDate>
</item>

<item>
<title>Re: [Config] Client VPN problems on Cisco 1720</title>
<link>http://www.dslreports.com/forum/remark,20774912</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : I'm confused about what you are asking.  Are you wondering if I can ping the outside of the router from the client?  I can do that.  There isn't really any way to ping in the other direction because the computer is on the inside of a network.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20774912</guid>
<pubDate>Fri, 11 Jul 2008 11:29:38 EDT</pubDate>
</item>

<item>
<title>Re: [Config] Client VPN problems on Cisco 1720</title>
<link>http://www.dslreports.com/forum/remark,20773718</link>
<description><![CDATA[<A HREF="/useremail/u/1464423"><b>kubaff</b></A> : <br>It looks as though the first phase (ISAKMP) of the security association isn't even coming up<br><br>Can you ping from the client to the remote side then ran the command again ?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20773718</guid>
<pubDate>Fri, 11 Jul 2008 05:40:02 EDT</pubDate>
</item>

<item>
<title>Re: [Config] Client VPN problems on Cisco 1720</title>
<link>http://www.dslreports.com/forum/remark,20770033</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : There didn't end up being any related data about this connection in <b>sh crypto ipsec sa</b>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20770033</guid>
<pubDate>Thu, 10 Jul 2008 13:24:23 EDT</pubDate>
</item>

<item>
<title>Re: [Config] Client VPN problems on Cisco 1720</title>
<link>http://www.dslreports.com/forum/remark,20769974</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : This is the pertinent line in <b>sh crypto isakmp sa</b>:<br><textarea name="code" class="text" cols=50 rows=10>###.###.###.81   ###.###.###.250   AG_NO_STATE          5    0&#012;</textarea><!--end code block--><br>The ACLs for the VPN I think are correct.  The ACL match addresses you are referring to are all for the store to store VPNs, which don't have a problem.  We have ACL 199 for <b>crypto isakmp client</b>:<br><textarea name="code" class="text" cols=50 rows=10>crypto isakmp client configuration group VPNclient&#012; key ########&#012; dns 148.74.252.7&#012; pool ippool&#012; acl 199&#012;.......&#012;ip local pool ippool 10.10.10.1 10.10.10.254&#012;.......&#012;access-list 199 permit ip 192.168.230.0 0.0.0.255 10.10.10.0 0.0.0.255&#012;</textarea><!--end code block-->]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20769974</guid>
<pubDate>Thu, 10 Jul 2008 13:15:09 EDT</pubDate>
</item>

<item>
<title>Re: [Config] Client VPN problems on Cisco 1720</title>
<link>http://www.dslreports.com/forum/remark,20769631</link>
<description><![CDATA[<A HREF="/useremail/u/557302"><b>zno</b></A> : ACLs 103-107 & 111 are being applied to VPN tunnels.  it doesn't matter whether you apply these to the serial interface or not.  these ACLs control what gets in and out of your VPN tunnels.  check your VPN ACLs if you haven't already done so.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20769631</guid>
<pubDate>Thu, 10 Jul 2008 12:13:41 EDT</pubDate>
</item>

<item>
<title>Re: [Config] Client VPN problems on Cisco 1720</title>
<link>http://www.dslreports.com/forum/remark,20768195</link>
<description><![CDATA[<A HREF="/useremail/u/1464423"><b>kubaff</b></A> : please post the following<br><br>1. show crypto isakmp sa<br>2. show crypto ipsec sa<br><br>this will help narrow down on where the mismatch is occuring]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20768195</guid>
<pubDate>Thu, 10 Jul 2008 02:42:54 EDT</pubDate>
</item>

<item>
<title>Re: [Config] Client VPN problems on Cisco 1720</title>
<link>http://www.dslreports.com/forum/remark,20766409</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : I tried setting policy three to use md5 hash with no luck.  I think this one uses the standard SHA because it is a VPN Client rather than a store to store VPN between routers like all the others.<br><br>Here is the pertinent state change in a router nearly identical to the one I am having a problem with.<br><br><textarea name="code" class="text" cols=50 rows=10>10:28:03: ISAKMP (0:4): Checking ISAKMP transform 9 against priority 3 policy&#012;10:28:03: ISAKMP:      encryption 3DES-CBC&#012;10:28:03: ISAKMP:      hash SHA&#012;10:28:03: ISAKMP:      default group 2&#012;10:28:03: ISAKMP:      auth XAUTHInitPreShared&#012;10:28:03: ISAKMP:      life type in seconds&#012;10:28:03: ISAKMP:      life duration (VPI) of  0x0 0x20 0xC4 0x9B &#012;10:28:03: ISAKMP (0:4): atts are acceptable. Next payload is 3&#012;10:28:03: ISAKMP (0:4): processing KE payload. message ID = 0&#012;10:28:03: ISAKMP (0:4): processing NONCE payload. message ID = 0&#012;10:28:03: ISAKMP (0:4): processing vendor id payload&#012;10:28:03: ISAKMP (0:4): processing vendor id payload&#012;10:28:03: ISAKMP (0:4): processing vendor id payload&#012;10:28:03: ISAKMP (0:4): processing vendor id payload&#012;10:28:03: ISAKMP (0:4): processing vendor id payload&#012;10:28:03: ISAKMP (0:4): Input = IKE_MESG_FROM_PEER, IKE_AM_EXCH&#012;Old State = IKE_READY  New State = IKE_R_AM_AAA_AWAIT &#012;</textarea><!--end code block--><br>On this one the policy three is identical to the problem router.  Here is the same section from the log on the bad router:<br><br><textarea name="code" class="text" cols=50 rows=10>00:53:05: ISAKMP (0:3): Checking ISAKMP transform 9 against priority 3 policy&#012;00:53:05: ISAKMP:      encryption 3DES-CBC&#012;00:53:05: ISAKMP:      hash SHA&#012;00:53:05: ISAKMP:      default group 2&#012;00:53:05: ISAKMP:      auth XAUTHInitPreShared&#012;00:53:05: ISAKMP:      life type in seconds&#012;00:53:05: ISAKMP:      life duration (VPI) of  0x0 0x20 0xC4 0x9B &#012;00:53:05: ISAKMP (0:3): Xauth authentication by pre-shared key offered but does not match policy!&#012;00:53:05: ISAKMP (0:3): atts are not acceptable. Next payload is 3&#012;</textarea><!--end code block--><br>I think this is mhere is it supposed to match, but no luck.  Like I said, these routers are nearly identical, right down to the fact that they both have miltiple remotes and are attached to T1 lines.  I just can't figure out what the difference is.  I can post the other if anyone cares to look.<br><br>As to the ACL, it is not currently enabled on the Serial0.1 interface, maybe I'm misunderstanding what you are saying.  Please let me know if there is something I am missing.<br>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20766409</guid>
<pubDate>Wed, 09 Jul 2008 19:27:36 EDT</pubDate>
</item>

<item>
<title>Re: [Config] Client VPN problems on Cisco 1720</title>
<link>http://www.dslreports.com/forum/remark,20763529</link>
