Notices
Computer & Technology Related Post here for help and discussion of computing and related technology. Internet, TVs, phones, consoles, computers, tablets and any other gadgets.

More Cisco VPN questions

Thread Tools
 
Search this Thread
 
Old 25 September 2002, 04:28 PM
  #1  
NotoriousREV
Scooby Regular
Thread Starter
 
NotoriousREV's Avatar
 
Join Date: Jan 2002
Posts: 11,581
Likes: 0
Received 0 Likes on 0 Posts
Post

I've configured a Cisco router to connect a VPN to another non-Cisco router. They've exchanged keys and ar happy with each others identity etc, however I can't route traffic over the VPN at all and am seeing lots of the following error messages:

00:07:46: %CRYPTO-4-IKMP_NO_SA: IKE message from [peer address] has no SA and is not an initialization offer

I beleive the problem is that the internal ip address range at the remote peer has been incorrectly numbered. They are using live ip addresses that belong to someone else (all hidden so it won't have any other side effects) but I think my router is having routing trouble, even though I've set a route to use the peer as the gateway for that address range.

Am I barking up the wrong tree? Have I missed something really basic?
Old 25 September 2002, 05:48 PM
  #2  
scoob_dood
Scooby Regular
 
scoob_dood's Avatar
 
Join Date: Jan 2002
Location: London
Posts: 550
Likes: 0
Received 0 Likes on 0 Posts
Post

Have you tried punching the error message into the Cisco website ? That can be useful.
Old 25 September 2002, 06:19 PM
  #3  
SiCotty
Scooby Regular
 
SiCotty's Avatar
 
Join Date: Jan 2001
Posts: 442
Likes: 0
Received 0 Likes on 0 Posts
Post

This is something to do with the IKE Security Association which is needed to setup the IPSec tunnel. You may have a configuration error at one end or the other. This is to do with the Keys used to encrypt the data.

Have not played with this in some time so sorry I can not be of any more use.

Si

Have a look at

http://www.cisco.com/warp/public/707/ipsec_debug.html

and the following for some config guides and examples

http://www.cisco.com/warp/public/707/#ipsec

[Edited by SiCotty - 9/25/2002 6:22:29 PM]
Old 26 September 2002, 09:41 AM
  #4  
Jeff Wiltshire
Scooby Regular
 
Jeff Wiltshire's Avatar
 
Join Date: Nov 2000
Location: 412 Wheel HP Audi RS4
Posts: 2,021
Likes: 0
Received 1 Like on 1 Post
Post

It looks like the far end doesn't have your information correctly set-up in the SA. You need to associate the far network with the IKE SA so that it knows to use the tunnel correctly. This needs to be done at both ends. Apologies if this is teaching Grandma to suck eggs.....


Jeff
Related Topics
Thread
Thread Starter
Forum
Replies
Last Post
KAS35RSTI
Subaru
27
04 November 2021 07:12 PM
slimwiltaz
General Technical
20
09 October 2015 07:40 PM
IanG1983
Wheels, Tyres & Brakes
2
06 October 2015 03:08 PM
Brzoza
Engine Management and ECU Remapping
1
02 October 2015 05:26 PM
the shreksta
Other Marques
26
01 October 2015 02:30 PM



Quick Reply: More Cisco VPN questions



All times are GMT +1. The time now is 03:27 AM.