Pages

Saturday, May 21, 2016

Troubleshooting Cisco IPSec Site to Site VPN - "reason: Unknown delete reason!" after Phase 1 Completed

It is always not easy when troubleshooting a vpn issue. You will meet many situations. Here is one of examples I used to meet during configuring ipsec vpn.
Other examples to troubleshoot IPSec VPN issue:
Topology:







Symptom:

When traffic initiated from remote site server 19.16.19.158 to local server 19.24.11.59, vpn tunnel can be built without problem. But if Traffic initiated from local site, tunnel failed and SA deleted right away after tunnel phase 1 completed.


Configuration :


crypto isakmp policy 2
encr aes 256
authentication pre-share
group 5
crypto isakmp key xxxxxxxxx address 19.16.19.136
crypto isakmp aggressive-mode disable

crypto ipsec transform-set Set1 esp-aes 256 esp-sha-hmac

crypto map vpn 30 ipsec-isakmp 
set peer 19.16.19.136
set transform-set Set1 
 set pfs group2
match address VPN-Test

ip access-list extended VPN-Test

permit ip host 19.24.11.59 host 19.16.19.158


When traffic initiated from local server 19.24.11.59 to remote server 19.16.19.158, VPN Tunnel was not up based on above configuration.


Troubleshooting: 

Troubleshooting command on Cisco router:

  • Debug Crypto ISAKMP
  • Debug Crypto IPSEC
  • Terminal Monitor


Following is the terminal logs:


R1-IPSEC1#
031993: May 20 12:00:33.442 EDT: IPSEC(sa_request): ,
  (key eng. msg.) OUTBOUND local= 19.24.11.142:500, remote= 

19.16.19.136:500, 
    local_proxy= 19.24.11.59/255.255.255.255/0/0 (type=1), 
    remote_proxy= 19.16.19.158/255.255.255.255/0/0 (type=1),
    protocol= ESP, transform= esp-aes 256 esp-sha-hmac  (Tunnel), 
    lifedur= 3600s and 4608000kb, 
    spi= 0x0(0), conn_id= 0, keysize= 256, flags= 0x0
031994: May 20 12:00:33.442 EDT: ISAKMP:(0): SA request profile is (NULL)
031995: May 20 12:00:33.442 EDT: ISAKMP: Created a peer struct for 

19.16.19.136, peer port 500
031996: May 20 12:00:33.442 EDT: ISAKMP: New peer created peer = 0x313D5AA8 

peer_handle = 0x80000049
031997: May 20 12:00:33.442 EDT: ISAKMP: Locking peer struct 0x313D5AA8, 

refcount 1 for isakmp_initiator
031998: May 20 12:00:33.446 EDT: ISAKMP: local port 500, remote port 500
031999: May 20 12:00:33.446 EDT: ISAKMP: set new node 0 to QM_IDLE      
032000: May 20 12:00:33.446 EDT: ISAKMP:(0):insert sa successfully sa = 

2A271B9C
032001: May 20 12:00:33.446 EDT: %CRYPTO-5-IKMP_AG_MODE_DISABLED: Unable to 

initiate or respond to Aggressive Mode while disabled
032002: May 20 12:00:33.446 EDT: ISAKMP:(0):Can not start Aggressive mode, 

trying Main mode.
032003: May 20 12:00:33.446 EDT: ISAKMP:(0):found peer pre-shared key matching 

19.16.19.136
032004: May 20 12:00:33.446 EDT: ISAKMP:(0): constructed NAT-T vendor-rfc3947 

ID
032005: May 20 12:00:33.446 EDT: ISAKMP:(0): constructed NAT-T vendor-07 ID
032006: May 20 12:00:33.446 EDT: ISAKMP:(0): constructed NAT-T vendor-03 ID
032007: May 20 12:00:33.446 EDT: ISAKMP:(0): constructed NAT-T vendor-02 ID
032008: May 20 12:00:33.446 EDT: ISAKMP:(0):Input = IKE_MESG_FROM_IPSEC, 

IKE_SA_REQ_MM
032009: May 20 12:00:33.446 EDT: ISAKMP:(0):Old State = IKE_READY  New State = 