<description><![CDATA[<A HREF="/useremail/u/557302"><b>zno</b></A> : i'm purely speculating here since i don't know your entire setup...<br><br>how about adding "hash md5" to the crypto policy 3?  just to be consistent with your transform sets.<br>also from the debug, line 816 seems to indicate that you have mismatching hash.  <br><br>if this still doesn't fix your prob, check ACLs and see if you have any matching traffic while a client is trying to connect.<br><small>--<br>got anti-virus and firewall?</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20763529</guid>
<pubDate>Wed, 09 Jul 2008 10:48:50 EDT</pubDate>
</item>

<item>
<title>Re: [Config] Client VPN problems on Cisco 1720</title>
<link>http://www.dslreports.com/forum/remark,20763436</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : The other tunnels are Cisco to Cisco connections, those all work.  The PC we are using to test the tunnel is behind a NAT, but it is able to form a VPN client tunnel to several other sites.<br><br>It does seem like the logs indicate a mismatch, but strangely this is the same setup for all of our sites:<br><br>crypto isakmp policy 3   <br> encr 3des   <br> authentication pre-share   <br> group 2   <br><br>Thanks,<br>Conn]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20763436</guid>
<pubDate>Wed, 09 Jul 2008 10:30:55 EDT</pubDate>
</item>

<item>
<title>Re: [Config] Client VPN problems on Cisco 1720</title>
<link>http://www.dslreports.com/forum/remark,20763092</link>
<description><![CDATA[<A HREF="/useremail/u/1464423"><b>kubaff</b></A> : Looks like you have several VPN tunnels. Which one in particular are you trying to connect to ? <br><br>There seems to be a ISAKMP policy mismatch between the VPN server and client based on the logs.<br><br>I would verify the ACCESS-LIST on each ISAKMP policy to make sure no NAT is happenin within the VPN tunnel.<br><br>Does each peer still have the same initial OUTSIDE IP ?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20763092</guid>
<pubDate>Wed, 09 Jul 2008 09:13:55 EDT</pubDate>
</item>

<item>
<title>[Config] Client VPN problems on Cisco 1720</title>
<link>http://www.dslreports.com/forum/remark,20760708</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : I've been working on this for several days now and feel I'm not any closer to a solution.  I have a site which has been running a client VPN for years without trouble suddenly can no longer function.  They hadn't tried it in a while, but soon before they reported it we did add a new NAT overload and they had been upgraded to IOS 12.4 19 (they since have been brought back down again.  <br><br>Any help would be appreciated.  Here is the config (edited for IPs keys and passwords), the version, and the log (edited for IPs)<br><textarea name="code" class="text" cols=50 rows=10>!&#012;version 12.3&#012;service timestamps debug uptime&#012;service timestamps log uptime&#012;service password-encryption&#012;!&#012;hostname ##########&#012;!&#012;boot-start-marker&#012;boot-end-marker&#012;!&#012;logging buffered 8840 debugging&#012;enable secret level 6 5 ##############&#012;enable secret 5 ########################&#012;enable password 7 #######################&#012;!&#012;mmi polling-interval 60&#012;no mmi auto-configure&#012;no mmi pvc&#012;mmi snmp-timeout 180&#012;aaa new-model&#012;!&#012;!&#012;aaa authentication login userauthen local&#012;aaa authentication login telnet local&#012;aaa authorization network groupauthor local&#012;aaa session-id common&#012;ip subnet-zero&#012;!&#012;!&#012;ip dhcp excluded-address 192.168.230.1 192.168.230.99&#012;!&#012;ip dhcp pool 1&#012;   network 192.168.230.0 255.255.255.0&#012;   default-router 192.168.230.1&#012;   dns-server 198.6.1.122 198.6.1.142&#012;!&#012;ip cef&#012;ip inspect max-incomplete high 1100&#012;ip inspect one-minute high 1100&#012;ip inspect name FastEthernet_0 tcp&#012;ip inspect name FastEthernet_0 udp&#012;ip inspect name FastEthernet_0 cuseeme&#012;ip inspect name FastEthernet_0 h323&#012;ip inspect name FastEthernet_0 rcmd&#012;ip inspect name FastEthernet_0 realaudio&#012;ip inspect name FastEthernet_0 smtp&#012;ip inspect name FastEthernet_0 streamworks&#012;ip inspect name FastEthernet_0 vdolive&#012;ip inspect name FastEthernet_0 sqlnet&#012;ip inspect name FastEthernet_0 tftp&#012;ip inspect name FastEthernet_0 ftp&#012;ip audit po max-events 100&#012;!&#012;!&#012;username rivetek password 7 ##########&#012;username dis privilege 6 password 7 ##########&#012;username folcomer password 7 ##########&#012;!&#012;!&#012;!&#012;!&#012;crypto isakmp policy 1&#012; encr 3des&#012; hash md5&#012; authentication pre-share&#012; group 2&#012; lifetime 43200&#012;!&#012;crypto isakmp policy 3&#012; encr 3des&#012; authentication pre-share&#012; group 2&#012;!&#012;crypto isakmp policy 10&#012; encr 3des&#012; hash md5&#012; authentication pre-share&#012; group 2&#012;crypto isakmp key #################### address ########## no-xauth&#012;crypto isakmp key #################### address ########## no-xauth&#012;crypto isakmp key #################### address ########## no-xauth&#012;crypto isakmp key #################### address ########## no-xauth&#012;crypto isakmp key #################### address ########## no-xauth&#012;crypto isakmp key #################### address ######### no-xauth&#012;!&#012;crypto isakmp client configuration group VPNclient&#012; key folco123&#012; dns 198.6.1.122&#012; pool ippool&#012; acl 199&#012;!&#012;!&#012;crypto ipsec transform-set to_uppermarlboro esp-3des esp-md5-hmac&#012;crypto ipsec transform-set to_greenwood esp-3des esp-md5-hmac&#012;crypto ipsec transform-set to_baltimore esp-3des esp-md5-hmac&#012;crypto ipsec transform-set to_vlink esp-3des esp-md5-hmac&#012;crypto ipsec transform-set to_frederick esp-3des esp-md5-hmac&#012;!&#012;crypto dynamic-map dynmap 10&#012; set transform-set to_greenwood&#012;!&#012;!&#012;crypto map cm-cryptomap local-address Serial0.1&#012;crypto map cm-cryptomap client authentication list userauthen&#012;crypto map cm-cryptomap isakmp authorization list groupauthor&#012;crypto map cm-cryptomap client configuration address respond&#012;crypto map cm-cryptomap 3 ipsec-isakmp&#012; set peer ##########&#012; set transform-set to_baltimore&#012; match address 103&#012;crypto map cm-cryptomap 4 ipsec-isakmp&#012; set peer ##########&#012; set transform-set to_frederick&#012; match address 104&#012;crypto map cm-cryptomap 5 ipsec-isakmp&#012; set peer ##########&#012; set transform-set to_uppermarlboro&#012; match address 105&#012;crypto map cm-cryptomap 7 ipsec-isakmp&#012; set peer ##########&#012; set transform-set to_greenwood&#012; match address 107&#012;crypto map cm-cryptomap 10 ipsec-isakmp dynamic dynmap&#012;crypto map cm-cryptomap 11 ipsec-isakmp&#012; set peer ##########&#012; set transform-set to_vlink&#012; match address 111&#012;!&#012;!&#012;!