RE: IPsec VPN

From: Ryan West <rwest_at_zyedge.com>
Date: Thu, 18 Jun 2009 08:10:41 -0400

Without seeing the relevant information that Phase 2 must match on (interesting traffic and transform sets), it is hard to tell. Please post the following:

If you're running post 6.3(5), you can run the ASA commands on the PIX.

ASA:
Show run crypto
Show run access-list <insert interesting traffic ACLs>

PIX:
Show run | i crypto
Show run | i access-list <insert interesting traffic ACLs>

-ryan

-----Original Message-----
From: nobody_at_groupstudy.com [mailto:nobody_at_groupstudy.com] On Behalf Of Ali El Moussaoui
Sent: Thursday, June 18, 2009 4:47 AM
To: ccielab_at_groupstudy.com
Subject: IPsec VPN

Hello Experts,

I am building an IPsec tunnel between 2 remote sites (ASA and PIX). The
tunnel is comin up only when the ASA initiates the communication. When the
pix initiate the tunnel negotiation the following error shows up:

Group = x.x.x.x, IP = x.x.x.x, Removing peer from correlator table failed,
no match!
Group = x.x.x.x, IP = x.x.x.x, Connection terminated for peer x.x.x.x.
Reason: Peer Terminate Remote Proxy N/A, Local Proxy N/A
Group = x.x.x.x, IP = x.x.x.x, Received non-routine Notify message: No
proposal chosen (14)
Group = x.x.x.x, IP = x.x.x.x, PHASE 1 COMPLETED

Any clue about what could cos the above?

Ali

Blogs and organic groups at http://www.ccie.net
Received on Thu Jun 18 2009 - 08:10:41 ART

This archive was generated by hypermail 2.2.0 : Wed Jul 01 2009 - 20:02:37 ART