I'm having problem to creating VPN tunnel between these two devices.
I changed Firebox's IP-address to 1.1.1.1
And Cisco's to 2.2.2.2
Here is some debug output from Cisco 878:
*Apr 12 17:10:57.325: ISAKMP (0:2181): received packet from 1.1.1.1 dport 4500 sport 23294 Global (R) QM_IDLE
*Apr 12 17:10:57.325: ISAKMP: set new node 22914874 to QM_IDLE
*Apr 12 17:10:57.325: ISAKMP:(2181): processing HASH payload. message ID = 22914874
*Apr 12 17:10:57.329: ISAKMP:(2181): processing NOTIFY DPD/R_U_THERE protocol 1
spi 0, message ID = 22914874, sa = 83F42324
*Apr 12 17:10:57.329: ISAKMP:(2181):deleting node 22914874 error FALSE reason "Informational (in) state 1"
*Apr 12 17:10:57.329: ISAKMP:(2181):Input = IKE_MESG_FROM_PEER, IKE_INFO_NOTIFY
*Apr 12 17:10:57.329: ISAKMP:(2181):Old State = IKE_P1_COMPLETE New State = IKE_P1_COMPLETE
*Apr 12 17:10:57.329: ISAKMP:(2181):DPD/R_U_THER
E received from peer 1.1.1.1, sequence 0x4794DE66
*Apr 12 17:10:57.329: ISAKMP: set new node 1691270778 to QM_IDLE
*Apr 12 17:10:57.329: ISAKMP:(2181):Sending NOTIFY DPD/R_U_THERE_ACK protocol 1
spi 2208842384, message ID = 1691270778
*Apr 12 17:10:57.329: ISAKMP:(2181): seq. no 0x4794DE66
*Apr 12 17:10:57.329: ISAKMP:(2181): sending packet to 1.1.1.1 my_port 4500 peer_port 23294 (R) QM_IDLE
*Apr 12 17:10:57.329: ISAKMP:(2181):Sending an IKE IPv4 Packet.
*Apr 12 17:10:57.333: ISAKMP:(2181):purging node 1691270778
*Apr 12 17:10:57.333: ISAKMP:(2181):Input = IKE_MESG_FROM_PEER, IKE_MESG_KEEP_ALIVE
*Apr 12 17:10:57.333: ISAKMP:(2181):Old State = IKE_P1_COMPLETE New State = IKE_P1_COMPLETE
*Apr 12 17:11:07.557: IPSEC(key_engine): request timer fired: count = 2,
(identity) local= 2.2.2.2, remote= 1.1.1.1,
local_proxy= 192.168.3.0/255.255.255.0/
0/0 (type=4),
remote_proxy= 192.168.1.0/255.255.255.0/
0/0 (type=4)
*Apr 12 17:11:08.185: IPSEC(sa_request): ,
(key eng. msg.) OUTBOUND local= 2.2.2.2, remote= 1.1.1.1,
local_proxy= 192.168.3.0/255.255.255.0/
0/0 (type=4),
remote_proxy= 192.168.1.0/255.255.255.0/
0/0 (type=4),
protocol= ESP, transform= NONE (Tunnel),
lifedur= 28800s and 128000kb,
spi= 0x0(0), conn_id= 0, keysize= 256, flags= 0x0
*Apr 12 17:11:08.185: ISAKMP: set new node 0 to CONF_XAUTH
*Apr 12 17:11:08.185: ISAKMP:(0):SA is still budding. Attached new ipsec request to it. (local 2.2.2.2, remote 1.1.1.1)
*Apr 12 17:11:08.185: ISAKMP: Error while processing SA request: Failed to initialize SA
*Apr 12 17:11:08.185: ISAKMP: Error while processing KMI message 0, error 2.
*Apr 12 17:11:22.561: ISAKMP: quick mode timer expired.
*Apr 12 17:11:22.561: ISAKMP:(0):src 2.2.2.2 dst 1.1.1.1, SA is not authenticated
*Apr 12 17:11:22.561: ISAKMP:(0):peer does not do paranoid keepalives.