&#012;interface FastEthernet0&#012; description connected to EthernetLAN&#012; ip address 10.1.149.1 255.255.255.0 secondary&#012; ip address 192.168.230.1 255.255.255.0&#012; ip access-group 100 in&#012; ip nat inside&#012; ip inspect FastEthernet_0 in&#012; speed auto&#012;!&#012;interface Serial0&#012; description TI Internet Verizon Circuit ID (wcomw0r67540)&#012; bandwidth 1536&#012; no ip address&#012; encapsulation frame-relay IETF&#012; service-module t1 timeslots 1-24&#012; frame-relay lmi-type ansi&#012;!&#012;interface Serial0.1 point-to-point&#012; description connected to Internet&#012; bandwidth 1536&#012; ip address ########## 255.255.255.240&#012; ip nat outside&#012; frame-relay interface-dlci 500 IETF&#012; crypto map cm-cryptomap&#012;!&#012;ip local pool ippool 10.10.10.1 10.10.10.254&#012;ip nat inside source route-map nonat interface Serial0.1 overload&#012;ip nat inside source static tcp 10.1.149.2 21 interface Serial0.1 21&#012;ip nat inside source static tcp 10.1.149.2 20 interface Serial0.1 20&#012;ip nat inside source static 192.168.230.4 ##########&#012;ip classless&#012;ip route 0.0.0.0 0.0.0.0 Serial0.1&#012;no ip http server&#012;no ip http secure-server&#012;!&#012;!&#012;access-list 1 permit 192.168.230.0 0.0.0.255&#012;access-list 100 permit ip any any&#012;access-list 102 permit icmp any any&#012;access-list 102 permit esp any any&#012;access-list 102 permit udp any any eq isakmp&#012;access-list 102 permit ip 192.168.232.0 0.0.0.255 any&#012;access-list 102 permit ip 192.168.233.0 0.0.0.255 any&#012;access-list 102 permit ip ########## 0.0.0.7 any&#012;access-list 102 permit ip ########## 0.0.0.7 any&#012;access-list 102 permit ip 10.10.10.0 0.0.0.255 any&#012;access-list 102 permit ip 192.168.234.0 0.0.0.255 any&#012;access-list 102 permit ip ########## 0.0.0.7 any&#012;access-list 102 permit ip 192.168.231.0 0.0.0.255 any&#012;access-list 102 permit ip 192.168.202.0 0.0.0.15 any&#012;access-list 102 permit udp any any eq non500-isakmp&#012;access-list 102 permit tcp host 63.240.122.161 host ########## eq ftp&#012;access-list 102 permit tcp host 65.127.84.74 host ########## eq ftp&#012;access-list 102 permit tcp 216.57.222.128 0.0.0.127 host ########## eq ftp&#012;access-list 102 permit ip 216.57.222.128 0.0.0.127 any&#012;access-list 103 permit ip 192.168.230.0 0.0.0.255 192.168.231.0 0.0.0.255&#012;access-list 104 permit ip 192.168.230.0 0.0.0.255 192.168.234.0 0.0.0.255&#012;access-list 105 permit ip 192.168.230.0 0.0.0.255 192.168.232.0 0.0.0.255&#012;access-list 107 permit ip 192.168.230.0 0.0.0.255 192.168.233.0 0.0.0.255&#012;access-list 110 deny   ip 10.1.149.0 0.0.0.255 192.168.202.0 0.0.0.15&#012;access-list 110 deny   ip 192.168.230.0 0.0.0.255 10.10.10.0 0.0.0.255&#012;access-list 110 deny   ip 192.168.230.0 0.0.0.255 192.168.231.0 0.0.0.255&#012;access-list 110 deny   ip 192.168.230.0 0.0.0.255 192.168.232.0 0.0.0.255&#012;access-list 110 deny   ip 192.168.230.0 0.0.0.255 192.168.233.0 0.0.0.255&#012;access-list 110 deny   ip 192.168.230.0 0.0.0.255 192.168.234.0 0.0.0.255&#012;access-list 110 permit ip 192.168.230.0 0.0.0.255 any&#012;access-list 111 permit ip 10.1.149.0 0.0.0.255 192.168.202.0 0.0.0.15&#012;access-list 199 permit ip 192.168.230.0 0.0.0.255 10.10.10.0 0.0.0.255&#012;!&#012;route-map nonat permit 10&#012; match ip address 110&#012;!&#012;snmp-server community rivetmon RO&#012;snmp-server contact Rivetek,360-715-1220,Support@########.com&#012;!&#012;privilege exec level 6 show startup-config&#012;privilege exec level 6 show&#012;!&#012;line con 0&#012; exec-timeout 0 0&#012; password 7 05190F1924584B02&#012;line aux 0&#012;line vty 0 4&#012; login authentication telnet&#012;!&#012;end&#012;............................................................&#012;Cisco Internetwork Operating System Software&#012;IOS (tm) C1700 Software (C1700-K9O3SY7-M), Version 12.3(26), RELEASE SOFTWARE (fc2)&#012;Technical Support: http://www.cisco.com/techsupport&#012;Copyright (c) 1986-2008 by cisco Systems, Inc.&#012;Compiled Mon 17-Mar-08 14:24 by dchih&#012; &#012;ROM: System Bootstrap, Version 12.2(7r)XM2, RELEASE SOFTWARE (fc1)&#012; &#012;########## uptime is 1 hour, 34 minutes&#012;System returned to ROM by reload&#012;System image file is "flash:c1700-k9o3sy7-mz.123-26.bin"&#012; &#012;This product contains cryptographic features and is subject to United&#012;States and local country laws governing import, export, transfer and&#012;use. Delivery of Cisco cryptographic products does not imply&#012;third-party authority to import, export, distribute or use encryption.&#012;Importers, exporters, distributors and users are responsible for&#012;compliance with U.S. and local country laws. By using this product you&#012;agree to comply with applicable laws and regulations. If you are unable&#012;to comply with U.S. and local laws, return this product immediately.&#012; &#012;A summary of U.S. laws governing Cisco cryptographic products may be found at:&#012;http://www.cisco.com/wwl/export/crypto/tool/stqrg.html&#012; &#012;If you require further assistance please contact us by sending email to&#012;export@cisco.com.&#012; &#012;cisco 1721 (MPC860P) processor (revision 0x500) with 83711K/14593K bytes of memory.&#012;Processor board ID FOC10283PE2 (1057174431), with hardware revision 0000&#012;MPC860P processor: part number 5, mask 2&#012;Bridging software.&#012;X.25 software, Version 3.0.0.&#012;1 FastEthernet/IEEE 802.3 interface(s)&#012;1 Serial network interface(s)&#012;1 Virtual Private Network (VPN) Module(s)&#012;WIC T1-DSU&#012;32K bytes of non-volatile configuration memory.&#012;32768K bytes of processor board System flash (Read/Write)&#012; &#012;Configuration register is 0x2102&#012; &#012;...........................................................&#012; &#012;=~=~=~=~=~=~=~=~=~=~=~= PuTTY log 2008.07.08 16:04:08 =~=~=~=~=~=~=~=~=~=~=~=&#012;01:27:05: ISAKMP (0:0): received packet from ####.####.####.250 dport 500 sport 500 Global (N) NEW SA&#012;01:27:05: ISAKMP: Created a peer struct for ####.####.####.250, peer port 500&#012;01:27:05: ISAKMP: Locking peer struct 0x821E1110, IKE refcount 1 for Responding to new initiation&#012;01:27:05: ISAKMP: local port 500, remote port 500&#012;01:27:05: ISAKMP: insert sa successfully sa = 821E29F8&#012;01:27:05: ISAKMP (0:4): processing SA payload. message ID = 0&#012;01:27:05: ISAKMP (0:4): processing ID payload. message ID = 0&#012;01:27:05: ISAKMP (0:4): ID payload &#012;next-payload : 13&#012;type         : 11 &#012;group id     : VPNclient &#012;protocol     : 17 &#012;port         : 500 &#012;length       : 17&#012;01:27:05: ISAKMP (0:4): peer matches *none* of the profiles&#012;01:27:05: ISAKMP (0:4): processing vendor id payload&#012;01:27:05: ISAKMP (0:4): vendor ID seems Unity/DPD but major 215 mismatch&#012;01:27:05: ISAKMP (0:4): vendor ID is XAUTH&#012;01:27:05: ISAKMP (0:4): processing vendor id payload&#012;01:27:05: ISAKMP (0:4): vendor ID is DPD&#012;01:27:05: ISAKMP (0:4): processing vendor id payload&#012;01:27:05: ISAKMP (0:4): vendor ID seems Unity/DPD but major 123 mismatch&#012;01:27:05: ISAKMP (0:4): vendor ID is NAT-T v2&#012;01:27:05: ISAKMP (0:4): processing vendor id payload&#012;01:27:05: ISAKMP (0:4): vendor ID seems Unity/DPD but major 194 mismatch&#012;01:27:05: ISAKMP (0:4): processing vendor id payload&#012;01:27:05: ISAKMP (0:4): vendor ID is Unity&#012;01:27:05: ISAKMP : Scanning profiles for xauth ...