We help IT Professionals succeed at work.

cisco vpn client

Medium Priority
Last Modified: 2012-05-06
Below is log file. Any ideas as to 'why' greatly appreciated. Many thanks

Cisco Systems VPN Client Version
Copyright (C) 1998-2007 Cisco Systems, Inc. All Rights Reserved.
Client Type(s): Windows, WinNT
Running on: 5.1.2600 Service Pack 2

1      14:14:38.895  02/09/09  Sev=Info/4      CM/0x63100002
Begin connection process

2      14:14:38.895  02/09/09  Sev=Info/4      CM/0x63100004
Establish secure connection

3      14:14:38.895  02/09/09  Sev=Info/4      CM/0x63100024
Attempt connection with server ""

4      14:14:38.895  02/09/09  Sev=Info/6      CM/0x6310002F
Allocated local TCP port 2695 for TCP connection.

5      14:14:38.926  02/09/09  Sev=Info/4      IPSEC/0x63700008
IPSec driver successfully started

6      14:14:38.926  02/09/09  Sev=Info/4      IPSEC/0x63700014
Deleted all keys

7      14:14:38.926  02/09/09  Sev=Info/6      IPSEC/0x6370002C
Sent 4 packets, 0 were fragmented.

8      14:14:38.926  02/09/09  Sev=Info/6      IPSEC/0x63700020
TCP SYN sent to, src port 2695, dst port 10000

9      14:14:39.426  02/09/09  Sev=Info/6      IPSEC/0x6370001C
TCP SYN-ACK received from, src port 10000, dst port 2695

10     14:14:39.426  02/09/09  Sev=Info/6      IPSEC/0x63700021
TCP ACK sent to, src port 2695, dst port 10000

11     14:14:39.426  02/09/09  Sev=Info/4      CM/0x63100029
TCP connection established on port 10000 with server ""

12     14:14:39.926  02/09/09  Sev=Info/4      CM/0x63100024
Attempt connection with server ""

13     14:14:39.926  02/09/09  Sev=Info/6      IKE/0x6300003B
Attempting to establish a connection with

14     14:14:39.926  02/09/09  Sev=Info/4      IKE/0x63000013
SENDING >>> ISAKMP OAK AG (SA, KE, NON, ID, VID(Xauth), VID(dpd), VID(Frag), VID(Unity)) to

15     14:14:44.926  02/09/09  Sev=Info/4      IKE/0x63000021
Retransmitting last packet!

16     14:14:44.926  02/09/09  Sev=Info/4      IKE/0x63000013
SENDING >>> ISAKMP OAK AG (Retransmission) to

17     14:14:49.926  02/09/09  Sev=Info/4      IKE/0x63000021
Retransmitting last packet!

18     14:14:49.926  02/09/09  Sev=Info/4      IKE/0x63000013
SENDING >>> ISAKMP OAK AG (Retransmission) to

19     14:14:54.926  02/09/09  Sev=Info/4      IKE/0x63000021
Retransmitting last packet!

20     14:14:54.926  02/09/09  Sev=Info/4      IKE/0x63000013
SENDING >>> ISAKMP OAK AG (Retransmission) to

21     14:14:59.926  02/09/09  Sev=Info/4      IKE/0x63000017
Marking IKE SA for deletion  (I_Cookie=2BDD19A785CCE2AC R_Cookie=0000000000000000) reason = DEL_REASON_PEER_NOT_RESPONDING

22     14:15:00.426  02/09/09  Sev=Info/4      IKE/0x6300004B
Discarding IKE SA negotiation (I_Cookie=2BDD19A785CCE2AC R_Cookie=0000000000000000) reason = DEL_REASON_PEER_NOT_RESPONDING

23     14:15:00.426  02/09/09  Sev=Info/4      CM/0x63100014
Unable to establish Phase 1 SA with server "" because of "DEL_REASON_PEER_NOT_RESPONDING"

24     14:15:00.426  02/09/09  Sev=Info/5      CM/0x63100025
Initializing CVPNDrv

25     14:15:00.426  02/09/09  Sev=Info/4      CM/0x6310002D
Resetting TCP connection on port 10000

26     14:15:00.426  02/09/09  Sev=Info/6      CM/0x63100030
Removed local TCP port 2695 for TCP connection.

27     14:15:00.426  02/09/09  Sev=Info/6      CM/0x63100046
Set tunnel established flag in registry to 0.

28     14:15:00.426  02/09/09  Sev=Info/4      IKE/0x63000001
IKE received signal to terminate VPN connection

29     14:15:00.426  02/09/09  Sev=Info/6      IPSEC/0x63700023
TCP RST sent to, src port 2695, dst port 10000

30     14:15:00.426  02/09/09  Sev=Info/4      IPSEC/0x63700014
Deleted all keys

31     14:15:00.426  02/09/09  Sev=Info/4      IPSEC/0x63700014
Deleted all keys

32     14:15:00.426  02/09/09  Sev=Info/4      IPSEC/0x63700014
Deleted all keys

33     14:15:00.426  02/09/09  Sev=Info/4      IPSEC/0x6370000A
IPSec driver successfully stopped
Watch Question

What are you connecting to?  Can you post the configuration?

Not the solution you were looking for? Getting a personalized solution is easy.

Ask the Experts


This individual is passing through a firewall and natted into a network and then vpn across that network to a vpn concentrator located at another remote site. What type of concentrator I don't know but evidently it must work if an rdp unit can reach it. Individual can rdp to another unit and establish vpn session but is located on another network. Do not know if that unit is natted as well. Guess I should try and get the ip of concentrator and see if he can at least ping interface ie. if interface will respond to a ping.
Phase I not forming, could be preshared key not matching and NAT firewall/router as I see port 10000 tcp resets
so NAT-T (nat-traversal) could also be issue due to router/firewall

config please so we can troubleshoot

Access more of Experts Exchange with a free account
Thanks for using Experts Exchange.

Create a free account to continue.

Limited access with a free account allows you to:

  • View three pieces of content (articles, solutions, posts, and videos)
  • Ask the experts questions (counted toward content limit)
  • Customize your dashboard and profile

*This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.


Please enter a first name

Please enter a last name

8+ characters (letters, numbers, and a symbol)

By clicking, you agree to the Terms of Use and Privacy Policy.