IKE_I_MM1 

032010: May 20 12:00:33.446 EDT: ISAKMP:(0): beginning Main Mode exchange
032011: May 20 12:00:33.446 EDT: ISAKMP:(0): sending packet to 19.16.19.136 

my_port 500 peer_port 500 (I) MM_NO_STATE
032012: May 20 12:00:33.446 EDT: ISAKMP:(0):Sending an IKE IPv4 Packet.
032013: May 20 12:00:33.474 EDT: ISAKMP (0): received packet from 

19.16.19.136 dport 500 sport 500 Global (I) MM_NO_STATE
032014: May 20 12:00:33.474 EDT: ISAKMP:(0):Input = IKE_MESG_FROM_PEER, 

IKE_MM_EXCH
032015: May 20 12:00:33.474 EDT: ISAKMP:(0):Old State = IKE_I_MM1  New State = 

IKE_I_MM2 

032016: May 20 12:00:33.474 EDT: ISAKMP:(0): processing SA payload. message ID 

= 0
032017: May 20 12:00:33.474 EDT: ISAKMP:(0): processing vendor id payload
032018: May 20 12:00:33.474 EDT: ISAKMP:(0): vendor ID seems Unity/DPD but 

major 69 mismatch
032019: May 20 12:00:33.474 EDT: ISAKMP (0): vendor ID is NAT-T RFC 3947
032020: May 20 12:00:33.474 EDT: ISAKMP:(0): processing vendor id payload
032021: May 20 12:00:33.474 EDT: ISAKMP:(0): processing IKE frag vendor id 

payload
032022: May 20 12:00:33.474 EDT: ISAKMP:(0):Support for IKE Fragmentation not 

enabled
032023: May 20 12:00:33.474 EDT: ISAKMP:(0):found peer pre-shared key matching 

19.16.19.136
032024: May 20 12:00:33.478 EDT: ISAKMP:(0): local preshared key found
032025: May 20 12:00:33.478 EDT: ISAKMP : Scanning profiles for xauth ...
032026: May 20 12:00:33.478 EDT: ISAKMP:(0):Checking ISAKMP transform 1 

against priority 1 policy
032027: May 20 12:00:33.478 EDT: ISAKMP:      encryption 3DES-CBC
032028: May 20 12:00:33.478 EDT: ISAKMP:      hash SHA
032029: May 20 12:00:33.478 EDT: ISAKMP:      default group 2
032030: May 20 12:00:33.478 EDT: ISAKMP:      auth pre-share
032031: May 20 12:00:33.478 EDT: ISAKMP:      life type in seconds
032032: May 20 12:00:33.478 EDT: ISAKMP:      life duration (basic) of 3600
032033: May 20 12:00:33.478 EDT: ISAKMP:(0):atts are acceptable. Next payload 

is 0
032034: May 20 12:00:33.478 EDT: ISAKMP:(0):Acceptable atts:actual life: 0
032035: May 20 12:00:33.478 EDT: ISAKMP:(0):Acceptable atts:life: 0
032036: May 20 12:00:33.478 EDT: ISAKMP:(0):Basic life_in_seconds:3600
032037: May 20 12:00:33.478 EDT: ISAKMP:(0):Returning Actual lifetime: 3600
032038: May 20 12:00:33.478 EDT: ISAKMP:(0)::Started lifetime timer: 3600.

032039: May 20 12:00:33.478 EDT: ISAKMP:(0): processing vendor id payload
032040: May 20 12:00:33.478 EDT: ISAKMP:(0): vendor ID seems Unity/DPD but 

major 69 mismatch
032041: May 20 12:00:33.478 EDT: ISAKMP (0): vendor ID is NAT-T RFC 3947
032042: May 20 12:00:33.478 EDT: ISAKMP:(0): processing vendor id payload
032043: May 20 12:00:33.478 EDT: ISAKMP:(0): processing IKE frag vendor id 

payload
032044: May 20 12:00:33.478 EDT: ISAKMP:(0):Support for IKE Fragmentation not 

enabled
032045: May 20 12:00:33.478 EDT: ISAKMP:(0):Input = IKE_MESG_INTERNAL, 

IKE_PROCESS_MAIN_MODE
032046: May 20 12:00:33.478 EDT: ISAKMP:(0):Old State = IKE_I_MM2  New State = 

