Cisco ASA & Client VPN - IKE Re-transmission

Posted on 2008-11-14
Last Modified: 2012-05-05
I have an ASA 5505 with 2 WAN interfaces - 1st accepts and connects with the VPN client but the 2nd doesn't.   I get the following messages in client log:

213    20:57:26.781  11/14/08  Sev=Info/4               CM/0x63100029
TCP connection established on port 10000 with server ""

214    20:57:27.265  11/14/08  Sev=Info/4               CM/0x63100024
Attempt connection with server ""

215    20:57:27.328  11/14/08  Sev=Info/6               IKE/0x6300003B
Attempting to establish a connection with

216    20:57:27.328  11/14/08  Sev=Info/4               IKE/0x63000013
SENDING >>> ISAKMP OAK AG (SA, KE, NON, ID, VID(Xauth), VID(dpd), VID(Frag), VID(Unity)) to

217    20:57:31.765  11/14/08  Sev=Info/6               IPSEC/0x6370001D
TCP RST received from, src port 10000, dst port 2520

218    20:57:32.765  11/14/08  Sev=Info/4               IKE/0x63000021
Retransmitting last packet!

Question by:snchelpdesk
    1 Comment
    LVL 6

    Accepted Solution

    try dropping:
    sysopt connection permit-vpn , this allow you to bypass nat and acl rule for ipsec traffic.

    then now we can start troubleshoot the ipsec or VPN setting.

    "route outside 1 track 1"

    you will have 2 different route for 2 wan interfaces

    for testing the 2nd WAN interface, use:

    route outside x.x.x.x  x.x.x.x. x.x.x(seecond wan interface) 1

    Please provide config and logs from the remote device for further assistant..


    Write Comment

    Please enter a first name

    Please enter a last name

    We will never share this with anyone.

    Featured Post

    PRTG Network Monitor: Intuitive Network Monitoring

    Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

    Overview The Cisco PIX 501, PIX 506e, ASA 5505 and ASA 5510 (most if not all of this information will be relevant to the PIX 515e but I do not have a working configuration handy to verify the validity) are primarily used within small to medium busi…
    From Cisco ASA version 8.3, the Network Address Translation (NAT) configuration has been completely redesigned and it may be helpful to have the syntax configuration for both at a glance. You may as well want to read official Cisco published AS…
    Hi everyone! This is Experts Exchange customer support.  This quick video will show you how to change your primary email address.  If you have any questions, then please Write a Comment below!
    This video gives you a great overview about bandwidth monitoring with SNMP and WMI with our network monitoring solution PRTG Network Monitor ( If you're looking for how to monitor bandwidth using netflow or packet s…

    737 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    17 Experts available now in Live!

    Get 1:1 Help Now