&#012;01:27:05: ISAKMP (0:4): Checking ISAKMP transform 1 against priority 1 policy&#012;01:27:05: ISAKMP:      encryption AES-CBC&#012;01:27:05: ISAKMP:      hash SHA&#012;01:27:05: ISAKMP:      default group 2&#012;01:27:05: ISAKMP:      auth XAUTHInitPreShared&#012;01:27:05: ISAKMP:      life type in seconds&#012;01:27:05: ISAKMP:      life duration (VPI) of  0x0 0x20 0xC4 0x9B &#012;01:27:05: ISAKMP:      keylength of 256&#012;01:27:05: ISAKMP (0:4): Encryption algorithm offered does not match policy!&#012;01:27:05: ISAKMP (0:4): atts are not acceptable. Next payload is 3&#012;01:27:05: ISAKMP (0:4): Checking ISAKMP transform 2 against priority 1 policy&#012;01:27:05: ISAKMP:      encryption AES-CBC&#012;01:27:05: ISAKMP:      hash MD5&#012;01:27:05: ISAKMP:      default group 2&#012;01:27:05: ISAKMP:      auth XAUTHInitPreShared&#012;01:27:05: ISAKMP:      life type in seconds&#012;01:27:05: ISAKMP:      life duration (VPI) of  0x0 0x20 0xC4 0x9B &#012;01:27:05: ISAKMP:      keylength of 256&#012;01:27:05: ISAKMP (0:4): Encryption algorithm offered does not match policy!&#012;01:27:05: ISAKMP (0:4): atts are not acceptable. Next payload is 3&#012;01:27:05: ISAKMP (0:4): Checking ISAKMP transform 3 against priority 1 policy&#012;01:27:05: ISAKMP:      encryption AES-CBC&#012;01:27:05: ISAKMP:      hash SHA&#012;01:27:05: ISAKMP:      default group 2&#012;01:27:05: ISAKMP:      auth pre-share&#012;01:27:05: ISAKMP:      life type in seconds&#012;01:27:06: ISAKMP:      life duration (VPI) of  0x0 0x20 0xC4 0x9B &#012;01:27:06: ISAKMP:      keylength of 256&#012;01:27:06: ISAKMP (0:4): Encryption algorithm offered does not match policy!&#012;01:27:06: ISAKMP (0:4): atts are not acceptable. Next payload is 3&#012;01:27:06: ISAKMP (0:4): Checking ISAKMP transform 4 against priority 1 policy&#012;01:27:06: ISAKMP:      encryption AES-CBC&#012;01:27:06: ISAKMP:      hash MD5&#012;01:27:06: ISAKMP:      default group 2&#012;01:27:06: ISAKMP:      auth pre-share&#012;01:27:06: ISAKMP:      life type in seconds&#012;01:27:06: ISAKMP:      life duration (VPI) of  0x0 0x20 0xC4 0x9B &#012;01:27:06: ISAKMP:      keylength of 256&#012;01:27:06: ISAKMP (0:4): Encryption algorithm offered does not match policy!&#012;01:27:06: ISAKMP (0:4): atts are not acceptable. Next payload is 3&#012;01:27:06: ISAKMP (0:4): Checking ISAKMP transform 5 against priority 1 policy&#012;01:27:06: ISAKMP:      encryption AES-CBC&#012;01:27:06: ISAKMP:      hash SHA&#012;01:27:06: ISAKMP:      default group 2&#012;01:27:06: ISAKMP:      auth XAUTHInitPreShared&#012;01:27:06: ISAKMP:      life type in seconds&#012;01:27:06: ISAKMP:      life duration (VPI) of  0x0 0x20 0xC4 0x9B &#012;01:27:06: ISAKMP:      keylength of 128&#012;01:27:06: ISAKMP (0:4): Encryption algorithm offered does not match policy!&#012;01:27:06: ISAKMP (0:4): atts are not acceptable. Next payload is 3&#012;01:27:06: ISAKMP (0:4): Checking ISAKMP transform 6 against priority 1 policy&#012;01:27:06: ISAKMP:      encryption AES-CBC&#012;01:27:06: ISAKMP:      hash MD5&#012;01:27:06: ISAKMP:      default group 2&#012;01:27:06: ISAKMP:      auth XAUTHInitPreShared&#012;01:27:06: ISAKMP:      life type in seconds&#012;01:27:06: ISAKMP:      life duration (VPI) of  0x0 0x20 0xC4 0x9B &#012;01:27:06: ISAKMP:      keylength of 128&#012;01:27:06: ISAKMP (0:4): Encryption algorithm offered does not match policy!&#012;01:27:06: ISAKMP (0:4): atts are not acceptable. Next payload is 3&#012;01:27:06: ISAKMP (0:4): Checking ISAKMP transform 7 against priority 1 policy&#012;01:27:06: ISAKMP:      encryption AES-CBC&#012;01:27:06: ISAKMP:      hash SHA&#012;01:27:06: ISAKMP:      default group 2&#012;01:27:06: ISAKMP:      auth pre-share&#012;01:27:06: ISAKMP:      life type in seconds&#012;01:27:06: ISAKMP:      life duration (VPI) of  0x0 0x20 0xC4 0x9B &#012;01:27:06: ISAKMP:      keylength of 128&#012;01:27:06: ISAKMP (0:4): Encryption algorithm offered does not match policy!&#012;01:27:06: ISAKMP (0:4): atts are not acceptable. Next payload is 3&#012;01:27:06: ISAKMP (0:4): Checking ISAKMP transform 8 against priority 1 policy&#012;01:27:06: ISAKMP:      encryption AES-CBC&#012;01:27:06: ISAKMP:      hash MD5&#012;01:27:06: ISAKMP:      default group 2&#012;01:27:06: ISAKMP:      auth pre-share&#012;01:27:06: ISAKMP:      life type in seconds&#012;01:27:06: ISAKMP:      life duration (VPI) of  0x0 0x20 0xC4 0x9B &#012;01:27:06: ISAKMP:      keylength of 128&#012;01:27:06: ISAKMP (0:4): Encryption algorithm offered does not match policy!&#012;01:27:06: ISAKMP (0:4): atts are not acceptable. Next payload is 3&#012;01:27:06: ISAKMP (0:4): Checking ISAKMP transform 9 against priority 1 policy&#012;01:27:06: ISAKMP:      encryption 3DES-CBC&#012;01:27:06: ISAKMP:      hash SHA&#012;01:27:06: ISAKMP:      default group 2&#012;01:27:06: ISAKMP:      auth XAUTHInitPreShared&#012;01:27:06: ISAKMP:      life type in seconds&#012;01:27:06: ISAKMP:      life duration (VPI) of  0x0 0x20 0xC4 0x9B &#012;01:27:06: ISAKMP (0:4): Hash algorithm offered does not match policy!&#012;01:27:06: ISAKMP (0:4): atts are not acceptable. Next payload is 3&#012;01:27:06: ISAKMP (0:4): Checking ISAKMP transform 10 against priority 1 policy&#012;01:27:06: ISAKMP:      encryption 3DES-CBC&#012;01:27:06: ISAKMP:      hash MD5&#012;01:27:06: ISAKMP:      default group 2&#012;01:27:06: ISAKMP:      auth XAUTHInitPreShared&#012;01:27:06: ISAKMP:      life type in seconds&#012;01:27:06: ISAKMP:      life duration (VPI) of  0x0 0x20 0xC4 0x9B &#012;01:27:06: ISAKMP (0:4): Xauth authentication by pre-shared key offered but does not match policy!&#012;01:27:06: ISAKMP (0:4): atts are not acceptable. Next payload is 3&#012;01:27:06: ISAKMP (0:4): Checking ISAKMP transform 11 against priority 1 policy&#012;01:27:06: ISAKMP:      encryption 3DES-CBC&#012;01:27:06: ISAKMP:      hash SHA&#012;01:27:06: ISAKMP:      default group 2&#012;01:27:06: ISAKMP:      auth pre-share&#012;01:27:06: ISAKMP:      life type in seconds&#012;01:27:06: ISAKMP:      life duration (VPI) of  0x0 0x20 0xC4 0x9B &#012;01:27:06: ISAKMP (0:4): Hash algorithm offered does not match policy!