IKE_I_MM2 

032047: May 20 12:00:33.478 EDT: ISAKMP:(0): sending packet to 19.16.19.136 

my_port 500 peer_port 500 (I) MM_SA_SETUP
032048: May 20 12:00:33.478 EDT: ISAKMP:(0):Sending an IKE IPv4 Packet.
032049: May 20 12:00:33.478 EDT: ISAKMP:(0):Input = IKE_MESG_INTERNAL, 

IKE_PROCESS_COMPLETE
032050: May 20 12:00:33.478 EDT: ISAKMP:(0):Old State = IKE_I_MM2  New State = 

IKE_I_MM3 

032051: May 20 12:00:33.506 EDT: ISAKMP (0): received packet from 

19.16.19.136 dport 500 sport 500 Global (I) MM_SA_SETUP
032052: May 20 12:00:33.506 EDT: ISAKMP:(0):Input = IKE_MESG_FROM_PEER, 

IKE_MM_EXCH
032053: May 20 12:00:33.506 EDT: ISAKMP:(0):Old State = IKE_I_MM3  New State = 

IKE_I_MM4 

032054: May 20 12:00:33.510 EDT: ISAKMP:(0): processing KE payload. message ID 

= 0
032055: May 20 12:00:33.534 EDT: ISAKMP:(0): processing NONCE payload. message 

ID = 0
032056: May 20 12:00:33.534 EDT: ISAKMP:(0):found peer pre-shared key matching 

19.16.19.136
032057: May 20 12:00:33.534 EDT: ISAKMP:(1112): processing vendor id payload
032058: May 20 12:00:33.534 EDT: ISAKMP:(1112): vendor ID is Unity
032059: May 20 12:00:33.534 EDT: ISAKMP:(1112): processing vendor id payload
032060: May 20 12:00:33.534 EDT: ISAKMP:(1112): vendor ID seems Unity/DPD but 

major 245 mismatch
032061: May 20 12:00:33.534 EDT: ISAKMP:(1112): vendor ID is XAUTH
032062: May 20 12:00:33.534 EDT: ISAKMP:(1112): processing vendor id payload
032063: May 20 12:00:33.534 EDT: ISAKMP:(1112): speaking to another IOS box!
032064: May 20 12:00:33.534 EDT: ISAKMP:(1112): processing vendor id payload
032065: May 20 12:00:33.534 EDT: ISAKMP:(1112):vendor ID seems Unity/DPD but 

hash mismatch
032066: May 20 12:00:33.534 EDT: ISAKMP:received payload type 20
032067: May 20 12:00:33.534 EDT: ISAKMP (1112): His hash no match - this node 

outside NAT
032068: May 20 12:00:33.534 EDT: ISAKMP:received payload type 20
032069: May 20 12:00:33.534 EDT: ISAKMP (1112): No NAT Found for self or peer
032070: May 20 12:00:33.534 EDT: ISAKMP:(1112):Input = IKE_MESG_INTERNAL, 

IKE_PROCESS_MAIN_MODE
032071: May 20 12:00:33.534 EDT: ISAKMP:(1112):Old State = IKE_I_MM4  New 

State = IKE_I_MM4 

032072: May 20 12:00:33.538 EDT: ISAKMP:(1112):Send initial contact
032073: May 20 12:00:33.538 EDT: ISAKMP:(1112):SA is doing pre-shared key 

authentication using id type ID_IPV4_ADDR
032074: May 20 12:00:33.538 EDT: ISAKMP (1112): ID payload 
        next-payload : 8
        type         : 1 
        address      : 19.24.11.142 
        protocol     : 17 
        port         : 500 
        length       : 12
032075: May 20 12:00:33.538 EDT: ISAKMP:(1112):Total payload length: 12
032076: May 20 12:00:33.538 EDT: ISAKMP:(1112): sending packet to 