*Apr 12 17:11:22.561: ISAKMP:(0):deleting SA reason "QM_TIMER expired" state (I) MM_NO_STATE (peer 1.1.1.1)
*Apr 12 17:11:22.561: ISAKMP:(0):deleting SA reason "QM_TIMER expired" state (I) MM_NO_STATE (peer 1.1.1.1)
*Apr 12 17:11:22.561: ISAKMP: Unlocking peer struct 0x8358D698 for isadb_mark_sa_deleted(), count 0
*Apr 12 17:11:22.561: ISAKMP: Deleting peer node by peer_reap for 1.1.1.1: 8358D698
*Apr 12 17:11:22.561: ISAKMP:(0):deleting node -1531374776 error FALSE reason "IKE deleted"
*Apr 12 17:11:22.561: ISAKMP:(0):deleting node -1783709907 error FALSE reason "IKE deleted"
*Apr 12 17:11:22.561: ISAKMP:(0):deleting node 930963450 error FALSE reason "IKE deleted"
*Apr 12 17:11:22.561: ISAKMP:(0):Input = IKE_MESG_INTERNAL, IKE_PHASE1_DEL
*Apr 12 17:11:22.561: ISAKMP:(0):Old State = IKE_I_MM1 New State = IKE_DEST_SA
*Apr 12 17:11:22.565: IPSEC(key_engine): got a queue event with 1 KMI message(s)
*Apr 12 17:11:38.185: IPSEC(key_engine): request timer fired: count = 1,
(identity) local= 2.2.2.2, remote= 1.1.1.1,
local_proxy= 192.168.3.0/255.255.255.0/
0/0 (type=4),
remote_proxy= 192.168.1.0/255.255.255.0/
0/0 (type=4)
*Apr 12 17:11:38.185: IPSEC(sa_request): ,
(key eng. msg.) OUTBOUND local= 2.2.2.2, remote= 1.1.1.1,
local_proxy= 192.168.3.0/255.255.255.0/
0/0 (type=4),
remote_proxy= 192.168.1.0/255.255.255.0/
0/0 (type=4),
protocol= ESP, transform= NONE (Tunnel),
lifedur= 28800s and 128000kb,
spi= 0x0(0), conn_id= 0, keysize= 256, flags= 0x0
*Apr 12 17:11:38.185: ISAKMP:(0): SA request profile is (NULL)
*Apr 12 17:11:38.185: ISAKMP: Created a peer struct for 1.1.1.1, peer port 500
*Apr 12 17:11:38.185: ISAKMP: New peer created peer = 0x83EC688C peer_handle = 0x80000581
*Apr 12 17:11:38.185: ISAKMP: Locking peer struct 0x83EC688C, refcount 1 for isakmp_initiator
*Apr 12 17:11:38.185: ISAKMP:(0):Setting client config settings 842BEBAC
*Apr 12 17:11:38.185: ISAKMP:(0):(Re)Setting client xauth list and state
*Apr 12 17:11:38.185: ISAKMP/xauth: initializing AAA request
*Apr 12 17:11:38.189: ISAKMP: local port 500, remote port 500
*Apr 12 17:11:38.189: ISAKMP: set new node 0 to CONF_XAUTH
*Apr 12 17:11:38.189: ISAKMP: Find a dup sa in the avl tree during calling isadb_insert sa = 83E3A7E4
*Apr 12 17:11:38.189: ISAKMP:(0):Can not start Aggressive mode, trying Main mode.
