I know this can't be a difficult problem, but this is a first-time set up for me; I've been setting up multiple IPsec connections from 1710 routers to our 3000 Concentrator and this is the only 3002 hardware client of the lot. I'm getting a phase I error trying to establish a tunnel in client mode; this is the log:
137 07/08/2004 13:22:38.890 SEV=7 IPSECDBG/14 RPT=6
Sending KEY_ACQUIRE to IKE for src ##.##.##.##, dst ##.##.##.##
138 07/08/2004 13:22:38.890 SEV=8 IKEDBG/0 RPT=16
pitcher: received a key acquire message!
139 07/08/2004 13:22:38.890 SEV=4 IKE/41 RPT=12 ##.##.##.##
IKE Initiator: New Phase 1, Intf 12, IKE Peer ##.##.##.##
local Proxy Address ##.##.##.##, remote Proxy Address ##.##.##.##,
SA (ESP-3DES-MD5)
142 07/08/2004 13:22:38.890 SEV=5 IP/45 RPT=9
Client transmitting TCP SYN pkt to device ##.##.##.## on TCP src port #####, dst port 10000
144 07/08/2004 13:22:58.890 SEV=7 IKEDBG/65 RPT=6 ##.##.##.##
IKE AM Initiator FSM error history (struct &0xed2960)
<state>, <event>:
AM_DONE, EV_ERROR_CONT
AM_DONE, EV_ERROR
AM_CTCP_WAIT_REPLY, EV_CTCP_LINK_FAIL
AM_CTCP_WAIT_REPLY, EV_TIMEOUT
149 07/08/2004 13:22:58.890 SEV=9 IKEDBG/0 RPT=17 ##.##.##.##
IKE SA AM:6cf0d0d5 terminating:
flags 0x01000021, refcnt 0, tuncnt 0
150 07/08/2004 13:22:58.890 SEV=9 IKEDBG/0 RPT=18
sending delete/delete with reason message
151 07/08/2004 13:22:58.890 SEV=5 IP/36 RPT=9
Client fails to connect to headend device ##.##.##.## on TCP port 10000.
I haven't been able to locate any documentation that breaks down this error string to where I can correct the config - any takers?
Thanks,
Marc
137 07/08/2004 13:22:38.890 SEV=7 IPSECDBG/14 RPT=6
Sending KEY_ACQUIRE to IKE for src ##.##.##.##, dst ##.##.##.##
138 07/08/2004 13:22:38.890 SEV=8 IKEDBG/0 RPT=16
pitcher: received a key acquire message!
139 07/08/2004 13:22:38.890 SEV=4 IKE/41 RPT=12 ##.##.##.##
IKE Initiator: New Phase 1, Intf 12, IKE Peer ##.##.##.##
local Proxy Address ##.##.##.##, remote Proxy Address ##.##.##.##,
SA (ESP-3DES-MD5)
142 07/08/2004 13:22:38.890 SEV=5 IP/45 RPT=9
Client transmitting TCP SYN pkt to device ##.##.##.## on TCP src port #####, dst port 10000
144 07/08/2004 13:22:58.890 SEV=7 IKEDBG/65 RPT=6 ##.##.##.##
IKE AM Initiator FSM error history (struct &0xed2960)
<state>, <event>:
AM_DONE, EV_ERROR_CONT
AM_DONE, EV_ERROR
AM_CTCP_WAIT_REPLY, EV_CTCP_LINK_FAIL
AM_CTCP_WAIT_REPLY, EV_TIMEOUT
149 07/08/2004 13:22:58.890 SEV=9 IKEDBG/0 RPT=17 ##.##.##.##
IKE SA AM:6cf0d0d5 terminating:
flags 0x01000021, refcnt 0, tuncnt 0
150 07/08/2004 13:22:58.890 SEV=9 IKEDBG/0 RPT=18
sending delete/delete with reason message
151 07/08/2004 13:22:58.890 SEV=5 IP/36 RPT=9
Client fails to connect to headend device ##.##.##.## on TCP port 10000.
I haven't been able to locate any documentation that breaks down this error string to where I can correct the config - any takers?
Thanks,
Marc