19.16.19.136 my_port 500 peer_port 500 (I) MM_KEY_EXCH
032077: May 20 12:00:33.538 EDT: ISAKMP:(1112):Sending an IKE IPv4 Packet.
032078: May 20 12:00:33.538 EDT: ISAKMP:(1112):Input = IKE_MESG_INTERNAL, 

IKE_PROCESS_COMPLETE
032079: May 20 12:00:33.538 EDT: ISAKMP:(1112):Old State = IKE_I_MM4  New 

State = IKE_I_MM5 

032080: May 20 12:00:33.566 EDT: ISAKMP (1112): received packet from 

19.16.19.136 dport 500 sport 500 Global (I) MM_KEY_EXCH
032081: May 20 12:00:33.566 EDT: ISAKMP:(1112): processing ID payload. message 

ID = 0
032082: May 20 12:00:33.566 EDT: ISAKMP (1112): ID payload 
        next-payload : 8
        type         : 1 
        address      : 19.16.19.136 
        protocol     : 17 
        port         : 0 
        length       : 12
032083: May 20 12:00:33.566 EDT: ISAKMP:(0):: peer matches *none* of the 

profiles
032084: May 20 12:00:33.566 EDT: ISAKMP:(1112): processing HASH payload. 

message ID = 0
032085: May 20 12:00:33.566 EDT: ISAKMP:received payload type 17
032086: May 20 12:00:33.566 EDT: ISAKMP:(1112): processing vendor id payload
032087: May 20 12:00:33.566 EDT: ISAKMP:(1112): vendor ID is DPD
032088: May 20 12:00:33.566 EDT: ISAKMP:(1112):SA authentication status:
        authenticated
032089: May 20 12:00:33.566 EDT: ISAKMP:(1112):SA has been authenticated with 

19.16.19.136
032090: May 20 12:00:33.566 EDT: ISAKMP: Trying to insert a peer 

19.24.11.142/19.16.19.136/500/,  and inserted successfully 313D5AA8.
032091: May 20 12:00:33.566 EDT: ISAKMP:(1112):Input = IKE_MESG_FROM_PEER, 

IKE_MM_EXCH
032092: May 20 12:00:33.566 EDT: ISAKMP:(1112):Old State = IKE_I_MM5  New 

State = IKE_I_MM6 

032093: May 20 12:00:33.566 EDT: ISAKMP:(1112):Input = IKE_MESG_INTERNAL, 

IKE_PROCESS_MAIN_MODE
032094: May 20 12:00:33.566 EDT: ISAKMP:(1112):Old State = IKE_I_MM6  New 

State = IKE_I_MM6 

032095: May 20 12:00:33.566 EDT: ISAKMP:(1112):Input = IKE_MESG_INTERNAL, 

IKE_PROCESS_COMPLETE
032096: May 20 12:00:33.566 EDT: ISAKMP:(1112):Old State = IKE_I_MM6  New 

State = IKE_P1_COMPLETE 

032097: May 20 12:00:33.570 EDT: ISAKMP:(1112):beginning Quick Mode exchange, 

M-ID of 3822625957
032098: May 20 12:00:33.570 EDT: ISAKMP:(1112):QM Initiator gets spi
032099: May 20 12:00:33.570 EDT: ISAKMP:(1112): sending packet to 

19.16.19.136 my_port 500 peer_port 500 (I) QM_IDLE      
032100: May 20 12:00:33.570 EDT: ISAKMP:(1112):Sending an IKE IPv4 Packet.
032101: May 20 12:00:33.570 EDT: ISAKMP:(1112):Node 3822625957, Input = 

IKE_MESG_INTERNAL, IKE_INIT_QM
032102: May 20 12:00:33.570 EDT: ISAKMP:(1112):Old State = IKE_QM_READY  New 

State = IKE_QM_I_QM1
032103: May 20 12:00:33.570 EDT: ISAKMP:(1112):Input = IKE_MESG_INTERNAL, 

IKE_PHASE1_COMPLETE
032104: May 20 12:00:33.570 EDT: ISAKMP:(1112):Old State = IKE_P1_COMPLETE  

New State = IKE_P1_COMPLETE 

032105: May 20 12:00:33.602 EDT: ISAKMP (1112): received packet from 

19.16.19.136 dport 500 sport 500 Global (I) QM_IDLE      
032106: May 20 12:00:33.602 EDT: ISAKMP: set new node 497356209 to QM_IDLE     


