Home/Support/Support Forum/IPSec main mode failing connection
Welcome to Digi Forum, where you can ask questions and receive answers from other members of the community.

IPSec main mode failing connection

0 votes
Hello All:

I'm getting an error that is not in the latest version of the QN51 doc when connecting and IPsec tunnel to a Cisco IOS router in main mode:
10:17:22, 16 Nov 2018,(321) IKE SA Removed. Peer: 125.19.8.230,Negotiation Failure
10:17:22, 16 Nov 2018,(322) IKE SA Removed. Peer: 125.19.8.230,Negotiation Failure
10:17:22, 16 Nov 2018,(322) IKE Negotiation Failed. Peer: ,Inactivity
10:17:20, 16 Nov 2018,IKE Request Received From Eroute 2
10:17:10, 16 Nov 2018,IKE Request Received From Eroute 2
10:17:00, 16 Nov 2018,IKE Request Received From Eroute 2
10:16:52, 16 Nov 2018,(322) New Phase 2 IKE Session 125.19.8.230,Initiator
10:16:52, 16 Nov 2018,(321) IKE Keys Negotiated. Peer:
10:16:50, 16 Nov 2018,(321) New Phase 1 IKE Session 125.19.8.230,Initiator
10:16:50, 16 Nov 2018,IKE Request Received From Eroute 2

This just continually repeats. I have other sites connected to this router that are fine.

The field units are WR41s but I am testing locally withe a WR44v2.
FW in my WR44v2 is:
Firmware Version: 6.1.3.8 (Sep 21 2018 14:37:04)
SBIOS Version: 7.63u
Build Version: LW
HW Version: 2204a

I have crossed checked the config with other Digi's I have connected to my local Cisco 2911 and their configs looks the same as this one so am scratching my head.

I do not have access to the Cisco side debug as its a customer's system that I assisted with configuration on 2 years ago and everything was working so they changes all the pwds and access stuff as its not my router...so yah, we can only see stuff from the Digi side.

Any pointers would be helpful.

Cheers,
john
asked Nov 15 in Digi TransPort Cellular by jserink New to the Community (42 points)

Please log in or register to answer this question.

2 Answers

0 votes
Update.....
Changed the IKE timeout to 40 seconds from the default 30:
Stop IKE negotiation if no packet received for 40 seconds

And the eventlog messages changed slightly:
10:46:02, 16 Nov 2018,(493) IKE SA Removed. Peer: 125.19.8.230,Negotiation Failure
10:46:02, 16 Nov 2018,(494) IKE SA Removed. Peer: 125.19.8.230,Negotiation Failure
10:46:02, 16 Nov 2018,(494) IKE Negotiation Failed. Peer: ,Retries Exceeded
10:46:00, 16 Nov 2018,IKE Request Received From Eroute 2
10:45:50, 16 Nov 2018,IKE Request Received From Eroute 2
10:45:40, 16 Nov 2018,IKE Request Received From Eroute 2
10:45:32, 16 Nov 2018,(494) New Phase 2 IKE Session 125.19.8.230,Initiator
10:45:32, 16 Nov 2018,(493) IKE Keys Negotiated. Peer:
10:45:30, 16 Nov 2018,(493) New Phase 1 IKE Session 125.19.8.230,Initiator
10:45:30, 16 Nov 2018,IKE Request Received From Eroute 2
answered Nov 15 by jserink New to the Community (42 points)
0 votes
Hi

You are stuck as it looks like the Cisco is not liking the connection and is not responding to the request.

You would need to see what is wrong with the proposal on the Cisco .

You would need to check the configuration on the other routers and see what is different on this device

regards
answered Nov 20 by James.Wilson Veteran of the Digi Community (1,091 points)
Contact a Digi expert and get started today! Contact Us
...