Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people, just like you, are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
Solved

Cisco ASA 5510 Problem to sonicwal pro1260

Posted on 2009-04-06
5
1,298 Views
Last Modified: 2012-05-06
Hello experts, hope you can help
I have a cisco asa5510 with multiple lan to lan vpn's configured (terminating on a mixture of cisco 837, 877 and pix 501)

I also have a single lan to lan vpn terminating on a sonicwall pro 1260, this vpn does not come up, it fails phase 1,
looking at the logs from the sonicwall i seem to be getting errors "invalid cookie",

Now I have spent the 2 days trying to resolve this issue, I have looked on the web a few people seem to have the same issues, i have chacked my isakmp and ipsec (protected traffic) etc and all looks fine, it is worth mentioning we had a pix 515 before the asa and the sonicwall vpn terminated fine with that then, just no good with asa,

Already logged a call with sonicwall but they can not help, they said it should be working

someone has mentioned a way of disabling aggresive mode on the asa as this might be a problem (even though my tunnel is configured for main mode).... ?

I can provide error logs /configs but not until tomorrow morning,

Thanks guys
Andy

0
Comment
Question by:webleyaxsor
  • 4
5 Comments
 
LVL 33

Accepted Solution

by:
MikeKane earned 500 total points
ID: 24088247
If you use 86400 as the lifetime, try reducing it to 28800 on both devices, use SHA1 instead of MD5.   If the error still happens, then try dropping to DES instead of 3DES.    

I saw another post that recommended Deleting and recreating the SA on the sonicwall as a possible fix as well.  
0
 

Author Comment

by:webleyaxsor
ID: 24091915
Hi, the lifetime is already set to 28800 for phase 1 and 2 , i have tried 3des and des for phase 1, also changed the authentication md5 to sha1 on both phases and rebuilt the the sa on the sonicwall, I have a sonicwall "expert" looking at it tomorrow, I will keep you updated, i am beginning to suspect a compatability issue between the 2 devices, oh for standards
andy ..
0
 

Author Comment

by:webleyaxsor
ID: 24443424
thank you all sorted, liftime error
0
 

Author Comment

by:webleyaxsor
ID: 24443432
all sorted thankyou
0
 

Author Closing Comment

by:webleyaxsor
ID: 31567271
thankyou very much, sorry for late reply for the points,
0

Featured Post

Portable, direct connect server access

The ATEN CV211 connects a laptop directly to any server allowing you instant access to perform data maintenance and local operations, for quick troubleshooting, updating, service and repair.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

This article will step through configuring a SonicWALL appliance to utilize an internal DHCP server for Global VPN Client (GVC) hosts.  There are times when using an external (external to the SonicWALL) DHCP server, such as Windows Servers, isn’t pr…
This article is a how to to configure a UCS Ethernet-uplink portchannel via the console. It is easy to do and can be done quite quickly. In certain versions of the UCS manager the portchannel has issues coming up and this is a workaround. I am…
Nobody understands Phishing better than an anti-spam company. That’s why we are providing Phishing Awareness Training to our customers. According to a report by Verizon, only 3% of targeted users report malicious emails to management. With compan…
With Secure Portal Encryption, the recipient is sent a link to their email address directing them to the email laundry delivery page. From there, the recipient will be required to enter a user name and password to enter the page. Once the recipient …

789 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question