We help IT Professionals succeed at work.
Get Started

ASA 5545-X  and ASA 5520 FW VPN tunnel issue

1,331 Views
Last Modified: 2016-02-21
Before upgrading ASA 5520 from 8.4.6 to version 9.1(7), VPN tunnel between both FW was working fine.
Now I am having few loggs on ASA 5520 about Ipsec.

on ASA 5545-X FW,
Command : show isakmp sa
36  IKE Peer: XXX-EXT
    Type    : user            Role    : initiator
    Rekey   : no              State   : MM_WAIT_MSG2

Loggs from ASA 5520:

Feb 21 2016 04:06:01: %ASA-7-713906: IKE Receiver: Packet received on XX.XX.XX.8:500 from XX.XX.XX.8:500
Feb 21 2016 04:06:01: %ASA-7-713236: IP = XX.XX.XX.8, IKE_DECODE RECEIVED Message (msgid=0) with payloads : HDR + SA (1) + VENDOR (13) + VENDOR (13) + VENDOR (13) + VENDOR (13) + NONE (0) total length : 244
Feb 21 2016 04:06:01: %ASA-7-715047: IP = XX.XX.XX.8, processing SA payload
Feb 21 2016 04:06:01: %ASA-7-713906: IKE Proposals rejected, no responder proposals configured!
Feb 21 2016 04:06:01: %ASA-7-713906: IKE Proposals rejected, no responder proposals configured!
Feb 21 2016 04:06:01: %ASA-7-713906: IKE Proposals rejected, no responder proposals configured!
Feb 21 2016 04:06:01: %ASA-7-713236: IP = XX.XX.XX.8, IKE_DECODE SENDING Message (msgid=0) with payloads : HDR + NOTIFY (11) + NONE (0) total length : 172
Feb 21 2016 04:06:01: %ASA-7-713906: IP = XX.XX.XX.8, All SA proposals found unacceptable
Feb 21 2016 04:06:01: %ASA-3-713048: IP = XX.XX.XX.8, Error processing payload: Payload ID: 1
Feb 21 2016 04:06:01: %ASA-7-715065: IP = XX.XX.XX.8, IKE MM Responder FSM error history (struct &0x760828c8)  <state>, <event>:  MM_DONE, EV_ERROR-->MM_START, EV_RCV_MSG-->MM_START, EV_START_MM-->MM_START, EV_START_MM-->MM_START, EV_START_MM-->MM_START, EV_START_MM-->MM_START, EV_START_MM-->MM_START, EV_START_MM
Feb 21 2016 04:06:01: %ASA-7-713906: IP = XX.XX.XX.8, IKE SA MM:b8ca90dc terminating:  flags 0x01000002, refcnt 0, tuncnt 0
Feb 21 2016 04:06:01: %ASA-7-713906: IP = XX.XX.XX.8, sending delete/delete with reason message
Feb 21 2016 04:06:04: %ASA-5-752004: Tunnel Manager dispatching a KEY_ACQUIRE message to IKEv1.  Map Tag = outside_map.  Map Sequence Number = 10.
Feb 21 2016 04:06:04: %ASA-7-715077: Pitcher: received a key acquire message, spi 0x0
Feb 21 2016 04:06:04: %ASA-6-713905: There is no valid IKE proposal available, check IPSec SA configuration!
Feb 21 2016 04:06:04: %ASA-4-752012: IKEv1 was unsuccessful at setting up a tunnel.  Map Tag = outside_map.  Map Sequence Number = 10.
Feb 21 2016 04:06:04: %ASA-3-752015: Tunnel Manager has failed to establish an L2L SA.  All configured IKE versions failed to establish the tunnel. Map Tag= outside_map.  Map Sequence Number = 10.
Feb 21 2016 04:06:04: %ASA-7-752002: Tunnel Manager Removed entry.  Map Tag = outside_map.  Map Sequence Number = 10.
Comment
Watch Question
Network Engineer
Commented:
This problem has been solved!
Unlock 1 Answer and 7 Comments.
See Answer
Why Experts Exchange?

Experts Exchange always has the answer, or at the least points me in the correct direction! It is like having another employee that is extremely experienced.

Jim Murphy
Programmer at Smart IT Solutions

When asked, what has been your best career decision?

Deciding to stick with EE.

Mohamed Asif
Technical Department Head

Being involved with EE helped me to grow personally and professionally.

Carl Webster
CTP, Sr Infrastructure Consultant
Ask ANY Question

Connect with Certified Experts to gain insight and support on specific technology challenges including:

  • Troubleshooting
  • Research
  • Professional Opinions
Did You Know?

We've partnered with two important charities to provide clean water and computer science education to those who need it most. READ MORE