[c-nsp] Strange debug crypto isakmp error messages
tony kam
chiwaikam at hotmail.com
Sat Apr 10 08:54:41 EDT 2010
We have the following topology:
A-router(IPSec) <---LAN-->(inside)ASA5505(outside)<-----internet------>B-router(IPSec)
B-router has the following "debug crypto isakmp error" messages keep repeating.
========
*Apr 8 07:23:25.772: ISAKMP:(1316):peer 22x.x.x.y not responding!
*Apr 8 07:23:40.788: ISAKMP:(1316):deleting SA reason "Death by retransmission throw" state (R) QM_IDLE (peer 220.227.43.225)
*Apr 8 07:23:40.788: ISAKMP:(1316):deleting SA reason "Death by retransmission throw" state (R) QM_IDLE (peer 220.227.43.225)
*Apr 8 07:23:40.788: ISAKMP:(0):Can't decrement IKE Call Admission Control stat incoming_active since it's already 0.
*Apr 8 07:24:10.700: ISAKMP:(1319): no outgoing phase 1 packet to retransmit. QM_IDLE
*Apr 8 07:24:10.892: ISAKMP:(1319): no outgoing phase 1 packet to retransmit. QM_IDLE
*Apr 8 07:24:20.892: ISAKMP:(1319): no outgoing phase 1 packet to retransmit. QM_IDLE
==========
ASA5505 has IPSec passthrough configured and NAT for A-router.
B-router is using public IP.
22x.x.x.y is ASA5505 public IP.
Then, what will be the root causes for the above error messages ?
Thanks!
More information about the cisco-nsp
mailing list