> nameif inside
> ip address 10.28.5.20 255.255.255.0
If your inside LAN subnet is 10.28.5.0/24 then nothing else in the config makes any sense.
All of your acls and statics refer to 10.1.3.0/24 as being inside
You have no inside route statement routing 10.1.3.0 anywhere
What exact versions of ASA 7.x and VPN client are you using?
There is a new VPN 5.0.0600 version client
Main Topics
Browse All Topics





by: greenbeanx81Posted on 2007-07-27 at 01:47:09ID: 19580958
Hello All,
T_MSG3, EV_TIMEOUT-->AM_WAIT_MSG3, NullEvent-->AM_SND_MSG2, EV_CRYPTO_ACTIVE-->AM_SND_ MSG2, EV_SND_MSG-->AM_SND_MSG2, EV_START_TMR-->AM_SND_MSG2 , EV_RESEND_MSG
I ran a crypto debug level 15. Here is the output. What concerns me is the duplicate phase 1 packets. Any thoughts?
Jul 27 01:15:16 [IKEv1]: IP = x.x.x.181, IKE_DECODE RECEIVED Message (msgid=0) with payloads : HDR + SA (1) + KE (4) + NONCE (10) + ID (5) + VENDOR (13) + VENDOR (13) + VENDOR (13) + VENDOR (13) + VENDOR (13) + NONE (0) total length : 850
Jul 27 01:15:16 [IKEv1 DEBUG]: IP = x.x.x.181, processing SA payload
Jul 27 01:15:16 [IKEv1 DEBUG]: IP = x.x.x.181, processing ke payload
Jul 27 01:15:16 [IKEv1 DEBUG]: IP = x.x.x.181, processing ISA_KE payload
Jul 27 01:15:16 [IKEv1 DEBUG]: IP = x.x.x.181, processing nonce payload
Jul 27 01:15:16 [IKEv1 DEBUG]: IP = x.x.x.181, processing ID payload
Jul 27 01:15:16 [IKEv1 DEBUG]: IP = x.x.x.181, processing VID payload
Jul 27 01:15:16 [IKEv1 DEBUG]: IP = x.x.x.181, Received xauth V6 VID
Jul 27 01:15:16 [IKEv1 DEBUG]: IP = x.x.x.181, processing VID payload
Jul 27 01:15:16 [IKEv1 DEBUG]: IP = x.x.x.181, Received DPD VID
Jul 27 01:15:16 [IKEv1 DEBUG]: IP = x.x.x.181, processing VID payload
Jul 27 01:15:16 [IKEv1 DEBUG]: IP = x.x.x.181, Received Fragmentation VID
Jul 27 01:15:16 [IKEv1 DEBUG]: IP = x.x.x.181, IKE Peer included IKE fragmentation capability flags: Main Mode: True Aggressive Mode: False
Jul 27 01:15:16 [IKEv1 DEBUG]: IP = x.x.x.181, processing VID payload
Jul 27 01:15:16 [IKEv1 DEBUG]: IP = x.x.x.181, Received NAT-Traversal ver 02 VID
Jul 27 01:15:16 [IKEv1 DEBUG]: IP = x.x.x.181, processing VID payload
Jul 27 01:15:16 [IKEv1 DEBUG]: IP = x.x.x.181, Received Cisco Unity client VID
Jul 27 01:15:16 [IKEv1]: IP = x.x.x.181, Connection landed on tunnel_group BARODA
Jul 27 01:15:16 [IKEv1 DEBUG]: Group = BARODA, IP = x.x.x.181, processing IKE SA payload
Jul 27 01:15:16 [IKEv1 DEBUG]: Group = BARODA, IP = x.x.x.181, IKE SA Proposal # 1, Transform # 13 acceptable Matches global IKE entry # 1
Jul 27 01:15:16 [IKEv1 DEBUG]: Group = BARODA, IP = x.x.x.181, constructing ISAKMP SA payload
Jul 27 01:15:16 [IKEv1 DEBUG]: Group = BARODA, IP = x.x.x.181, constructing ke payload
Jul 27 01:15:16 [IKEv1 DEBUG]: Group = BARODA, IP = x.x.x.181, constructing nonce payload
Jul 27 01:15:16 [IKEv1 DEBUG]: Group = BARODA, IP = x.x.x.181, Generating keys for Responder...
