• Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 32
  • Last Modified:

vpn issue

i was able to successfully create a site to site between asa5506 and tp-link r600vpn, however, when i applied the same settings to asa5515, the tunnel does not come up and always display this on the logs:

       reject the packet, received unexpecting payload: payload id:1
0
mwauki
Asked:
mwauki
  • 5
  • 3
1 Solution
 
JohnBusiness Consultant (Owner)Commented:
The layout of settings for the other box are probably different even though IPsec VPN is fundamentally the same.

Make a list of the setting of the asa5506 and match these to the settings on the asa5515. Watch for Main vs Aggressive mode (need Main mode). Watch for NAT Traversal and Dead Peer detect settings.

Check the external static and internal addressing to be sure it is correct in the new box.
0
 
mwaukiSystems EngineerAuthor Commented:
thank you, John!  yes i have done that.
0
 
mwaukiSystems EngineerAuthor Commented:
whenever i switch to main on both ends (asa5506 & TP-Link), the tunnel goes down.  so when i switched both back to aggresive mode, tunnel comes back online and able to ping LANs on both ends.
0
Worried about phishing attacks?

90% of attacks start with a phish. It’s critical that IT admins and MSSPs have the right security in place to protect their end users from these phishing attacks. Check out our latest feature brief for tips and tricks to keep your employees off a hackers line!

 
JohnBusiness Consultant (Owner)Commented:
Aggressive mode makes connections easier, whereas Main is more secure. But if Aggressive works, try it.
0
 
mwaukiSystems EngineerAuthor Commented:
yes, Aggressive mode works for the asa5506 and the tp-link but not asa5515 & the tp-link
0
 
mwaukiSystems EngineerAuthor Commented:
thanks for the support.... had to put encryption and authendication on the tp-link to auto and now asa5515 and tp-link are talking....
0
 
JohnBusiness Consultant (Owner)Commented:
Good to know but was that not part of the settings I asked you to review.?
0
 
mwaukiSystems EngineerAuthor Commented:
figured it out myself...
0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

Join & Write a Comment

Featured Post

Free Tool: Site Down Detector

Helpful to verify reports of your own downtime, or to double check a downed website you are trying to access.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

  • 5
  • 3
Tackle projects and never again get stuck behind a technical roadblock.
Join Now