[c-nsp] Strange debug crypto isakmp error messages

tony kam chiwaikam at hotmail.com
Sat Apr 10 08:54:41 EDT 2010


We have the following topology:

A-router(IPSec) <---LAN-->(inside)ASA5505(outside)<-----internet------>B-router(IPSec)


B-router has the following "debug crypto isakmp error" messages keep repeating.

========
*Apr  8 07:23:25.772: ISAKMP:(1316):peer 22x.x.x.y not responding!
*Apr  8 07:23:40.788: ISAKMP:(1316):deleting SA reason "Death by retransmission throw" state (R) QM_IDLE       (peer 220.227.43.225)
*Apr  8 07:23:40.788: ISAKMP:(1316):deleting SA reason "Death by retransmission throw" state (R) QM_IDLE       (peer 220.227.43.225) 
*Apr  8 07:23:40.788: ISAKMP:(0):Can't decrement IKE Call Admission Control stat incoming_active since it's already 0.
*Apr  8 07:24:10.700: ISAKMP:(1319): no outgoing phase 1 packet to retransmit. QM_IDLE      
*Apr  8 07:24:10.892: ISAKMP:(1319): no outgoing phase 1 packet to retransmit. QM_IDLE      
*Apr  8 07:24:20.892: ISAKMP:(1319): no outgoing phase 1 packet to retransmit. QM_IDLE      
==========


ASA5505 has IPSec passthrough configured and NAT for A-router.
B-router is using public IP.
22x.x.x.y is ASA5505 public IP.

Then, what will be the root causes for the above error messages ?

Thanks!




More information about the cisco-nsp mailing list