032107: May 20 12:00:33.602 EDT: ISAKMP:(1112): processing HASH payload. 

message ID = 497356209
032108: May 20 12:00:33.602 EDT: ISAKMP:(1112): processing NOTIFY 

PROPOSAL_NOT_CHOSEN protocol 3
        spi 0, message ID = 497356209, sa = 0x2A271B9C
032109: May 20 12:00:33.602 EDT: ISAKMP:(1112):deleting node 497356209 error 

FALSE reason "Informational (in) state 1"
032110: May 20 12:00:33.602 EDT: ISAKMP:(1112):Input = IKE_MESG_FROM_PEER, 

IKE_INFO_NOTIFY
032111: May 20 12:00:33.602 EDT: ISAKMP:(1112):Old State = IKE_P1_COMPLETE  

New State = IKE_P1_COMPLETE 

032112: May 20 12:00:33.602 EDT: ISAKMP (1112): received packet from 

19.16.19.136 dport 500 sport 500 Global (I) QM_IDLE      
032113: May 20 12:00:33.602 EDT: ISAKMP: set new node 309704327 to QM_IDLE     


032114: May 20 12:00:33.602 EDT: ISAKMP:(1112): processing HASH payload. 

message ID = 309704327
032115: May 20 12:00:33.602 EDT: ISAKMP:received payload type 18
032116: May 20 12:00:33.602 EDT: ISAKMP:(1112):Processing delete with reason 

payload
032117: May 20 12:00:33.602 EDT: ISAKMP:(1112):delete doi = 1
032118: May 20 12:00:33.602 EDT: ISAKMP:(1112):delete protocol id = 1
032119: May 20 12:00:33.602 EDT: ISAKMP:(1112):delete spi_size =  16
032120: May 20 12:00:33.602 EDT: ISAKMP:(1112):delete num spis = 1
032121: May 20 12:00:33.602 EDT: ISAKMP:(1112):delete_reason = 10
032122: May 20 12:00:33.606 EDT: ISAKMP:(1112): processing DELETE_WITH_REASON 

payload, message ID = 309704327, reason: Unknown delete reason!
032123: May 20 12:00:33.606 EDT: ISAKMP:(1112):peer does not do paranoid 

keepalives.

032124: May 20 12:00:33.606 EDT: ISAKMP:(1112):deleting SA reason "IKE SA 

Lifetime Exceeded" state (I) QM_IDLE       (peer 19.16.19.136)
032125: May 20 12:00:33.606 EDT: ISAKMP:(1112):deleting node 309704327 error 

FALSE reason "Informational (in) state 1"
032126: May 20 12:00:33.606 EDT: ISAKMP: set new node -1825006387 to QM_IDLE   

   
032127: May 20 12:00:33.606 EDT: ISAKMP:(1112): sending packet to 

19.16.19.136 my_port 500 peer_port 500 (I) QM_IDLE      
032128: May 20 12:00:33.606 EDT: ISAKMP:(1112):Sending an IKE IPv4 Packet.
032129: May 20 12:00:33.606 EDT: ISAKMP:(1112):purging node -1825006387
032130: May 20 12:00:33.606 EDT: ISAKMP:(1112):Input = IKE_MESG_INTERNAL, 

IKE_PHASE1_DEL
032131: May 20 12:00:33.606 EDT: ISAKMP:(1112):Old State = IKE_P1_COMPLETE  

New State = IKE_DEST_SA 

032132: May 20 12:00:33.606 EDT: ISAKMP:(1112):deleting SA reason "IKE SA 

Lifetime Exceeded" state (I) QM_IDLE       (peer 19.16.19.136) 
032133: May 20 12:00:33.606 EDT: ISAKMP: Unlocking peer struct 0x313D5AA8 for 

isadb_mark_sa_deleted(), count 0
032134: May 20 12:00:33.606 EDT: ISAKMP: Deleting peer node by peer_reap for 

