Link to home
Start Free TrialLog in
Avatar of frukeus
frukeusFlag for Singapore

asked on

Cisco ASA Header Invalid (next payload = 11)

IP = 46.50.218.93, processing VID payload
IP = 46.50.218.93, Received DPD VID
IP = 46.50.218.93, Received NAT-Traversal RFC VID
IP = 46.50.218.93, Received NAT-Traversal ver 03 VID
IP = 46.50.218.93, Received NAT-Traversal ver 02 VID
IP = 46.50.218.93, processing VID payload
IP = 46.50.218.93, IKE SA Proposal # 1, Transform # 11 acceptable  Matches global IKE entry # 3
IP = 46.50.218.93, constructing NAT-Traversal VID ver 02 payload
IP = 46.50.218.93, IKE_DECODE SENDING Message (msgid=0) with payloads : HDR + SA (1) + VENDOR (13) + VENDOR (13) + NONE (0) total length : 128
IP = 46.50.218.93, IKE_DECODE RESENDING Message (msgid=0) with payloads : HDR + SA (1) + VENDOR (13) + VENDOR (13) + NONE (0) total length : 128
IP = 46.50.218.93, IKE_DECODE RESENDING Message (msgid=0) with payloads : HDR + SA (1) + VENDOR (13) + VENDOR (13) + NONE (0) total length : 128
IP = 46.50.218.93, IKE_DECODE RESENDING Message (msgid=0) with payloads : HDR + SA (1) + VENDOR (13) + VENDOR (13) + NONE (0) total length : 128
IP = 46.50.218.93, IKE MM Responder FSM error history (struct &0xdb289848)  <state>, <event>:  MM_DONE, EV_ERROR-->MM_WAIT_MSG3, EV_TIMEOUT-->MM_WAIT_MSG3, NullEvent-->MM_SND_MSG2, EV_SND_MSG-->MM_SND_MSG2, EV_START_TMR-->MM_SND_MSG2, EV_RESEND_MSG-->MM_WAIT_MSG3, EV_TIMEOUT-->MM_WAIT_MSG3, NullEvent
IP = 46.50.218.93, sending delete/delete with reason message
IP = 46.50.218.93, IKE SA MM:8b824f2c terminating:  flags 0x01000002, refcnt 0, tuncnt 0
IP = 46.50.218.93, Header invalid (next payload = 11)

Open in new window


I keep getting Header invalid (next payload =11) error when I connect my openswan server to ASA. I have checked my preshared key many times and it is accurate.
What else can I do?
ASKER CERTIFIED SOLUTION
Avatar of MartinDRZ
MartinDRZ

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
SOLUTION
Avatar of Ernie Beek
Ernie Beek
Flag of Netherlands image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of frukeus

ASKER

I did a sudo ipsec barf and realised that my secret file is malformed.
It requires PSK "password", quotes was missing from it.
Glad to see you got it working :)

Thx 4 the points.
Avatar of Colossus1
Colossus1

Was the issue on the "openswan" server or the ASA?