[nsp] IPSEC Error on Cat6500 MSFC

Matti Saarinen mjs at cc.tut.fi
Tue Sep 9 11:50:26 EDT 2003


Tay Chee Yong <tcy at pacific.net.sg> writes:

> I am getting an IPSEC error on my msfc running Version 12.1(8b)E14, when
> there is no IPSEC configuration on it.
>
> Sep  7 00:05:17 router1.domain.com 1460: Sep  7 00:05:16:
> %CRYPTO-6-IKMP_MODE_FAILURE: Processing of Main mode
> failed 

     I've seen these, too, after the we uograded the MSFC to an image
     that has SSH support and SSH was switched on. I managed to get
     rid of these messages by switching ISAKMP off.


     msfc(config)#no crypto isakmp enable


> Does anyone knows where does this error message comes from, and what
> is causing this error?

     I don't know the cause. I assume that when the cryptographic keys
     are generated some cryptographic features are enabled at the same
     time. Why the router sees the ISAKMP/IKE packets in the first
     place or does it even see them is a completely different
     question.

     Cheers,

-- 
- Matti -


More information about the cisco-nsp mailing list