Solved

Cisco ASA 5510 Problem to sonicwal pro1260

Posted on 2009-04-06
5
1,293 Views
Last Modified: 2012-05-06
Hello experts, hope you can help
I have a cisco asa5510 with multiple lan to lan vpn's configured (terminating on a mixture of cisco 837, 877 and pix 501)

I also have a single lan to lan vpn terminating on a sonicwall pro 1260, this vpn does not come up, it fails phase 1,
looking at the logs from the sonicwall i seem to be getting errors "invalid cookie",

Now I have spent the 2 days trying to resolve this issue, I have looked on the web a few people seem to have the same issues, i have chacked my isakmp and ipsec (protected traffic) etc and all looks fine, it is worth mentioning we had a pix 515 before the asa and the sonicwall vpn terminated fine with that then, just no good with asa,

Already logged a call with sonicwall but they can not help, they said it should be working

someone has mentioned a way of disabling aggresive mode on the asa as this might be a problem (even though my tunnel is configured for main mode).... ?

I can provide error logs /configs but not until tomorrow morning,

Thanks guys
Andy

0
Comment
Question by:webleyaxsor
  • 4
5 Comments
 
LVL 33

Accepted Solution

by:
MikeKane earned 500 total points
ID: 24088247
If you use 86400 as the lifetime, try reducing it to 28800 on both devices, use SHA1 instead of MD5.   If the error still happens, then try dropping to DES instead of 3DES.    

I saw another post that recommended Deleting and recreating the SA on the sonicwall as a possible fix as well.  
0
 

Author Comment

by:webleyaxsor
ID: 24091915
Hi, the lifetime is already set to 28800 for phase 1 and 2 , i have tried 3des and des for phase 1, also changed the authentication md5 to sha1 on both phases and rebuilt the the sa on the sonicwall, I have a sonicwall "expert" looking at it tomorrow, I will keep you updated, i am beginning to suspect a compatability issue between the 2 devices, oh for standards
andy ..
0
 

Author Comment

by:webleyaxsor
ID: 24443424
thank you all sorted, liftime error
0
 

Author Comment

by:webleyaxsor
ID: 24443432
all sorted thankyou
0
 

Author Closing Comment

by:webleyaxsor
ID: 31567271
thankyou very much, sorry for late reply for the points,
0

Featured Post

Netscaler Common Configuration How To guides

If you use NetScaler you will want to see these guides. The NetScaler How To Guides show administrators how to get NetScaler up and configured by providing instructions for common scenarios and some not so common ones.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Optimal Xbox 360 connectivity requires "OPEN NAT". If you use Juniper Netscreen or SSG firewall products in a home setting, the following steps will allow you get rid of the dreaded warning screen below and achieve the best online gaming environment…
Imagine you have a shopping list of items you need to get at the grocery store. You have two options: A. Take one trip to the grocery store and get everything you need for the week, or B. Take multiple trips, buying an item at a time, to achieve t…
Microsoft Active Directory, the widely used IT infrastructure, is known for its high risk of credential theft. The best way to test your Active Directory’s vulnerabilities to pass-the-ticket, pass-the-hash, privilege escalation, and malware attacks …
Established in 1997, Technology Architects has become one of the most reputable technology solutions companies in the country. TA have been providing businesses with cost effective state-of-the-art solutions and unparalleled service that is designed…

777 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question