&#012;01:27:06: ISAKMP (0:4): atts are not acceptable. Next payload is 3&#012;01:27:06: ISAKMP (0:4): Checking ISAKMP transform 12 against priority 1 policy&#012;01:27:06: ISAKMP:      encryption 3DES-CBC&#012;01:27:06: ISAKMP:      hash MD5&#012;01:27:06: ISAKMP:      default group 2&#012;01:27:06: ISAKMP:      auth pre-share&#012;01:27:06: ISAKMP:      life type in seconds&#012;01:27:06: ISAKMP:      life duration (VPI) of  0x0 0x20 0xC4 0x9B &#012;01:27:06: ISAKMP (0:4): Preshared authentication offered but does not match policy!&#012;01:27:06: ISAKMP (0:4): atts are not acceptable. Next payload is 3&#012;01:27:06: ISAKMP (0:4): Checking ISAKMP transform 13 against priority 1 policy&#012;01:27:06: ISAKMP:      encryption DES-CBC&#012;01:27:06: ISAKMP:      hash MD5&#012;01:27:06: ISAKMP:      default group 2&#012;01:27:06: ISAKMP:      auth XAUTHInitPreShared&#012;01:27:06: ISAKMP:      life type in seconds&#012;01:27:06: ISAKMP:      life duration (VPI) of  0x0 0x20 0xC4 0x9B &#012;01:27:06: ISAKMP (0:4): Encryption algorithm offered does not match policy!&#012;01:27:06: ISAKMP (0:4): atts are not acceptable. Next payload is 3&#012;01:27:06: ISAKMP (0:4): Checking ISAKMP transform 14 against priority 1 policy&#012;01:27:06: ISAKMP:      encryption DES-CBC&#012;01:27:06: ISAKMP:      hash MD5&#012;01:27:06: ISAKMP:      default group 2&#012;01:27:06: ISAKMP:      auth pre-share&#012;01:27:06: ISAKMP:      life type in seconds&#012;01:27:06: ISAKMP:      life duration (VPI) of  0x0 0x20 0xC4 0x9B &#012;01:27:06: ISAKMP (0:4): Encryption algorithm offered does not match policy!&#012;01:27:06: ISAKMP (0:4): atts are not acceptable. Next payload is 0&#012;01:27:06: ISAKMP (0:4): Checking ISAKMP transform 1 against priority 3 policy&#012;01:27:06: ISAKMP:      encryption AES-CBC&#012;01:27:06: ISAKMP:      hash SHA&#012;01:27:06: ISAKMP:      default group 2&#012;01:27:06: ISAKMP:      auth XAUTHInitPreShared&#012;01:27:06: ISAKMP:      life type in seconds&#012;01:27:06: ISAKMP:      life duration (VPI) of  0x0 0x20 0xC4 0x9B &#012;01:27:06: ISAKMP:      keylength of 256&#012;01:27:06: ISAKMP (0:4): Encryption algorithm offered does not match policy!&#012;01:27:06: ISAKMP (0:4): atts are not acceptable. Next payload is 3&#012;01:27:06: ISAKMP (0:4): Checking ISAKMP transform 2 against priority 3 policy&#012;01:27:06: ISAKMP:      encryption AES-CBC&#012;01:27:06: ISAKMP:      hash MD5&#012;01:27:06: ISAKMP:      default group 2&#012;01:27:06: ISAKMP:      auth XAUTHInitPreShared&#012;01:27:06: ISAKMP:      life type in seconds&#012;01:27:06: ISAKMP:      life duration (VPI) of  0x0 0x20 0xC4 0x9B &#012;01:27:06: ISAKMP:      keylength of 256&#012;01:27:06: ISAKMP (0:4): Encryption algorithm offered does not match policy!&#012;01:27:06: ISAKMP (0:4): atts are not acceptable. Next payload is 3&#012;01:27:06: ISAKMP (0:4): Checking ISAKMP transform 3 against priority 3 policy&#012;01:27:06: ISAKMP:      encryption AES-CBC&#012;01:27:06: ISAKMP:      hash SHA&#012;01:27:06: ISAKMP:      default group 2&#012;01:27:06: ISAKMP:      auth pre-share&#012;01:27:06: ISAKMP:      life type in seconds&#012;01:27:06: ISAKMP:      life duration (VPI) of  0x0 0x20 0xC4 0x9B &#012;01:27:06: ISAKMP:      keylength of 256&#012;01:27:06: ISAKMP (0:4): Encryption algorithm offered does not match policy!&#012;01:27:06: ISAKMP (0:4): atts are not acceptable. Next payload is 3&#012;01:27:06: ISAKMP (0:4): Checking ISAKMP transform 4 against priority 3 policy&#012;01:27:06: ISAKMP:      encryption AES-CBC&#012;01:27:06: ISAKMP:      hash MD5&#012;01:27:06: ISAKMP:      default group 2&#012;01:27:06: ISAKMP:      auth pre-share&#012;01:27:06: ISAKMP:      life type in seconds&#012;01:27:06: ISAKMP:      life duration (VPI) of  0x0 0x20 0xC4 0x9B &#012;01:27:06: ISAKMP:      keylength of 256&#012;01:27:06: ISAKMP (0:4): Encryption algorithm offered does not match policy!&#012;01:27:06: ISAKMP (0:4): atts are not acceptable. Next payload is 3&#012;01:27:06: ISAKMP (0:4): Checking ISAKMP transform 5 against priority 3 policy&#012;01:27:06: ISAKMP:      encryption AES-CBC&#012;01:27:06: ISAKMP:      hash SHA&#012;01:27:06: ISAKMP:      default group 2&#012;01:27:06: ISAKMP:      auth XAUTHInitPreShared&#012;01:27:06: ISAKMP:      life type in seconds&#012;01:27:06: ISAKMP:      life duration (VPI) of  0x0 0x20 0xC4 0x9B &#012;01:27:06: ISAKMP:      keylength of 128&#012;01:27:06: ISAKMP (0:4): Encryption algorithm offered does not match policy!&#012;01:27:06: ISAKMP (0:4): atts are not acceptable. Next payload is 3&#012;01:27:06: ISAKMP (0:4): Checking ISAKMP transform 6 against priority 3 policy&#012;01:27:06: ISAKMP:      encryption AES-CBC&#012;01:27:06: ISAKMP:      hash MD5&#012;01:27:06: ISAKMP:      default group 2&#012;01:27:06: ISAKMP:      auth XAUTHInitPreShared&#012;01:27:06: ISAKMP:      life type in seconds&#012;01:27:06: ISAKMP:      life duration (VPI) of  0x0 0x20 0xC4 0x9B &#012;01:27:06: ISAKMP:      keylength of 128&#012;01:27:06: ISAKMP (0:4): Encryption algorithm offered does not match policy!&#012;01:27:06: ISAKMP (0:4): atts are not acceptable. Next payload is 3&#012;01:27:06: ISAKMP (0:4): Checking ISAKMP transform 7 against priority 3 policy&#012;01:27:06: ISAKMP:      encryption AES-CBC&#012;01:27:06: ISAKMP:      hash SHA&#012;01:27:06: ISAKMP:      default group 2&#012;01:27:06: ISAKMP:      auth pre-share&#012;01:27:06: ISAKMP:      life type in seconds&#012;01:27:06: ISAKMP:      life duration (VPI) of  0x0 0x20 0xC4 0x9B &#012;01:27:06: ISAKMP:      keylength of 128&#012;01:27:06: ISAKMP (0:4): Encryption algorithm offered does not match policy!&#012;01:27:06: ISAKMP (0:4): atts are not acceptable. Next payload is 3&#012;01:27:06: ISAKMP (0:4): Checking ISAKMP transform 8 against priority 3 policy&#012;01:27:06: ISAKMP:      encryption AES-CBC&#012;01:27:06: ISAKMP:      hash MD5&#012;01:27:06: ISAKMP:      default group 2&#012;01:27:06: ISAKMP:      auth pre-share&#012;01:27:06: ISAKMP:      life type in seconds&#012;01:27:06: ISAKMP:      life duration (VPI) of  0x0 0x20 0xC4 0x9B &#012;01:27:06: ISAKMP:      keylength of 128&#012;01:27:06: ISAKMP (0:4): Encryption algorithm offered does not match policy!&#012;01:27:06: ISAKMP (0:4): atts are not acceptable. Next payload is 3&#012;01:27:06: ISAKMP (0:4): Checking ISAKMP transform 9 against priority 3 policy&#012;01:27:06: ISAKMP:      encryption 3DES-CBC&#012;01:27:06: ISAKMP:      hash SHA&#012;01:27:06: ISAKMP:      default group 2&#012;01:27:06: ISAKMP:      auth XAUTHInitPreShared&#012;01:27:06: ISAKMP:      life type in seconds&#012;01:27:06: ISAKMP:      life duration (VPI) of  0x0 0x20 0xC4 0x9B &#012;01:27:06: ISAKMP (0:4): Xauth authentication by pre-shared key offered but does not match policy!