*Apr 12 17:11:38.189: ISAKMP:(0):found peer pre-shared key matching 1.1.1.1
*Apr 12 17:11:38.189: ISAKMP:(0): constructed NAT-T vendor-07 ID
*Apr 12 17:11:38.189: ISAKMP:(0): constructed NAT-T vendor-03 ID
*Apr 12 17:11:38.189: ISAKMP:(0): constructed NAT-T vendor-02 ID
*Apr 12 17:11:38.189: ISAKMP:(0):Input = IKE_MESG_FROM_IPSEC, IKE_SA_REQ_MM
*Apr 12 17:11:38.189: ISAKMP:(0):Old State = IKE_READY New State = IKE_I_MM1
*Apr 12 17:11:38.189: ISAKMP:(0): beginning Main Mode exchange
*Apr 12 17:11:38.189: ISAKMP:(0): sending packet to 1.1.1.1 my_port 500 peer_port 500 (I) MM_NO_STATE
*Apr 12 17:11:38.189: ISAKMP:(0):Sending an IKE IPv4 Packet.
*Apr 12 17:11:38.205: ISAKMP (0:0): received packet from 1.1.1.1 dport 500 sport 500 Global (I) MM_NO_STATE
*Apr 12 17:11:38.209: ISAKMP:(0):Notify has no hash. Rejected.
*Apr 12 17:11:38.209: ISAKMP (0:0): Unknown Input IKE_MESG_FROM_PEER, IKE_INFO_NOTIFY: state = IKE_I_MM1
*Apr 12 17:11:38.209: ISAKMP:(0):Input = IKE_MESG_FROM_PEER, IKE_INFO_NOTIFY
*Apr 12 17:11:38.209: ISAKMP:(0):Old State = IKE_I_MM1 New State = IKE_I_MM1
*Apr 12 17:11:38.209: %CRYPTO-6-IKMP_MODE_FAILUR
E: Processing of Informational mode failed with peer at 1.1.1.1
*Apr 12 17:11:47.329: ISAKMP:(2181):purging node 22914874
*Apr 12 17:12:08.185: IPSEC(key_engine): request timer fired: count = 2,
(identity) local= 2.2.2.2, remote= 1.1.1.1,
local_proxy= 192.168.3.0/255.255.255.0/
0/0 (type=4),
remote_proxy= 192.168.1.0/255.255.255.0/
0/0 (type=4)
*Apr 12 17:12:12.849: ISAKMP (0:2181): received packet from 1.1.1.1 dport 4500 sport 23294 Global (R) QM_IDLE
*Apr 12 17:12:12.849: ISAKMP: set new node 1353152698 to QM_IDLE
*Apr 12 17:12:12.849: ISAKMP:(2181): processing HASH payload. message ID = 1353152698
*Apr 12 17:12:12.849: ISAKMP:(2181): processing NOTIFY DPD/R_U_THERE protocol 1
spi 0, message ID = 1353152698, sa = 83F42324
*Apr 12 17:12:12.849: ISAKMP:(2181):deleting node 1353152698 error FALSE reason "Informational (in) state 1"
*Apr 12 17:12:12.849: ISAKMP:(2181):Input = IKE_MESG_FROM_PEER, IKE_INFO_NOTIFY
*Apr 12 17:12:12.849: ISAKMP:(2181):Old State = IKE_P1_COMPLETE New State = IKE_P1_COMPLETE
*Apr 12 17:12:12.853: ISAKMP:(2181):DPD/R_U_THER
E received from peer 1.1.1.1, sequence 0x4794DE67
*Apr 12 17:12:12.853: ISAKMP: set new node -859419958 to QM_IDLE
*Apr 12 17:12:12.853: ISAKMP:(2181):Sending NOTIFY DPD/R_U_THERE_ACK protocol 1
spi 2208842384, message ID = -859419958
*Apr 12 17:12:12.853: ISAKMP:(2181): seq. no 0x4794DE67
*Apr 12 17:12:12.853: ISAKMP:(2181): sending packet to 1.1.1.1 my_port 4500 peer_port 23294 (R) QM_IDLE
*Apr 12 17:12:12.853: ISAKMP:(2181):Sending an IKE IPv4 Packet.