19.16.19.136: 313D5AA8
032135: May 20 12:00:33.606 EDT: ISAKMP:(1112):deleting node -472341339 error 

FALSE reason "IKE deleted"
032136: May 20 12:00:33.606 EDT: ISAKMP:(1112):Input = IKE_MESG_FROM_PEER, 

IKE_MM_EXCH
032137: May 20 12:00:33.606 EDT: ISAKMP:(1112):Old State = IKE_DEST_SA  New 

State = IKE_DEST_SA 

R1-IPSEC1#
032138: May 20 12:00:33.606 EDT: IPSEC(key_engine): got a queue event with 1 

KMI message(s)
R1-IPSEC1#
032139: May 20 12:01:03.441 EDT: IPSEC(key_engine): request timer fired: count 

= 1,
  (identity) local= 19.24.11.142:0, remote= 19.16.19.136:0, 
    local_proxy= 19.24.11.59/255.255.255.255/0/0 (type=1), 
    remote_proxy= 19.16.19.158/255.255.255.255/0/0 (type=1)
032140: May 20 12:01:03.441 EDT: IPSEC(sa_request): ,
  (key eng. msg.) OUTBOUND local= 19.24.11.142:500, remote= 

19.16.19.136:500, 
    local_proxy= 19.24.11.59/255.255.255.255/0/0 (type=1), 
    remote_proxy= 19.16.19.158/255.255.255.255/0/0 (type=1),
    protocol= ESP, transform= esp-aes 256 esp-sha-hmac  (Tunnel), 
    lifedur= 3600s and 4608000kb, 
    spi= 0x0(0), conn_id= 0, keysize= 256, flags= 0x0
032141: May 20 12:01:03.441 EDT: ISAKMP:(0): SA request profile is (NULL)
032142: May 20 12:01:03.441 EDT: ISAKMP: Created a peer struct for 

19.16.19.136, peer port 500
032143: May 20 12:01:03.441 EDT: ISAKMP: New peer created peer = 0x313D3120 

peer_handle = 0x8000004B
032144: May 20 12:01:03.441 EDT: ISAKMP: Locking peer struct 0x313D3120, 

refcount 1 for isakmp_initiator
032145: May 20 12:01:03.441 EDT: ISAKMP: local port 500, remote port 500
032146: May 20 12:01:03.441 EDT: ISAKMP: set new node 0 to QM_IDLE      
032147: May 20 12:01:03.441 EDT: ISAKMP: Find a dup sa in the avl tree during 

calling isadb_insert sa = 30038454
032148: May 20 12:01:03.441 EDT: %CRYPTO-5-IKMP_AG_MODE_DISABLED: Unable to initiate or respond to Aggressive Mode while disabled
032149: May 20 12:01:03.441 EDT: ISAKMP:(0):Can not start Aggressive mode, 

trying Main mode.
032150: May 20 12:01:03.441 EDT: ISAKMP:(0):found peer pre-shared key matching 

19.16.19.136
032151: May 20 12:01:03.441 EDT: ISAKMP:(0): constructed NAT-T vendor-rfc3947 

ID
032152: May 20 12:01:03.441 EDT: ISAKMP:(0): constructed NAT-T vendor-07 ID
032153: May 20 12:01:03.441 EDT: ISAKMP:(0): constructed NAT-T vendor-03 ID
032154: May 20 12:01:03.441 EDT: ISAKMP:(0): constructed NAT-T vendor-02 ID
032155: May 20 12:01:03.441 EDT: ISAKMP:(0):Input = IKE_MESG_FROM_IPSEC, 

IKE_SA_REQ_MM
032156: May 20 12:01:03.441 EDT: ISAKMP:(0):Old State = IKE_READY  New State = 

IKE_I_MM1 

032157: May 20 12:01:03.441 EDT: ISAKMP:(0): beginning Main Mode exchange
032158: May 20 12:01:03.441 EDT: ISAKMP:(0): sending packet to 19.16.19.136 

my_port 500 peer_port 500 (I) MM_NO_STATE
032159: May 20 12:01:03.441 EDT: ISAKMP:(0):Sending an IKE IPv4 Packet.
032160: May 20 12:01:03.469 EDT: ISAKMP (0): received packet from 

