Solved

Cisco ASA 5510 Problem to sonicwal pro1260

Posted on 2009-04-06
5
1,283 Views
Last Modified: 2012-05-06
Hello experts, hope you can help
I have a cisco asa5510 with multiple lan to lan vpn's configured (terminating on a mixture of cisco 837, 877 and pix 501)

I also have a single lan to lan vpn terminating on a sonicwall pro 1260, this vpn does not come up, it fails phase 1,
looking at the logs from the sonicwall i seem to be getting errors "invalid cookie",

Now I have spent the 2 days trying to resolve this issue, I have looked on the web a few people seem to have the same issues, i have chacked my isakmp and ipsec (protected traffic) etc and all looks fine, it is worth mentioning we had a pix 515 before the asa and the sonicwall vpn terminated fine with that then, just no good with asa,

Already logged a call with sonicwall but they can not help, they said it should be working

someone has mentioned a way of disabling aggresive mode on the asa as this might be a problem (even though my tunnel is configured for main mode).... ?

I can provide error logs /configs but not until tomorrow morning,

Thanks guys
Andy

0
Comment
Question by:webleyaxsor
  • 4
5 Comments
 
LVL 33

Accepted Solution

by:
MikeKane earned 500 total points
Comment Utility
If you use 86400 as the lifetime, try reducing it to 28800 on both devices, use SHA1 instead of MD5.   If the error still happens, then try dropping to DES instead of 3DES.    

I saw another post that recommended Deleting and recreating the SA on the sonicwall as a possible fix as well.  
0
 

Author Comment

by:webleyaxsor
Comment Utility
Hi, the lifetime is already set to 28800 for phase 1 and 2 , i have tried 3des and des for phase 1, also changed the authentication md5 to sha1 on both phases and rebuilt the the sa on the sonicwall, I have a sonicwall "expert" looking at it tomorrow, I will keep you updated, i am beginning to suspect a compatability issue between the 2 devices, oh for standards
andy ..
0
 

Author Comment

by:webleyaxsor
Comment Utility
thank you all sorted, liftime error
0
 

Author Comment

by:webleyaxsor
Comment Utility
all sorted thankyou
0
 

Author Closing Comment

by:webleyaxsor
Comment Utility
thankyou very much, sorry for late reply for the points,
0

Featured Post

What Security Threats Are You Missing?

Enhance your security with threat intelligence from the web. Get trending threat insights on hackers, exploits, and suspicious IP addresses delivered to your inbox with our free Cyber Daily.

Join & Write a Comment

Do you have a computer or other electronic gear that is attached to a rat nest of cables, or alternatively have your cables all bundled nice at neat?  If so then read this post to sidstep common pitfalls. When I was a student at DeVry University,…
Hello All, I have been training on Multicast for a while now and whenever I start the topic , I find out that my friends /  Colleagues mention that they do not know how to test Multicast Joins. As most of the multicast would be video traffic and …
Sending a Secure fax is easy with eFax Corporate (http://www.enterprise.efax.com). First, Just open a new email message.  In the To field, type your recipient's fax number @efaxsend.com. You can even send a secure international fax — just include t…
This tutorial demonstrates a quick way of adding group price to multiple Magento products.

762 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

8 Experts available now in Live!

Get 1:1 Help Now