*Apr 12 17:12:12.853: ISAKMP:(2181):purging node -859419958
*Apr 12 17:12:12.853: ISAKMP:(2181):Input = IKE_MESG_FROM_PEER, IKE_MESG_KEEP_ALIVE
*Apr 12 17:12:12.853: ISAKMP:(2181):Old State = IKE_P1_COMPLETE New State = IKE_P1_COMPLETE
*Apr 12 17:12:22.561: ISAKMP:(0):purging SA., sa=83041BE0, delme=83041BE0
*Apr 12 17:12:22.561: ISAKMP:(0):purging node -1531374776
*Apr 12 17:12:22.561: ISAKMP:(0):purging node -1783709907
*Apr 12 17:12:22.561: ISAKMP:(0):purging node 930963450
*Apr 12 17:12:53.189: ISAKMP: quick mode timer expired.
*Apr 12 17:12:53.189: ISAKMP:(0):src 2.2.2.2 dst 1.1.1.1, SA is not authenticated
*Apr 12 17:12:53.189: ISAKMP:(0):peer does not do paranoid keepalives.
*Apr 12 17:12:53.189: ISAKMP:(0):deleting SA reason "QM_TIMER expired" state (I) MM_NO_STATE (peer 1.1.1.1)
*Apr 12 17:12:53.189: ISAKMP:(0):deleting SA reason "QM_TIMER expired" state (I) MM_NO_STATE (peer 1.1.1.1)
*Apr 12 17:12:53.189: ISAKMP: Unlocking peer struct 0x83EC688C for isadb_mark_sa_deleted(), count 0
*Apr 12 17:12:53.189: ISAKMP: Deleting peer node by peer_reap for 1.1.1.1: 83EC688C
*Apr 12 17:12:53.189: ISAKMP:(0):deleting node -408327990 error FALSE reason "IKE deleted"
*Apr 12 17:12:53.189: ISAKMP:(0):Input = IKE_MESG_INTERNAL, IKE_PHASE1_DEL
*Apr 12 17:12:53.189: ISAKMP:(0):Old State = IKE_I_MM1 New State = IKE_DEST_SA
*Apr 12 17:12:53.193: IPSEC(key_engine): got a queue event with 1 KMI message(s)
*Apr 12 17:13:02.849: ISAKMP:(2181):purging node 1353152698
*Apr 12 17:13:23.369: ISAKMP (0:2181): received packet from 1.1.1.1 dport 4500 sport 23294 Global (R) QM_IDLE
*Apr 12 17:13:23.369: ISAKMP: set new node 1338599672 to QM_IDLE
*Apr 12 17:13:23.369: ISAKMP:(2181): processing HASH payload. message ID = 1338599672
*Apr 12 17:13:23.369: ISAKMP:(2181): processing NOTIFY DPD/R_U_THERE protocol 1
spi 0, message ID = 1338599672, sa = 83F42324
*Apr 12 17:13:23.369: ISAKMP:(2181):deleting node 1338599672 error FALSE reason "Informational (in) state 1"
*Apr 12 17:13:23.369: ISAKMP:(2181):Input = IKE_MESG_FROM_PEER, IKE_INFO_NOTIFY
*Apr 12 17:13:23.369: ISAKMP:(2181):Old State = IKE_P1_COMPLETE New State = IKE_P1_COMPLETE
*Apr 12 17:13:23.369: ISAKMP:(2181):DPD/R_U_THER
E received from peer 1.1.1.1, sequence 0x4794DE68
*Apr 12 17:13:23.369: ISAKMP: set new node -1492865989 to QM_IDLE
*Apr 12 17:13:23.373: ISAKMP:(2181):Sending NOTIFY DPD/R_U_THERE_ACK protocol 1
spi 2208842384, message ID = -1492865989
*Apr 12 17:13:23.373: ISAKMP:(2181): seq. no 0x4794DE68
*Apr 12 17:13:23.373: ISAKMP:(2181): sending packet to 1.1.1.1 my_port 4500 peer_port 23294 (R) QM_IDLE
*Apr 12 17:13:23.373: ISAKMP:(2181):Sending an IKE IPv4 Packet.
