Solved

VPN error

Posted on 2014-04-25
9
644 Views
Last Modified: 2014-05-13
I have 2 sites with site-to-site VPN. I have a primary and a secondary tunnel. When I did the debug isakmp error command on site A, I got the error below:
ISAKMP:(0):deleting SA reason "Death by retransmission P1" state (I) MM_NO_STATE (peer 206.22.10.12).

106.22.10.12 is the secondary vpn connection. It is just a backup implemented with a floating static route.
How do I get rid of this error? Thanks
0
Comment
Question by:leblanc
  • 4
  • 3
  • 2
9 Comments
 
LVL 61

Assisted Solution

by:btan
btan earned 250 total points
ID: 40025191
If from the show crypto isakmp sa it shows the ISAKMP SA in MM_NO_STATE that would means that main mode has failed. It is also flagged in the erro msg shared. Pse verify that the phase 1 policy is on both peers, and ensure that all the attributes match.

The device that is performing NAT needs to forward the UDP 500, UDP 4500 and Protocol 50 (ESP), also to add on both devices the global configuration command "crypto ipsec nat-transparency spi-matching".

Also to suggest you double check any devices "in front" of the VPN devices to makes sure all access is un-restricted for VPN's.

Ref: IPsec Troubleshooting: Understanding and Using debug Commands
0
 
LVL 28

Accepted Solution

by:
asavener earned 250 total points
ID: 40027340
If you're using Cisco routers, try adding crypto isakmp invalid-spi-recovery at both ends.

There's a corresponding command for the ASA platform; I'll dig it up if you need it.
0
 
LVL 1

Author Comment

by:leblanc
ID: 40027454
I only have Cisco routers. What does crypto isakmp invalid-spi-recovery do? Will it be a downtime if I add the command on both side?
0
 
LVL 28

Expert Comment

by:asavener
ID: 40027496
It does not require any interruption of service.

Basically, it allows the routers to recover if the other end becomes unavailable for a time, or reboots.

The problem you're seeing may be due to one end dropping the VPN (or rebooting), and the other end thinking the VPN is still active.


Once you've entered the command, you may want to find a time when you can bounce the VPNs.  Run "clear crypto ipsec sa" which will force the VPNs to rebuild from scratch.  Typically this causes no down time, as the VPN rebuild process should take less than a second.
0
Better Security Awareness With Threat Intelligence

See how one of the leading financial services organizations uses Recorded Future as part of a holistic threat intelligence program to promote security awareness and proactively and efficiently identify threats.

 
LVL 1

Author Comment

by:leblanc
ID: 40027655
I have two tunnels going between 2 sites. One is the primary and the other one is secondary with a floating static route. So when the primary link is up and running, the route for the secondary link is not in the routing table of the router. I think that is why I see this error. So the crypto isakmp invalid-spi-recovery will not get rid of the error, does it? Thanks
0
 
LVL 61

Expert Comment

by:btan
ID: 40028586
The recovery is pertaining to SA getting out of sync, strictly speaking it may recover but root cause is still not established. However, your error doesnt seems to lead to out of sync as sample below. You can see cisco on this command here

Sep  2 13:27:57.707: %CRYPTO-4-RECVD_PKT_INV_SPI: decaps: rec'd IPSEC packet
   has invalid spi for destaddr=20.1.1.2, prot=50, spi=0xB761863E(3076621886),
   srcaddr=10.1.1.1
0
 
LVL 1

Author Comment

by:leblanc
ID: 40028669
Yes I don't have that command. Below is my error from debug crypto isakmp error command:
ISAKMP:(0):deleting SA reason "Death by retransmission P1" state (I) MM_NO_STATE (peer 206.22.10.12)
0
 
LVL 61

Expert Comment

by:btan
ID: 40028684
was the first posting possible to help you?
0
 
LVL 1

Author Comment

by:leblanc
ID: 40028696
I did not add any commands in my existing config as everything is currently working fine. I am just curious on those warnings. I said warning because when I did the debug crypto isakmp command error, it did not show that warning as an error. Thanks
0

Featured Post

Enabling OSINT in Activity Based Intelligence

Activity based intelligence (ABI) requires access to all available sources of data. Recorded Future allows analysts to observe structured data on the open, deep, and dark web.

Join & Write a Comment

Ransomware continues to be a growing problem for both personal and business users alike and Antivirus companies are still struggling to find a reliable way to protect you from this dangerous threat.
PRTG Network Monitor lets you monitor your bandwidth usage, so you know who is using up your bandwidth, and what they're using it for.
Here's a very brief overview of the methods PRTG Network Monitor (https://www.paessler.com/prtg) offers for monitoring bandwidth, to help you decide which methods you´d like to investigate in more detail.  The methods are covered in more detail in o…
In this tutorial you'll learn about bandwidth monitoring with flows and packet sniffing with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're interested in additional methods for monitoring bandwidt…

705 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

20 Experts available now in Live!

Get 1:1 Help Now