Solved

secure VPN Connection terminated by peer reason 433 (reason not specified by Peer)

Posted on 2009-05-13
2
16,621 Views
Last Modified: 2012-05-06
We have an ASA 5510 with IOA 8.0(2), were using XP systems with VPN client ver. 5.0.2.0090
We have been getting an intermittent error "secure VPN Connection terminated by peer reason 433 (reason not specified by Peer)"
If the users keep trying they are eventually able to connect, (sometimes after 1-3 attempts, sometimes not for 8+hrs)

We have users at various field sites using Comcast cable, Qwest DSL, Verizon 3G, and various other ISP's. We have tried going through wireless and directly connected to broadband modems. It doesn't seem to be vendor, WLAN, WWAN, or router platform specific
I set the one of the VPN clients for logging and tried connecting and received the following log, at the same time the ASA SYSLOG showed the results listed in the ASA-Log.

the log client logs are as follows

Cisco Systems VPN Client Version 5.0.02.0090
Copyright (C) 1998-2007 Cisco Systems, Inc. All Rights Reserved.
Client Type(s): Windows, WinNT
Running on: 5.1.2600 Service Pack 3

17     11:49:57.480  04/29/09  Sev=Info/4 IPSEC/0x63700008
IPSec driver successfully started

18     11:49:57.480  04/29/09  Sev=Info/4 IPSEC/0x63700014
Deleted all keys

19     11:49:58.480  04/29/09  Sev=Info/4 IKE/0x63000013
SENDING >>> ISAKMP OAK AG (SA, KE, NON, ID, VID(Xauth), VID(dpd), VID(Frag), VID(Unity)) to 204.131.84.3

20     11:49:58.559  04/29/09  Sev=Info/4 IKE/0x63000014
RECEIVING <<< ISAKMP OAK AG (SA, KE, NON, ID, HASH, VID(Unity), VID(Xauth), VID(dpd), VID(Frag), VID(?)) from 204.131.84.3

21     11:49:58.559  04/29/09  Sev=Info/4 IKE/0x63000013
SENDING >>> ISAKMP OAK AG *(HASH, NOTIFY:STATUS_INITIAL_CONTACT, VID(?), VID(Unity)) to 204.131.84.3

22     11:49:58.559  04/29/09  Sev=Info/4 IKE/0x63000083
IKE Port in use - Local Port =  0x0715, Remote Port = 0x01F4

23     11:49:58.637  04/29/09  Sev=Info/4 IKE/0x63000014
RECEIVING <<< ISAKMP OAK TRANS *(HASH, ATTR) from 204.131.84.3

24     11:50:04.449  04/29/09  Sev=Info/4 IKE/0x63000013
SENDING >>> ISAKMP OAK TRANS *(HASH, ATTR) to 204.131.84.3

25     11:50:04.543  04/29/09  Sev=Info/4 IKE/0x63000014
RECEIVING <<< ISAKMP OAK TRANS *(HASH, ATTR) from 204.131.84.3

26     11:50:04.543  04/29/09  Sev=Info/4 IKE/0x63000013
SENDING >>> ISAKMP OAK TRANS *(HASH, ATTR) to 204.131.84.3

27     11:50:04.559  04/29/09  Sev=Info/4 IKE/0x63000013
SENDING >>> ISAKMP OAK TRANS *(HASH, ATTR) to 204.131.84.3

28     11:50:04.637  04/29/09  Sev=Info/4 IKE/0x63000014
RECEIVING <<< ISAKMP OAK INFO *(HASH, DEL) from 204.131.84.3

29     11:50:04.637  04/29/09  Sev=Info/4 IKE/0x63000017
Marking IKE SA for deletion  (I_Cookie=0DC42AEA44EC6C1C R_Cookie=8ADA701705B148FA) reason = PEER_DELETE-IKE_DELETE_UNSPECIFIED

30     11:50:05.480  04/29/09  Sev=Info/4 IKE/0x6300004B
Discarding IKE SA negotiation (I_Cookie=0DC42AEA44EC6C1C R_Cookie=8ADA701705B148FA) reason = PEER_DELETE-IKE_DELETE_UNSPECIFIED

31     11:50:05.512  04/29/09  Sev=Info/4 IKE/0x63000001
IKE received signal to terminate VPN connection

32     11:50:05.512  04/29/09  Sev=Info/4 IPSEC/0x63700014
Deleted all keys

 33     11:50:05.512  04/29/09  Sev=Info/4 IPSEC/0x63700014
Deleted all keys

34     11:50:05.512  04/29/09  Sev=Info/4 IPSEC/0x63700014
Deleted all keys

35     11:50:05.512  04/29/09  Sev=Info/4 IPSEC/0x6370000A
IPSec driver successfully stopped

I've seen numerous posts concerning this error message and resolving it by setting NAT-T but if I'm not mistaken that is if you're using IPSec over UDP and we're using IPSec over TCP (port 10000) I still tried setting ADSM to NAT-T and tried several different timeouts (20sec, 30 sec, 60 sec, 120 sec) we want to keep IPSec over TCP because of TCP being more robust.

ASA-log.JPG
error-433.bmp
NAT-T.bmp
0
Comment
Question by:ghmangus
2 Comments
 
LVL 77

Accepted Solution

by:
arnold earned 500 total points
ID: 24381502
The default timeout is likely 30 minutes.  Setting it to such a short duration could explain the issue.
The article below has an explanation on why/when the PEER_DELETE-IKE_DELETE_UNSPECIFIED notice is issued to the VPN client from the VPN server/router.

http://www.cisco.com/en/US/products/ps6120/products_tech_note09186a00807e0aca.shtml
0

Featured Post

Comprehensive Backup Solutions for Microsoft

Acronis protects the complete Microsoft technology stack: Windows Server, Windows PC, laptop and Surface data; Microsoft business applications; Microsoft Hyper-V; Azure VMs; Microsoft Windows Server 2016; Microsoft Exchange 2016 and SQL Server 2016.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Adoption of Microsoft’s Enterprise Mobility and Security solution and Office 365 will re-order the File Sync and Share market Microsoft has stated that its Enterprise Mobility + Security (EMS) is the fastest growing product in the history of the …
The 21st century solution to antiquated pagers.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Windows 10 is mostly good. However the one thing that annoys me is how many clicks you have to do to dial a VPN connection. You have to go to settings from the start menu, (2 clicks), Network and Internet (1 click), Click VPN (another click) then fi…

816 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

9 Experts available now in Live!

Get 1:1 Help Now