troubleshooting Question

Crypto keeps droppping on PIX to PIX vpn tunnel

Avatar of ebigs27
ebigs27 asked on
NetworkingHardware FirewallsCisco
22 Comments1 Solution1558 ViewsLast Modified:
Hello again all
I am posting due to problems with our VPN tunnel.  It appears that the VPN tunnel is dropping due to a crypto error.  Users are complaining that while reading email in Outlook, they will get "Server no longer Available".  

I have been watching logs and the crypto status on 2 sites, and if I do a sho cry isa sa, it shows QM_IDLE, but under the column created the number keeps rising.   In one hour, the created column was up to 14count.

Errors I receive in log are as follows:

crypto_isakmp_process_block:src:1.2.3.4, dest:4.3.2.1 spt:500 dpt:500
ISAKMP (0): processing DELETE payload. message ID = 1693178854, spi size = 4IPSEC(key_engine): got a queue event...
IPSEC(key_engine_delete_sas): rec'd delete notify from ISAKMP

VPN Peer: IPSEC: Peer ip:1.2.3.4/500 Decrementing Ref cnt to:4 Total VPN Peers:1
VPN Peer: IPSEC: Peer ip:1.2.3.4/500 Decrementing Ref cnt to:3 Total VPN Peers:1
return status is IKMP_NO_ERR_NO_TRANS

crypto_isakmp_process_block:src:1.2.3.4, dest:4.3.2.1 spt:500 dpt:500
ISAKMP (0): processing NOTIFY payload 36136 protocol 1
        spi 0, message ID = 1023884254
ISAMKP (0): received DPD_R_U_THERE from peer 1.2.3.4
ISAKMP (0): sending NOTIFY message 36137 protocol 1
return status is IKMP_NO_ERR_NO_TRANS

Any suggestions on why the crypto would keep bouncing as it appears to be?   Any help would be appreciated.  Thanks
Join the community to see this answer!
Join our exclusive community to see this answer & millions of others.
Unlock 1 Answer and 22 Comments.
Join the Community
Learn from the best

Network and collaborate with thousands of CTOs, CISOs, and IT Pros rooting for you and your success.

Andrew Hancock - VMware vExpert
See if this solution works for you by signing up for a 7 day free trial.
Unlock 1 Answer and 22 Comments.
Try for 7 days

”The time we save is the biggest benefit of E-E to our team. What could take multiple guys 2 hours or more each to find is accessed in around 15 minutes on Experts Exchange.

-Mike Kapnisakis, Warner Bros