Jul 27 01:15:16 [IKEv1 DEBUG]: Group = BARODA, IP = x.x.x.181, constructing ID payload
Jul 27 01:15:16 [IKEv1 DEBUG]: Group = BARODA, IP = x.x.x.181, constructing hash payload
Jul 27 01:15:16 [IKEv1 DEBUG]: Group = BARODA, IP = x.x.x.181, Computing hash for ISAKMP
Jul 27 01:15:16 [IKEv1 DEBUG]: Group = BARODA, IP = x.x.x.181, constructing Cisco Unity VID payload
Jul 27 01:15:16 [IKEv1 DEBUG]: Group = BARODA, IP = x.x.x.181, constructing xauth V6 VID payload
Jul 27 01:15:16 [IKEv1 DEBUG]: Group = BARODA, IP = x.x.x.181, constructing dpd vid payload
Jul 27 01:15:16 [IKEv1 DEBUG]: Group = BARODA, IP = x.x.x.181, constructing NAT-Traversal VID ver 02 payload
Jul 27 01:15:16 [IKEv1 DEBUG]: Group = BARODA, IP = x.x.x.181, constructing NAT-Discovery payload
Jul 27 01:15:16 [IKEv1 DEBUG]: Group = BARODA, IP = x.x.x.181, computing NAT Discovery hash
Jul 27 01:15:16 [IKEv1 DEBUG]: Group = BARODA, IP = x.x.x.181, constructing NAT-Discovery payload
Jul 27 01:15:16 [IKEv1 DEBUG]: Group = BARODA, IP = x.x.x.181, computing NAT Discovery hash
Jul 27 01:15:16 [IKEv1 DEBUG]: Group = BARODA, IP = x.x.x.181, constructing Fragmentation VID + extended capabilities payload
Jul 27 01:15:16 [IKEv1 DEBUG]: Group = BARODA, IP = x.x.x.181, constructing VID payload
Jul 27 01:15:16 [IKEv1 DEBUG]: Group = BARODA, IP = x.x.x.181, Send Altiga/Cisco VPN3000/Cisco ASA GW VID
Jul 27 01:15:16 [IKEv1]: IP = x.x.x.181, IKE_DECODE SENDING Message (msgid=0) with payloads : HDR + SA (1) + KE (4) + NONCE (10) + ID (5) + HASH (8) + VENDOR (13) + VENDOR (13) + VENDOR (13) + VENDOR (13) + NAT-D (130) + NAT-D (130) + VENDOR (13) + VENDOR (13) + NONE (0) total length : 428
Jul 27 01:15:21 [IKEv1]: Group = BARODA, IP = x.x.x.181, Duplicate Phase 1 packet detected. Retransmitting last packet.
Jul 27 01:15:21 [IKEv1]: Group = BARODA, IP = x.x.x.181, P1 Retransmit msg dispatched to AM FSM
Jul 27 01:15:26 [IKEv1]: Group = BARODA, IP = x.x.x.181, Duplicate Phase 1 packet detected. Retransmitting last packet.
Jul 27 01:15:26 [IKEv1]: Group = BARODA, IP = x.x.x.181, P1 Retransmit msg dispatched to AM FSM
Jul 27 01:15:31 [IKEv1]: Group = BARODA, IP = x.x.x.181, Duplicate Phase 1 packet detected. Retransmitting last packet.
Jul 27 01:15:31 [IKEv1]: Group = BARODA, IP = x.x.x.181, P1 Retransmit msg dispatched to AM FSM
Jul 27 01:15:39 [IKEv1 DEBUG]: Group = BARODA, IP = x.x.x.181, IKE AM Responder FSM error history (struct &0x35fbd08) <state>, <event>: AM_DONE, EV_ERROR-->AM_WAIT_MSG3, EV_PROB_AUTH_FAIL-->AM_WAI
Jul 27 01:15:39 [IKEv1 DEBUG]: Group = BARODA, IP = x.x.x.181, IKE SA AM:9e37833d terminating: flags 0x0104c001, refcnt 0, tuncnt 0
Jul 27 01:15:39 [IKEv1 DEBUG]: Group = BARODA, IP = x.x.x.181, sending delete/delete with reason message
Jul 27 01:15:39 [IKEv1 DEBUG]: Group = BARODA, IP = x.x.x.181, constructing blank hash payload
Jul 27 01:15:39 [IKEv1 DEBUG]: Group = BARODA, IP = x.x.x.181, constructing IKE delete payload
Jul 27 01:15:39 [IKEv1 DEBUG]: Group = BARODA, IP = x.x.x.181, constructing qm hash payload
Jul 27 01:15:39 [IKEv1]: IP = x.x.x.181, IKE_DECODE SENDING Message (msgid=c4edb2e1) with payloads : HDR + HASH (8) + DELETE (12) + NONE (0) total length : 76
Jul 27 01:15:39 [IKEv1]: Group = BARODA, IP = x.x.x.181, Removing peer from peer table failed, no match!
Jul 27 01:15:39 [IKEv1]: Group = BARODA, IP = x.x.x.181, Error: Unable to remove PeerTblEntry