The Phase 1 error indicates the receiver is expecting DH Group 2 but you've got group 5 configured:
crypto isakmp policy 30
authentication pre-share
encryption aes
hash sha
group 5
lifetime 86400
Either change that to group 2 or have the connection set to use 3DES/SHA instead of AES.
Main Topics
Browse All Topics





by: erkki01Posted on 2009-08-25 at 13:11:08ID: 25181724
Here's my current configuration. Connection type used was L2TP, TRANS_ESP_AES-128_SHA.
Select allOpen in new window