Want to win a PS4? Go Premium and enter to win our High-Tech Treats giveaway. Enter to Win

x
?
Solved

secure VPN Connection terminated by peer reason 433 (reason not specified by Peer)

Posted on 2009-05-13
2
Medium Priority
?
16,906 Views
Last Modified: 2012-05-06
We have an ASA 5510 with IOA 8.0(2), were using XP systems with VPN client ver. 5.0.2.0090
We have been getting an intermittent error "secure VPN Connection terminated by peer reason 433 (reason not specified by Peer)"
If the users keep trying they are eventually able to connect, (sometimes after 1-3 attempts, sometimes not for 8+hrs)

We have users at various field sites using Comcast cable, Qwest DSL, Verizon 3G, and various other ISP's. We have tried going through wireless and directly connected to broadband modems. It doesn't seem to be vendor, WLAN, WWAN, or router platform specific
I set the one of the VPN clients for logging and tried connecting and received the following log, at the same time the ASA SYSLOG showed the results listed in the ASA-Log.

the log client logs are as follows

Cisco Systems VPN Client Version 5.0.02.0090
Copyright (C) 1998-2007 Cisco Systems, Inc. All Rights Reserved.
Client Type(s): Windows, WinNT
Running on: 5.1.2600 Service Pack 3

17     11:49:57.480  04/29/09  Sev=Info/4 IPSEC/0x63700008
IPSec driver successfully started

18     11:49:57.480  04/29/09  Sev=Info/4 IPSEC/0x63700014
Deleted all keys

19     11:49:58.480  04/29/09  Sev=Info/4 IKE/0x63000013
SENDING >>> ISAKMP OAK AG (SA, KE, NON, ID, VID(Xauth), VID(dpd), VID(Frag), VID(Unity)) to 204.131.84.3

20     11:49:58.559  04/29/09  Sev=Info/4 IKE/0x63000014
RECEIVING <<< ISAKMP OAK AG (SA, KE, NON, ID, HASH, VID(Unity), VID(Xauth), VID(dpd), VID(Frag), VID(?)) from 204.131.84.3

21     11:49:58.559  04/29/09  Sev=Info/4 IKE/0x63000013
SENDING >>> ISAKMP OAK AG *(HASH, NOTIFY:STATUS_INITIAL_CONTACT, VID(?), VID(Unity)) to 204.131.84.3

22     11:49:58.559  04/29/09  Sev=Info/4 IKE/0x63000083
IKE Port in use - Local Port =  0x0715, Remote Port = 0x01F4

23     11:49:58.637  04/29/09  Sev=Info/4 IKE/0x63000014
RECEIVING <<< ISAKMP OAK TRANS *(HASH, ATTR) from 204.131.84.3

24     11:50:04.449  04/29/09  Sev=Info/4 IKE/0x63000013
SENDING >>> ISAKMP OAK TRANS *(HASH, ATTR) to 204.131.84.3

25     11:50:04.543  04/29/09  Sev=Info/4 IKE/0x63000014
RECEIVING <<< ISAKMP OAK TRANS *(HASH, ATTR) from 204.131.84.3

26     11:50:04.543  04/29/09  Sev=Info/4 IKE/0x63000013
SENDING >>> ISAKMP OAK TRANS *(HASH, ATTR) to 204.131.84.3

27     11:50:04.559  04/29/09  Sev=Info/4 IKE/0x63000013
SENDING >>> ISAKMP OAK TRANS *(HASH, ATTR) to 204.131.84.3

28     11:50:04.637  04/29/09  Sev=Info/4 IKE/0x63000014
RECEIVING <<< ISAKMP OAK INFO *(HASH, DEL) from 204.131.84.3

29     11:50:04.637  04/29/09  Sev=Info/4 IKE/0x63000017
Marking IKE SA for deletion  (I_Cookie=0DC42AEA44EC6C1C R_Cookie=8ADA701705B148FA) reason = PEER_DELETE-IKE_DELETE_UNSPECIFIED

30     11:50:05.480  04/29/09  Sev=Info/4 IKE/0x6300004B
Discarding IKE SA negotiation (I_Cookie=0DC42AEA44EC6C1C R_Cookie=8ADA701705B148FA) reason = PEER_DELETE-IKE_DELETE_UNSPECIFIED

31     11:50:05.512  04/29/09  Sev=Info/4 IKE/0x63000001
IKE received signal to terminate VPN connection

32     11:50:05.512  04/29/09  Sev=Info/4 IPSEC/0x63700014
Deleted all keys

 33     11:50:05.512  04/29/09  Sev=Info/4 IPSEC/0x63700014
Deleted all keys

34     11:50:05.512  04/29/09  Sev=Info/4 IPSEC/0x63700014
Deleted all keys

35     11:50:05.512  04/29/09  Sev=Info/4 IPSEC/0x6370000A
IPSec driver successfully stopped

I've seen numerous posts concerning this error message and resolving it by setting NAT-T but if I'm not mistaken that is if you're using IPSec over UDP and we're using IPSec over TCP (port 10000) I still tried setting ADSM to NAT-T and tried several different timeouts (20sec, 30 sec, 60 sec, 120 sec) we want to keep IPSec over TCP because of TCP being more robust.

ASA-log.JPG
error-433.bmp
NAT-T.bmp
0
Comment
Question by:ghmangus
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
2 Comments
 
LVL 80

Accepted Solution

by:
arnold earned 2000 total points
ID: 24381502
The default timeout is likely 30 minutes.  Setting it to such a short duration could explain the issue.
The article below has an explanation on why/when the PEER_DELETE-IKE_DELETE_UNSPECIFIED notice is issued to the VPN client from the VPN server/router.

http://www.cisco.com/en/US/products/ps6120/products_tech_note09186a00807e0aca.shtml
0

Featured Post

Cyber Threats to Small Businesses (Part 1)

This past May, Webroot surveyed more than 600 IT decision-makers at medium-sized companies to see how these small businesses perceived new threats facing their organizations.  Read what Webroot CISO, Gary Hayslip, has to say about the survey in part 1 of this 2-part blog series.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Ransomware, the malware that locks down its victim’s files until they pay up, has always been a frustrating issue to deal with. However, a recent mobile ransomware will make the issue a little more personal… by sharing the victim’s mobile browsing h…
Tech spooks aren't just for those who are tech savvy, it also happens to those of us running a business. Check out the top tech spooks for business owners.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
In a question here at Experts Exchange (https://www.experts-exchange.com/questions/29062564/Adobe-acrobat-reader-DC.html), a member asked how to create a signature in Adobe Acrobat Reader DC (the free Reader product, not the paid, full Acrobat produ…

610 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question