*Apr 12 17:13:23.373: ISAKMP:(2181):purging node -1492865989
*Apr 12 17:13:23.373: ISAKMP:(2181):Input = IKE_MESG_FROM_PEER, IKE_MESG_KEEP_ALIVE
*Apr 12 17:13:23.373: ISAKMP:(2181):Old State = IKE_P1_COMPLETE New State = IKE_P1_COMPLETE
*Apr 12 17:13:53.189: ISAKMP:(0):purging SA., sa=83E3A7E4, delme=83E3A7E4
*Apr 12 17:13:53.189: ISAKMP:(0):purging node -408327990
*Apr 12 17:14:13.369: ISAKMP:(2181):purging node 1338599672
*Apr 12 17:14:34.645: IPSEC(sa_request): ,
(key eng. msg.) OUTBOUND local= 2.2.2.2, remote= 1.1.1.1,
local_proxy= 192.168.3.0/255.255.255.0/
0/0 (type=4),
remote_proxy= 192.168.1.0/255.255.255.0/
0/0 (type=4),
protocol= ESP, transform= NONE (Tunnel),
lifedur= 28800s and 128000kb,
spi= 0x0(0), conn_id= 0, keysize= 256, flags= 0x0
*Apr 12 17:14:34.645: ISAKMP:(0): SA request profile is (NULL)
*Apr 12 17:14:34.645: ISAKMP: Created a peer struct for 1.1.1.1, peer port 500
*Apr 12 17:14:34.649: ISAKMP: New peer created peer = 0x82EBEE28 peer_handle = 0x8000056A
*Apr 12 17:14:34.649: ISAKMP: Locking peer struct 0x82EBEE28, refcount 1 for isakmp_initiator
*Apr 12 17:14:34.649: ISAKMP:(0):Setting client config settings 842BEBAC
*Apr 12 17:14:34.649: ISAKMP:(0):(Re)Setting client xauth list and state
*Apr 12 17:14:34.649: ISAKMP/xauth: initializing AAA request
*Apr 12 17:14:34.649: ISAKMP: local port 500, remote port 500
*Apr 12 17:14:34.649: ISAKMP: set new node 0 to CONF_XAUTH
*Apr 12 17:14:34.649: insert sa successfully sa = 8358A314
*Apr 12 17:14:34.649: ISAKMP:(0):Can not start Aggressive mode, trying Main mode.
*Apr 12 17:14:34.649: ISAKMP:(0):found peer pre-shared key matching 1.1.1.1
*Apr 12 17:14:34.649: ISAKMP:(0): constructed NAT-T vendor-07 ID
*Apr 12 17:14:34.649: ISAKMP:(0): constructed NAT-T vendor-03 ID
*Apr 12 17:14:34.649: ISAKMP:(0): constructed NAT-T vendor-02 ID
*Apr 12 17:14:34.649: ISAKMP:(0):Input = IKE_MESG_FROM_IPSEC, IKE_SA_REQ_MM
*Apr 12 17:14:34.649: ISAKMP:(0):Old State = IKE_READY New State = IKE_I_MM1
*Apr 12 17:14:34.653: ISAKMP:(0): beginning Main Mode exchange
*Apr 12 17:14:34.653: ISAKMP:(0): sending packet to 1.1.1.1 my_port 500 peer_port 500 (I) MM_NO_STATE
*Apr 12 17:14:34.653: ISAKMP:(0):Sending an IKE IPv4 Packet.
*Apr 12 17:14:34.669: ISAKMP (0:0): received packet from 1.1.1.1 dport 500 sport 500 Global (I) MM_NO_STATE
*Apr 12 17:14:34.669: ISAKMP:(0):Notify has no hash. Rejected.