&#012;01:27:06: ISAKMP (0:4): atts are not acceptable. Next payload is 3&#012;01:27:06: ISAKMP (0:4): Checking ISAKMP transform 10 against priority 3 policy&#012;01:27:06: ISAKMP:      encryption 3DES-CBC&#012;01:27:06: ISAKMP:      hash MD5&#012;01:27:06: ISAKMP:      default group 2&#012;01:27:06: ISAKMP:      auth XAUTHInitPreShared&#012;01:27:06: ISAKMP:      life type in seconds&#012;01:27:06: ISAKMP:      life duration (VPI) of  0x0 0x20 0xC4 0x9B &#012;01:27:06: ISAKMP (0:4): Hash algorithm offered does not match policy!&#012;01:27:06: ISAKMP (0:4): atts are not acceptable. Next payload is 3&#012;01:27:06: ISAKMP (0:4): Checking ISAKMP transform 11 against priority 3 policy&#012;01:27:06: ISAKMP:      encryption 3DES-CBC&#012;01:27:06: ISAKMP:      hash SHA&#012;01:27:06: ISAKMP:      default group 2&#012;01:27:06: ISAKMP:      auth pre-share&#012;01:27:06: ISAKMP:      life type in seconds&#012;01:27:06: ISAKMP:      life duration (VPI) of  0x0 0x20 0xC4 0x9B &#012;01:27:06: ISAKMP (0:4): Preshared authentication offered but does not match policy!&#012;01:27:06: ISAKMP (0:4): atts are not acceptable. Next payload is 3&#012;01:27:06: ISAKMP (0:4): Checking ISAKMP transform 12 against priority 3 policy&#012;01:27:06: ISAKMP:      encryption 3DES-CBC&#012;01:27:06: ISAKMP:      hash MD5&#012;01:27:06: ISAKMP:      default group 2&#012;01:27:06: ISAKMP:      auth pre-share&#012;01:27:06: ISAKMP:      life type in seconds&#012;01:27:06: ISAKMP:      life duration (VPI) of  0x0 0x20 0xC4 0x9B &#012;01:27:06: ISAKMP (0:4): Hash algorithm offered does not match policy!&#012;01:27:06: ISAKMP (0:4): atts are not acceptable. Next payload is 3&#012;01:27:06: ISAKMP (0:4): Checking ISAKMP transform 13 against priority 3 policy&#012;01:27:06: ISAKMP:      encryption DES-CBC&#012;01:27:06: ISAKMP:      hash MD5&#012;01:27:06: ISAKMP:      default group 2&#012;01:27:06: ISAKMP:      auth XAUTHInitPreShared&#012;01:27:06: ISAKMP:      life type in seconds&#012;01:27:06: ISAKMP:      life duration (VPI) of  0x0 0x20 0xC4 0x9B &#012;01:27:06: ISAKMP (0:4): Encryption algorithm offered does not match policy!&#012;01:27:06: ISAKMP (0:4): atts are not acceptable. Next payload is 3&#012;01:27:06: ISAKMP (0:4): Checking ISAKMP transform 14 against priority 3 policy&#012;01:27:06: ISAKMP:      encryption DES-CBC&#012;01:27:06: ISAKMP:      hash MD5&#012;01:27:06: ISAKMP:      default group 2&#012;01:27:06: ISAKMP:      auth pre-share&#012;01:27:06: ISAKMP:      life type in seconds&#012;01:27:06: ISAKMP:      life duration (VPI) of  0x0 0x20 0xC4 0x9B &#012;01:27:06: ISAKMP (0:4): Encryption algorithm offered does not match policy!&#012;01:27:06: ISAKMP (0:4): atts are not acceptable. Next payload is 0&#012;01:27:06: ISAKMP (0:4): Checking ISAKMP transform 1 against priority 10 policy&#012;01:27:06: ISAKMP:      encryption AES-CBC&#012;01:27:06: ISAKMP:      hash SHA&#012;01:27:06: ISAKMP:      default group 2&#012;01:27:06: ISAKMP:      auth XAUTHInitPreShared&#012;01:27:06: ISAKMP:      life type in seconds&#012;01:27:06: ISAKMP:      life duration (VPI) of  0x0 0x20 0xC4 0x9B &#012;01:27:06: ISAKMP:      keylength of 256&#012;01:27:06: ISAKMP (0:4): Encryption algorithm offered does not match policy!&#012;01:27:06: ISAKMP (0:4): atts are not acceptable. Next payload is 3&#012;01:27:06: ISAKMP (0:4): Checking ISAKMP transform 2 against priority 10 policy&#012;01:27:06: ISAKMP:      encryption AES-CBC&#012;01:27:06: ISAKMP:      hash MD5&#012;01:27:06: ISAKMP:      default group 2&#012;01:27:06: ISAKMP:      auth XAUTHInitPreShared&#012;01:27:06: ISAKMP:      life type in seconds&#012;01:27:06: ISAKMP:      life duration (VPI) of  0x0 0x20 0xC4 0x9B &#012;01:27:06: ISAKMP:      keylength of 256&#012;01:27:06: ISAKMP (0:4): Encryption algorithm offered does not match policy!&#012;01:27:06: ISAKMP (0:4): atts are not acceptable. Next payload is 3&#012;01:27:06: ISAKMP (0:4): Checking ISAKMP transform 3 against priority 10 policy&#012;01:27:06: ISAKMP:      encryption AES-CBC&#012;01:27:06: ISAKMP:      hash SHA&#012;01:27:06: ISAKMP:      default group 2&#012;01:27:06: ISAKMP:      auth pre-share&#012;01:27:06: ISAKMP:      life type in seconds&#012;01:27:06: ISAKMP:      life duration (VPI) of  0x0 0x20 0xC4 0x9B &#012;01:27:06: ISAKMP:      keylength of 256&#012;01:27:06: ISAKMP (0:4): Encryption algorithm offered does not match policy!&#012;01:27:06: ISAKMP (0:4): atts are not acceptable. Next payload is 3&#012;01:27:06: ISAKMP (0:4): Checking ISAKMP transform 4 against priority 10 policy&#012;01:27:06: ISAKMP:      encryption AES-CBC&#012;01:27:06: ISAKMP:      hash MD5&#012;01:27:06: ISAKMP:      default group 2&#012;01:27:06: ISAKMP:      auth pre-share&#012;01:27:06: ISAKMP:      life type in seconds&#012;01:27:06: ISAKMP:      life duration (VPI) of  0x0 0x20 0xC4 0x9B &#012;01:27:06: ISAKMP:      keylength of 256&#012;01:27:06: ISAKMP (0:4): Encryption algorithm offered does not match policy!&#012;01:27:06: ISAKMP (0:4): atts are not acceptable. Next payload is 3&#012;01:27:06: ISAKMP (0:4): Checking ISAKMP transform 5 against priority 10 policy&#012;01:27:06: ISAKMP:      encryption AES-CBC&#012;01:27:06: ISAKMP:      hash SHA&#012;01:27:06: ISAKMP:      default group 2&#012;01:27:06: ISAKMP:      auth XAUTHInitPreShared&#012;01:27:06: ISAKMP:      life type in seconds&#012;01:27:06: ISAKMP:      life duration (VPI) of  0x0 0x20 0xC4 0x9B &#012;01:27:06: ISAKMP:      keylength of 128&#012;01:27:06: ISAKMP (0:4): Encryption algorithm offered does not match policy!&#012;01:27:06: ISAKMP (0:4): atts are not acceptable. Next payload is 3&#012;01:27:06: ISAKMP (0:4): Checking ISAKMP transform 6 against priority 10 policy&#012;01:27:06: ISAKMP:      encryption AES-CBC&#012;01:27:06: ISAKMP:      hash MD5&#012;01:27:06: ISAKMP:      default group 2&#012;01:27:06: ISAKMP:      auth XAUTHInitPreShared&#012;01:27:06: ISAKMP:      life type in seconds&#012;01:27:06: ISAKMP:      life duration (VPI) of  0x0 0x20 0xC4 0x9B &#012;01:27:06: ISAKMP:      keylength of 128&#012;01:27:06: ISAKMP (0:4): Encryption algorithm offered does not match policy!&#012;01:27:06: ISAKMP (0:4): atts are not acceptable. Next payload is 3&#012;01:27:06: ISAKMP (0:4): Checking ISAKMP transform 7 against priority 10 policy&#012;01:27:06: ISAKMP:      encryption AES-CBC&#012;01:27:06: ISAKMP:      hash SHA&#012;01:27:06: ISAKMP:      default group 2&#012;01:27:06: ISAKMP:      auth pre-share&#012;01:27:06: ISAKMP:      life type in seconds&#012;01:27:06: ISAKMP:      life duration (VPI) of  0x0 0x20 0xC4 0x9B &#012;01:27:06: ISAKMP:      keylength of 128&#012;01:27:06: ISAKMP (0:4): Encryption algorithm offered does not match policy!