ASA S2S Tunnel Error

Posted on 2010-03-28
Medium Priority
Last Modified: 2012-08-13
We are replacing a Linksys RV042 VPN endpoint with an ASA 5505 Security Plus appliance.

Having problems establishing one of our site-to-site VPN tunnels (unfortunately I do not know what the other device is, and all I can do for now is replicate the settings that were present for this tunnel on the ASA).

This is what I'm receiving:

      AAA retrieved default group policy (M-Tunnel) for user = Endpoint_IP
      Group = Endpoint_IP, IP = Endpoint_IP, PHASE 1 COMPLETED
      Group = Endpoint_IP, IP = Endpoint_IP, All IPSec SA proposals found unacceptable!
      Group = Endpoint_IP, IP = Endpoint_IP, QM FSM error (P2 struct &0xd5144720, mess id 0xf4ae87c3)!
      Group = Endpoint_IP, IP = Endpoint_IP, Removing peer from correlator table failed, no match!
      Group = Endpoint_IP, Username = Endpoint_IP, IP = Endpoint_IP, Session disconnected. Session Type: IKE, Duration: 0h:00m:00s, Bytes xmt: 0, Bytes rcv: 0, Reason: Phase 2 Mismatch
      Group = Endpoint_IP, IP = Endpoint_IP, Automatic NAT Detection Status: Remote end is NOT behind a NAT device This end is NOT behind a NAT device

*Endpoint_IP = WAN IP of Remote Gateway

I'm almost thinking I'm connecting to some sort of PPTP device not capable of IPSEC or not configured for IPSEC (Windows server?).

Any ideas; I'll hopefully find out tomorrow what I'm connecting to, but I'd like to get this solved ASAP.
Question by:Tercestisi
  • 2

Author Comment

ID: 28860556
What is strange was that the tunnel was up for some time (after we replaced the RV042 with the ASA, we confirmed the tunnel was up); when I checked back a few hours later, I noticed these events continually appearing in the syslog, and the tunnel not showing as up.

Accepted Solution

Tercestisi earned 0 total points
ID: 28868590
It is a PPTP tunnel and an ASA cannot be a PPTP server.
LVL 23

Expert Comment

by:Erik Bjers
ID: 28913444
All IPSec SA proposals found unacceptable!

This is your problem. You need to find out what SA proposal the other device accepts and set them up on your Asa.


Featured Post

Get expert help—faster!

Need expert help—fast? Use the Help Bell for personalized assistance getting answers to your important questions.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

On Feb. 28, Amazon’s Simple Storage Service (S3) went down after an employee issued the wrong command during a debugging exercise. Among those affected were big names like Netflix, Spotify and Expedia.
This article is in regards to the Cisco QSFP-4SFP10G-CU1M cables, which are designed to uplink/downlink 40GB ports to 10GB SFP ports. I recently experienced this and found very little configuration documentation on how these are supposed to be confi…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Both in life and business – not all partnerships are created equal. As the demand for cloud services increases, so do the number of self-proclaimed cloud partners. Asking the right questions up front in the partnership, will enable both parties …

593 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question