Yes, the error means Phase 1 )ISAKMP) completed successfully but Phase 2 (IPSec) failed because the firewall could not find a proposal match - check your crypto map and make sure you use the same IPSec settings the windows server is expecting. For example, if you're using AES-256 only and the other side is sending 3DES/SHA1, you'd get no match. This also happens if the proposals don't match exactly - you may have 3DES/MD5 with a SA lifetime of 28800 seconds while the other side uses 3DES/MD5 but a 86400 second lifetime...
Main Topics
Browse All Topics





by: mwecomputersPosted on 2009-10-22 at 12:17:01ID: 25637897
From first glance it looks like an IPSec mismatch, however there might be an underlying issue.
Can you post a sanitized version of your running config on the ASA 5510?