&#012;01:27:06: ISAKMP (0:4): atts are not acceptable. Next payload is 3&#012;01:27:06: ISAKMP (0:4): Checking ISAKMP transform 8 against priority 10 policy&#012;01:27:06: ISAKMP:      encryption AES-CBC&#012;01:27:06: ISAKMP:      hash MD5&#012;01:27:06: ISAKMP:      default group 2&#012;01:27:06: ISAKMP:      auth pre-share&#012;01:27:06: ISAKMP:      life type in seconds&#012;01:27:06: ISAKMP:      life duration (VPI) of  0x0 0x20 0xC4 0x9B &#012;01:27:06: ISAKMP:      keylength of 128&#012;01:27:06: ISAKMP (0:4): Encryption algorithm offered does not match policy!&#012;01:27:06: ISAKMP (0:4): atts are not acceptable. Next payload is 3&#012;01:27:06: ISAKMP (0:4): Checking ISAKMP transform 9 against priority 10 policy&#012;01:27:06: ISAKMP:      encryption 3DES-CBC&#012;01:27:06: ISAKMP:      hash SHA&#012;01:27:06: ISAKMP:      default group 2&#012;01:27:06: ISAKMP:      auth XAUTHInitPreShared&#012;01:27:06: ISAKMP:      life type in seconds&#012;01:27:06: ISAKMP:      life duration (VPI) of  0x0 0x20 0xC4 0x9B &#012;01:27:06: ISAKMP (0:4): Hash algorithm offered does not match policy!&#012;01:27:06: ISAKMP (0:4): atts are not acceptable. Next payload is 3&#012;01:27:06: ISAKMP (0:4): Checking ISAKMP transform 10 against priority 10 policy&#012;01:27:06: ISAKMP:      encryption 3DES-CBC&#012;01:27:06: ISAKMP:      hash MD5&#012;01:27:06: ISAKMP:      default group 2&#012;01:27:06: ISAKMP:      auth XAUTHInitPreShared&#012;01:27:06: ISAKMP:      life type in seconds&#012;01:27:06: ISAKMP:      life duration (VPI) of  0x0 0x20 0xC4 0x9B &#012;01:27:06: ISAKMP (0:4): Xauth authentication by pre-shared key offered but does not match policy!&#012;01:27:06: ISAKMP (0:4): atts are not acceptable. Next payload is 3&#012;01:27:06: ISAKMP (0:4): Checking ISAKMP transform 11 against priority 10 policy&#012;01:27:06: ISAKMP:      encryption 3DES-CBC&#012;01:27:06: ISAKMP:      hash SHA&#012;01:27:06: ISAKMP:      default group 2&#012;01:27:06: ISAKMP:      auth pre-share&#012;01:27:06: ISAKMP:      life type in seconds&#012;01:27:06: ISAKMP:      life duration (VPI) of  0x0 0x20 0xC4 0x9B &#012;01:27:06: ISAKMP (0:4): Hash algorithm offered does not match policy!&#012;01:27:06: ISAKMP (0:4): atts are not acceptable. Next payload is 3&#012;01:27:06: ISAKMP (0:4): Checking ISAKMP transform 12 against priority 10 policy&#012;01:27:06: ISAKMP:      encryption 3DES-CBC&#012;01:27:06: ISAKMP:      hash MD5&#012;01:27:06: ISAKMP:      default group 2&#012;01:27:06: ISAKMP:      auth pre-share&#012;01:27:06: ISAKMP:      life type in seconds&#012;01:27:06: ISAKMP:      life duration (VPI) of  0x0 0x20 0xC4 0x9B &#012;01:27:06: ISAKMP (0:4): Preshared authentication offered but does not match policy!&#012;01:27:06: ISAKMP (0:4): atts are not acceptable. Next payload is 3&#012;01:27:06: ISAKMP (0:4): Checking ISAKMP transform 13 against priority 10 policy&#012;01:27:06: ISAKMP:      encryption DES-CBC&#012;01:27:06: ISAKMP:      hash MD5&#012;01:27:06: ISAKMP:      default group 2&#012;01:27:06: ISAKMP:      auth XAUTHInitPreShared&#012;01:27:06: ISAKMP:      life type in seconds&#012;01:27:06: ISAKMP:      life duration (VPI) of  0x0 0x20 0xC4 0x9B &#012;01:27:06: ISAKMP (0:4): Encryption algorithm offered does not match policy!&#012;01:27:06: ISAKMP (0:4): atts are not acceptable. Next payload is 3&#012;01:27:06: ISAKMP (0:4): Checking ISAKMP transform 14 against priority 10 policy&#012;01:27:06: ISAKMP:      encryption DES-CBC&#012;01:27:06: ISAKMP:      hash MD5&#012;01:27:06: ISAKMP:      default group 2&#012;01:27:06: ISAKMP:      auth pre-share&#012;01:27:06: ISAKMP:      life type in seconds&#012;01:27:06: ISAKMP:      life duration (VPI) of  0x0 0x20 0xC4 0x9B &#012;01:27:06: ISAKMP (0:4): Encryption algorithm offered does not match policy!&#012;01:27:06: ISAKMP (0:4): atts are not acceptable. Next payload is 0&#012;01:27:06: ISAKMP (0:4): Checking ISAKMP transform 1 against priority 65535 policy&#012;01:27:06: ISAKMP:      encryption AES-CBC&#012;01:27:06: ISAKMP:      hash SHA&#012;01:27:06: ISAKMP:      default group 2&#012;01:27:06: ISAKMP:      auth XAUTHInitPreShared&#012;01:27:06: ISAKMP:      life type in seconds&#012;01:27:06: ISAKMP:      life duration (VPI) of  0x0 0x20 0xC4 0x9B &#012;01:27:06: ISAKMP:      keylength of 256&#012;01:27:06: ISAKMP (0:4): Encryption algorithm offered does not match policy!&#012;01:27:06: ISAKMP (0:4): atts are not acceptable. Next payload is 3&#012;01:27:06: ISAKMP (0:4): Checking ISAKMP transform 2 against priority 65535 policy&#012;01:27:06: ISAKMP:      encryption AES-CBC&#012;01:27:06: ISAKMP:      hash MD5&#012;01:27:06: ISAKMP:      default group 2&#012;01:27:06: ISAKMP:      auth XAUTHInitPreShared&#012;01:27:06: ISAKMP:      life type in seconds&#012;01:27:06: ISAKMP:      life duration (VPI) of  0x0 0x20 0xC4 0x9B &#012;01:27:06: ISAKMP:      keylength of 256&#012;01:27:06: ISAKMP (0:4): Encryption algorithm offered does not match policy!&#012;01:27:06: ISAKMP (0:4): atts are not acceptable. Next payload is 3&#012;01:27:06: ISAKMP (0:4): Checking ISAKMP transform 3 against priority 65535 policy&#012;01:27:06: ISAKMP:      encryption AES-CBC&#012;01:27:06: ISAKMP:      hash SHA&#012;01:27:06: ISAKMP:      default group 2&#012;01:27:06: ISAKMP:      auth pre-share&#012;01:27:06: ISAKMP:      life type in seconds&#012;01:27:06: ISAKMP:      life duration (VPI) of  0x0 0x20 0xC4 0x9B &#012;01:27:06: ISAKMP:      keylength of 256&#012;01:27:06: ISAKMP (0:4): Encryption algorithm offered does not match policy!&#012;01:27:06: ISAKMP (0:4): atts are not acceptable. Next payload is 3&#012;01:27:06: ISAKMP (0:4): Checking ISAKMP transform 4 against priority 65535 policy&#012;01:27:06: ISAKMP:      encryption AES-CBC&#012;01:27:06: ISAKMP:      hash MD5&#012;01:27:06: ISAKMP:      default group 2&#012;01:27:06: ISAKMP:      auth pre-share&#012;01:27:06: ISAKMP:      life type in seconds&#012;01:27:06: ISAKMP:      life duration (VPI) of  0x0 0x20 0xC4 0x9B &#012;01:27:06: ISAKMP:      keylength of 256&#012;01:27:06: ISAKMP (0:4): Encryption algorithm offered does not match policy!&#012;01:27:06: ISAKMP (0:4): atts are not acceptable. Next payload is 3&#012;01:27:06: ISAKMP (0:4): Checking ISAKMP transform 5 against priority 65535 policy&#012;01:27:06: ISAKMP:      encryption AES-CBC&#012;01:27:06: ISAKMP:      hash SHA&#012;01:27:06: ISAKMP:      default group 2&#012;01:27:06: ISAKMP:      auth XAUTHInitPreShared&#012;01:27:06: ISAKMP:      life type in seconds&#012;01:27:06: ISAKMP:      life duration (VPI) of  0x0 0x20 0xC4 0x9B &#012;01:27:06: ISAKMP:      keylength of 128&#012;01:27:06: ISAKMP (0:4): Encryption algorithm offered does not match policy!&#012;01:27:06: ISAKMP (0:4): atts are not acceptable. Next payload is 3&#012;01:27:06: ISAKMP (0:4): Checking ISAKMP transform 6 against priority 65535 policy&#012;01:27:06: ISAKMP:      encryption AES-CBC&#012;01:27:06: ISAKMP:      hash MD5&#012;01:27:06: ISAKMP:      default group 2&#012;01:27:06: ISAKMP:      auth XAUTHInitPreShared&#012;01:27:06: ISAKMP:      life type in seconds&#012;01:27:06: ISAKMP:      life duration (VPI) of  0x0 0x20 0xC4 0x9B &#012;01:27:06: ISAKMP:      keylength of 128&#012;01:27:06: ISAKMP (0:4): Encryption algorithm offered does not match policy!