Solved

VPN error

Posted on 2014-04-25
9
647 Views
Last Modified: 2014-05-13
I have 2 sites with site-to-site VPN. I have a primary and a secondary tunnel. When I did the debug isakmp error command on site A, I got the error below:
ISAKMP:(0):deleting SA reason "Death by retransmission P1" state (I) MM_NO_STATE (peer 206.22.10.12).

106.22.10.12 is the secondary vpn connection. It is just a backup implemented with a floating static route.
How do I get rid of this error? Thanks
0
Comment
Question by:leblanc
  • 4
  • 3
  • 2
9 Comments
 
LVL 62

Assisted Solution

by:btan
btan earned 250 total points
ID: 40025191
If from the show crypto isakmp sa it shows the ISAKMP SA in MM_NO_STATE that would means that main mode has failed. It is also flagged in the erro msg shared. Pse verify that the phase 1 policy is on both peers, and ensure that all the attributes match.

The device that is performing NAT needs to forward the UDP 500, UDP 4500 and Protocol 50 (ESP), also to add on both devices the global configuration command "crypto ipsec nat-transparency spi-matching".

Also to suggest you double check any devices "in front" of the VPN devices to makes sure all access is un-restricted for VPN's.

Ref: IPsec Troubleshooting: Understanding and Using debug Commands
0
 
LVL 28

Accepted Solution

by:
asavener earned 250 total points
ID: 40027340
If you're using Cisco routers, try adding crypto isakmp invalid-spi-recovery at both ends.

There's a corresponding command for the ASA platform; I'll dig it up if you need it.
0
 
LVL 1

Author Comment

by:leblanc
ID: 40027454
I only have Cisco routers. What does crypto isakmp invalid-spi-recovery do? Will it be a downtime if I add the command on both side?
0
 
LVL 28

Expert Comment

by:asavener
ID: 40027496
It does not require any interruption of service.

Basically, it allows the routers to recover if the other end becomes unavailable for a time, or reboots.

The problem you're seeing may be due to one end dropping the VPN (or rebooting), and the other end thinking the VPN is still active.


Once you've entered the command, you may want to find a time when you can bounce the VPNs.  Run "clear crypto ipsec sa" which will force the VPNs to rebuild from scratch.  Typically this causes no down time, as the VPN rebuild process should take less than a second.
0
Control application downtime with dependency maps

Visualize the interdependencies between application components better with Applications Manager's automated application discovery and dependency mapping feature. Resolve performance issues faster by quickly isolating problematic components.

 
LVL 1

Author Comment

by:leblanc
ID: 40027655
I have two tunnels going between 2 sites. One is the primary and the other one is secondary with a floating static route. So when the primary link is up and running, the route for the secondary link is not in the routing table of the router. I think that is why I see this error. So the crypto isakmp invalid-spi-recovery will not get rid of the error, does it? Thanks
0
 
LVL 62

Expert Comment

by:btan
ID: 40028586
The recovery is pertaining to SA getting out of sync, strictly speaking it may recover but root cause is still not established. However, your error doesnt seems to lead to out of sync as sample below. You can see cisco on this command here

Sep  2 13:27:57.707: %CRYPTO-4-RECVD_PKT_INV_SPI: decaps: rec'd IPSEC packet
   has invalid spi for destaddr=20.1.1.2, prot=50, spi=0xB761863E(3076621886),
   srcaddr=10.1.1.1
0
 
LVL 1

Author Comment

by:leblanc
ID: 40028669
Yes I don't have that command. Below is my error from debug crypto isakmp error command:
ISAKMP:(0):deleting SA reason "Death by retransmission P1" state (I) MM_NO_STATE (peer 206.22.10.12)
0
 
LVL 62

Expert Comment

by:btan
ID: 40028684
was the first posting possible to help you?
0
 
LVL 1

Author Comment

by:leblanc
ID: 40028696
I did not add any commands in my existing config as everything is currently working fine. I am just curious on those warnings. I said warning because when I did the debug crypto isakmp command error, it did not show that warning as an error. Thanks
0

Featured Post

Ransomware-A Revenue Bonanza for Service Providers

Ransomware – malware that gets on your customers’ computers, encrypts their data, and extorts a hefty ransom for the decryption keys – is a surging new threat.  The purpose of this eBook is to educate the reader about ransomware attacks.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Big data transfers via information superhighways require special attention and protection. Learn more about the IT-regulations of the country where your server is located. Analyze cloud providers and their encryption systems for safe data transit. S…
Three simple tips to quickly and efficiently back up and protect the contents of your PC and Mac®.
Sending a Secure fax is easy with eFax Corporate (http://www.enterprise.efax.com). First, just open a new email message. In the To field, type your recipient's fax number @efaxsend.com. You can even send a secure international fax — just include t…
Here's a very brief overview of the methods PRTG Network Monitor (https://www.paessler.com/prtg) offers for monitoring bandwidth, to help you decide which methods you´d like to investigate in more detail.  The methods are covered in more detail in o…

920 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

15 Experts available now in Live!

Get 1:1 Help Now