[2 days left] What’s wrong with your cloud strategy? Learn why multicloud solutions matter with Nimble Storage.Register Now

x
?
Solved

vpn issue

Posted on 2016-10-25
8
Medium Priority
?
23 Views
Last Modified: 2016-10-31
i was able to successfully create a site to site between asa5506 and tp-link r600vpn, however, when i applied the same settings to asa5515, the tunnel does not come up and always display this on the logs:

       reject the packet, received unexpecting payload: payload id:1
0
Comment
Question by:mwauki
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 5
  • 3
8 Comments
 
LVL 98

Expert Comment

by:John Hurst
ID: 41859679
The layout of settings for the other box are probably different even though IPsec VPN is fundamentally the same.

Make a list of the setting of the asa5506 and match these to the settings on the asa5515. Watch for Main vs Aggressive mode (need Main mode). Watch for NAT Traversal and Dead Peer detect settings.

Check the external static and internal addressing to be sure it is correct in the new box.
0
 

Author Comment

by:mwauki
ID: 41861421
thank you, John!  yes i have done that.
0
 

Author Comment

by:mwauki
ID: 41861447
whenever i switch to main on both ends (asa5506 & TP-Link), the tunnel goes down.  so when i switched both back to aggresive mode, tunnel comes back online and able to ping LANs on both ends.
0
Are You Ready for GDPR?

With the GDPR deadline set for May 25, 2018, many organizations are ill-prepared due to uncertainty about the criteria for compliance. According to a recent WatchGuard survey, a staggering 37% of respondents don't even know if their organization needs to comply with GDPR. Do you?

 
LVL 98

Expert Comment

by:John Hurst
ID: 41861456
Aggressive mode makes connections easier, whereas Main is more secure. But if Aggressive works, try it.
0
 

Author Comment

by:mwauki
ID: 41861473
yes, Aggressive mode works for the asa5506 and the tp-link but not asa5515 & the tp-link
0
 

Accepted Solution

by:
mwauki earned 0 total points
ID: 41861503
thanks for the support.... had to put encryption and authendication on the tp-link to auto and now asa5515 and tp-link are talking....
0
 
LVL 98

Expert Comment

by:John Hurst
ID: 41861511
Good to know but was that not part of the settings I asked you to review.?
0
 

Author Closing Comment

by:mwauki
ID: 41866616
figured it out myself...
0

Featured Post

VIDEO: THE CONCERTO CLOUD FOR HEALTHCARE

Modern healthcare requires a modern cloud. View this brief video to understand how the Concerto Cloud for Healthcare can help your organization.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Secure VPN Connection terminated locally by the Client.  Reason 442: Failed to enable Virtual Adapter. If you receive this error on Windows 8 or Windows 8.1 while trying to connect with the Cisco VPN Client then the solution is a simple registry f…
I've written this article to illustrate how we can implement a Dynamic Multipoint VPN (DMVPN) with both hub and spokes having a dynamically assigned non-broadcast multiple-access (NBMA) network IP (public IP). Here is the basic setup of DMVPN Pha…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

656 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question