&#012;01:27:06: ISAKMP (0:4): atts are not acceptable. Next payload is 3&#012;01:27:06: ISAKMP (0:4): Checking ISAKMP transform 7 against priority 65535 policy&#012;01:27:06: ISAKMP:      encryption AES-CBC&#012;01:27:06: ISAKMP:      hash SHA&#012;01:27:06: ISAKMP:      default group 2&#012;01:27:06: ISAKMP:      auth pre-share&#012;01:27:06: ISAKMP:      life type in seconds&#012;01:27:06: ISAKMP:      life duration (VPI) of  0x0 0x20 0xC4 0x9B &#012;01:27:06: ISAKMP:      keylength of 128&#012;01:27:06: ISAKMP (0:4): Encryption algorithm offered does not match policy!&#012;01:27:06: ISAKMP (0:4): atts are not acceptable. Next payload is 3&#012;01:27:06: ISAKMP (0:4): Checking ISAKMP transform 8 against priority 65535 policy&#012;01:27:06: ISAKMP:      encryption AES-CBC&#012;01:27:06: ISAKMP:      hash MD5&#012;01:27:06: ISAKMP:      default group 2&#012;01:27:06: ISAKMP:      auth pre-share&#012;01:27:06: ISAKMP:      life type in seconds&#012;01:27:06: ISAKMP:      life duration (VPI) of  0x0 0x20 0xC4 0x9B &#012;01:27:06: ISAKMP:      keylength of 128&#012;01:27:06: ISAKMP (0:4): Encryption algorithm offered does not match policy!&#012;01:27:06: ISAKMP (0:4): atts are not acceptable. Next payload is 3&#012;01:27:06: ISAKMP (0:4): Checking ISAKMP transform 9 against priority 65535 policy&#012;01:27:06: ISAKMP:      encryption 3DES-CBC&#012;01:27:06: ISAKMP:      hash SHA&#012;01:27:06: ISAKMP:      default group 2&#012;01:27:06: ISAKMP:      auth XAUTHInitPreShared&#012;01:27:06: ISAKMP:      life type in seconds&#012;01:27:06: ISAKMP:      life duration (VPI) of  0x0 0x20 0xC4 0x9B &#012;01:27:06: ISAKMP (0:4): Encryption algorithm offered does not match policy!&#012;01:27:06: ISAKMP (0:4): atts are not acceptable. Next payload is 3&#012;01:27:06: ISAKMP (0:4): Checking ISAKMP transform 10 against priority 65535 policy&#012;01:27:06: ISAKMP:      encryption 3DES-CBC&#012;01:27:06: ISAKMP:      hash MD5&#012;01:27:06: ISAKMP:      default group 2&#012;01:27:06: ISAKMP:      auth XAUTHInitPreShared&#012;01:27:06: ISAKMP:      life type in seconds&#012;01:27:06: ISAKMP:      life duration (VPI) of  0x0 0x20 0xC4 0x9B &#012;01:27:06: ISAKMP (0:4): Encryption algorithm offered does not match policy!&#012;01:27:06: ISAKMP (0:4): atts are not acceptable. Next payload is 3&#012;01:27:06: ISAKMP (0:4): Checking ISAKMP transform 11 against priority 65535 policy&#012;01:27:06: ISAKMP:      encryption 3DES-CBC&#012;01:27:06: ISAKMP:      hash SHA&#012;01:27:06: ISAKMP:      default group 2&#012;01:27:06: ISAKMP:      auth pre-share&#012;01:27:06: ISAKMP:      life type in seconds&#012;01:27:06: ISAKMP:      life duration (VPI) of  0x0 0x20 0xC4 0x9B &#012;01:27:06: ISAKMP (0:4): Encryption algorithm offered does not match policy!&#012;01:27:06: ISAKMP (0:4): atts are not acceptable. Next payload is 3&#012;01:27:06: ISAKMP (0:4): Checking ISAKMP transform 12 against priority 65535 policy&#012;01:27:06: ISAKMP:      encryption 3DES-CBC&#012;01:27:06: ISAKMP:      hash MD5&#012;01:27:06: ISAKMP:      default group 2&#012;01:27:06: ISAKMP:      auth pre-share&#012;01:27:06: ISAKMP:      life type in seconds&#012;01:27:06: ISAKMP:      life duration (VPI) of  0x0 0x20 0xC4 0x9B &#012;01:27:06: ISAKMP (0:4): Encryption algorithm offered does not match policy!&#012;01:27:06: ISAKMP (0:4): atts are not acceptable. Next payload is 3&#012;01:27:06: ISAKMP (0:4): Checking ISAKMP transform 13 against priority 65535 policy&#012;01:27:06: ISAKMP:      encryption DES-CBC&#012;01:27:06: ISAKMP:      hash MD5&#012;01:27:06: ISAKMP:      default group 2&#012;01:27:06: ISAKMP:      auth XAUTHInitPreShared&#012;01:27:06: ISAKMP:      life type in seconds&#012;01:27:06: ISAKMP:      life duration (VPI) of  0x0 0x20 0xC4 0x9B &#012;01:27:06: ISAKMP (0:4): Hash algorithm offered does not match policy!&#012;01:27:06: ISAKMP (0:4): atts are not acceptable. Next payload is 3&#012;01:27:06: ISAKMP (0:4): Checking ISAKMP transform 14 against priority 65535 policy&#012;01:27:06: ISAKMP:      encryption DES-CBC&#012;01:27:06: ISAKMP:      hash MD5&#012;01:27:06: ISAKMP:      default group 2&#012;01:27:06: ISAKMP:      auth pre-share&#012;01:27:06: ISAKMP:      life type in seconds&#012;01:27:06: ISAKMP:      life duration (VPI) of  0x0 0x20 0xC4 0x9B &#012;01:27:06: ISAKMP (0:4): Hash algorithm offered does not match policy!&#012;01:27:06: ISAKMP (0:4): atts are not acceptable. Next payload is 0&#012;01:27:06: ISAKMP (0:4): no offers accepted!&#012;01:27:06: ISAKMP (0:4): phase 1 SA policy not acceptable! (local ####.####.####.81 remote ####.####.####.250)&#012;01:27:06: ISAKMP (0:4): incrementing error counter on sa, attempt 1 of 5: construct_fail_ag_init&#012;01:27:06: ISAKMP (0:4): Unknown Input IKE_MESG_FROM_PEER, IKE_AM_EXCH:  state = IKE_READY&#012;01:27:06: ISAKMP (0:4): Input = IKE_MESG_FROM_PEER, IKE_AM_EXCH&#012;01:27:06: ISAKMP (0:4): Old State = IKE_READY  New State = IKE_READY &#012; &#012;01:27:06: %CRYPTO-6-IKMP_MODE_FAILURE: Processing of Aggressive mode failed with peer at ####.####.####.250  &#012;01:27:11: ISAKMP (0:4): received packet from ####.####.####.250 dport 500 sport 500 Global (R) AG_NO_STATE&#012;01:27:11: ISAKMP (0:4): phase 1 packet is a duplicate of a previous packet.&#012;01:27:11: ISAKMP (0:4): retransmitting due to retransmit phase 1&#012;01:27:11: ISAKMP (0:4): retransmitting phase 1 AG_NO_STATE...&#012;01:27:11: ISAKMP (0:4): incrementing error counter on sa, attempt 2 of 5: retransmit phase 1&#012;01:27:11: ISAKMP (0:4): retransmitting phase 1 AG_NO_STATE&#012;01:27:11: ISAKMP (0:4): sending packet to ####.####.####.250 my_port 500 peer_port 500 (R) AG_NO_STATE&#012;01:27:16: ISAKMP (0:4): received packet from ####.####.####.250 dport 500 sport 500 Global (R) AG_NO_STATE&#012;01:27:16: ISAKMP (0:4): phase 1 packet is a duplicate of a previous packet.&#012;01:27:16: ISAKMP (0:4): retransmitting due to retransmit phase 1&#012;01:27:16: ISAKMP (0:4): no outgoing phase 1 packet to retransmit. AG_NO_STATE&#012;01:27:21: ISAKMP (0:4): received packet from ####.####.####.250 dport 500 sport 500 Global (R) AG_NO_STATE&#012;01:27:21: ISAKMP (0:4): phase 1 packet is a duplicate of a previous packet.&#012;01:27:21: ISAKMP (0:4): retransmitting due to retransmit phase 1&#012;01:27:21: ISAKMP (0:4): no outgoing phase 1 packet to retransmit. AG_NO_STATE&#012;</textarea><!--end code block--><br>Please let me know if there is anything else that might assist in your assistance.<br><br>Thank you,<br>Conn]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20760708</guid>
<pubDate>Tue, 08 Jul 2008 19:16:41 EDT</pubDate>
</item>

</channel>
</rss>