*Apr 12 17:14:34.669: ISAKMP (0:0): Unknown Input IKE_MESG_FROM_PEER, IKE_INFO_NOTIFY: state = IKE_I_MM1
*Apr 12 17:14:34.669: ISAKMP:(0):Input = IKE_MESG_FROM_PEER, IKE_INFO_NOTIFY
*Apr 12 17:14:34.669: ISAKMP:(0):Old State = IKE_I_MM1 New State = IKE_I_MM1
*Apr 12 17:14:34.669: %CRYPTO-6-IKMP_MODE_FAILUR
E: Processing of Informational mode failed with peer at 1.1.1.1
*Apr 12 17:14:44.397: ISAKMP (0:2181): received packet from 1.1.1.1 dport 4500 sport 23294 Global (R) QM_IDLE
*Apr 12 17:14:44.397: ISAKMP: set new node -1973294896 to QM_IDLE
*Apr 12 17:14:44.397: ISAKMP:(2181): processing HASH payload. message ID = -1973294896
*Apr 12 17:14:44.397: ISAKMP:(2181): processing NOTIFY DPD/R_U_THERE protocol 1
spi 0, message ID = -1973294896, sa = 83F42324
*Apr 12 17:14:44.397: ISAKMP:(2181):deleting node -1973294896 error FALSE reason "Informational (in) state 1"
*Apr 12 17:14:44.397: ISAKMP:(2181):Input = IKE_MESG_FROM_PEER, IKE_INFO_NOTIFY
*Apr 12 17:14:44.397: ISAKMP:(2181):Old State = IKE_P1_COMPLETE New State = IKE_P1_COMPLETE
*Apr 12 17:14:44.401: ISAKMP:(2181):DPD/R_U_THER
E received from peer 1.1.1.1, sequence 0x4794DE69
*Apr 12 17:14:44.401: ISAKMP: set new node -1527469735 to QM_IDLE
*Apr 12 17:14:44.401: ISAKMP:(2181):Sending NOTIFY DPD/R_U_THERE_ACK protocol 1
spi 2208842384, message ID = -1527469735
*Apr 12 17:14:44.401: ISAKMP:(2181): seq. no 0x4794DE69
*Apr 12 17:14:44.401: ISAKMP:(2181): sending packet to 1.1.1.1 my_port 4500 peer_port 23294 (R) QM_IDLE
*Apr 12 17:14:44.401: ISAKMP:(2181):Sending an IKE IPv4 Packet.
*Apr 12 17:14:44.401: ISAKMP:(2181):purging node -1527469735
*Apr 12 17:14:44.401: ISAKMP:(2181):Input = IKE_MESG_FROM_PEER, IKE_MESG_KEEP_ALIVE
*Apr 12 17:14:44.401: ISAKMP:(2181):Old State = IKE_P1_COMPLETE New State = IKE_P1_COMPLETE
*Apr 12 17:15:04.645: IPSEC(key_engine): request timer fired: count = 1,
(identity) local= 2.2.2.2, remote= 1.1.1.1,
local_proxy= 192.168.3.0/255.255.255.0/
0/0 (type=4),
remote_proxy= 192.168.1.0/255.255.255.0/
0/0 (type=4)
*Apr 12 17:15:04.645: IPSEC(sa_request): ,
(key eng. msg.) OUTBOUND local= 2.2.2.2, remote= 1.1.1.1,
local_proxy= 192.168.3.0/255.255.255.0/
0/0 (type=4),
remote_proxy= 192.168.1.0/255.255.255.0/
0/0 (type=4),
protocol= ESP, transform= NONE (Tunnel),
lifedur= 28800s and 128000kb,
spi= 0x0(0), conn_id= 0, keysize= 256, flags= 0x0
*Apr 12 17:15:04.645: ISAKMP: set new node 0 to CONF_XAUTH
*Apr 12 17:15:04.645: ISAKMP:(0):SA is still budding. Attached new ipsec request to it. (local 2.2.2.2, remote 1.1.1.1)
*Apr 12 17:15:04.645: ISAKMP: Error while processing SA request: Failed to initialize SA
*Apr 12 17:15:04.645: ISAKMP: Error while processing KMI message 0, error 2.
Cisco878#
Cisco878#undebug all
All possible debugging has been turned off
Cisco878#show crypto isakmp sa
IPv4 Crypto ISAKMP SA
dst src state conn-id slot status
1.1.1.1 2.2.2.2 MM_NO_STATE 0 0 ACTIVE (deleted)
2.2.2.2 1.1.1.1 QM_IDLE 2181 0 ACTIVE