19.16.19.136 dport 500 sport 500 Global (I) MM_NO_STATE
032161: May 20 12:01:03.469 EDT: ISAKMP:(0):Input = IKE_MESG_FROM_PEER, 

IKE_MM_EXCH
032162: May 20 12:01:03.469 EDT: ISAKMP:(0):Old State = IKE_I_MM1  New State = 

IKE_I_MM2 

032163: May 20 12:01:03.469 EDT: ISAKMP:(0): processing SA payload. message ID 

= 0
032164: May 20 12:01:03.469 EDT: ISAKMP:(0): processing vendor id payload
032165: May 20 12:01:03.469 EDT: ISAKMP:(0): vendor ID seems Unity/DPD but 

major 69 mismatch
032166: May 20 12:01:03.469 EDT: ISAKMP (0): vendor ID is NAT-T RFC 3947
032167: May 20 12:01:03.469 EDT: ISAKMP:(0): processing vendor id payload
032168: May 20 12:01:03.473 EDT: ISAKMP:(0): processing IKE frag vendor id 

payload
032169: May 20 12:01:03.473 EDT: ISAKMP:(0):Support for IKE Fragmentation not 

enabled
032170: May 20 12:01:03.473 EDT: ISAKMP:(0):found peer pre-shared key matching 

19.16.19.136
032171: May 20 12:01:03.473 EDT: ISAKMP:(0): local preshared key found
032172: May 20 12:01:03.473 EDT: ISAKMP : Scanning profiles for xauth ...
032173: May 20 12:01:03.473 EDT: ISAKMP:(0):Checking ISAKMP transform 1 

against priority 1 policy
032174: May 20 12:01:03.473 EDT: ISAKMP:      encryption 3DES-CBC
032175: May 20 12:01:03.473 EDT: ISAKMP:      hash SHA
032176: May 20 12:01:03.473 EDT: ISAKMP:      default group 2
032177: May 20 12:01:03.473 EDT: ISAKMP:      auth pre-share
032178: May 20 12:01:03.473 EDT: ISAKMP:      life type in seconds
032179: May 20 12:01:03.473 EDT: ISAKMP:      life duration (basic) of 3600
032180: May 20 12:01:03.473 EDT: ISAKMP:(0):atts are acceptable. Next payload 

is 0
032181: May 20 12:01:03.473 EDT: ISAKMP:(0):Acceptable atts:actual life: 0
032182: May 20 12:01:03.473 EDT: ISAKMP:(0):Acceptable atts:life: 0
032183: May 20 12:01:03.473 EDT: ISAKMP:(0):Basic life_in_seconds:3600
032184: May 20 12:01:03.473 EDT: ISAKMP:(0):Returning Actual lifetime: 3600
032185: May 20 12:01:03.473 EDT: ISAKMP:(0)::Started lifetime timer: 3600.

032186: May 20 12:01:03.473 EDT: ISAKMP:(0): processing vendor id payload
032187: May 20 12:01:03.473 EDT: ISAKMP:(0): vendor ID seems Unity/DPD but 

major 69 mismatch
032188: May 20 12:01:03.473 EDT: ISAKMP (0): vendor ID is NAT-T RFC 3947
032189: May 20 12:01:03.473 EDT: ISAKMP:(0): processing vendor id payload
032190: May 20 12:01:03.473 EDT: ISAKMP:(0): processing IKE frag vendor id 

payload
032191: May 20 12:01:03.473 EDT: ISAKMP:(0):Support for IKE Fragmentation not 

enabled
032192: May 20 12:01:03.473 EDT: ISAKMP:(0):Input = IKE_MESG_INTERNAL, 

IKE_PROCESS_MAIN_MODE
032193: May 20 12:01:03.473 EDT: ISAKMP:(0):Old State = IKE_I_MM2  New State = 

IKE_I_MM2 

032194: May 20 12:01:03.473 EDT: ISAKMP:(0): sending packet to 19.16.19.136 

my_port 500 peer_port 500 (I) MM_SA_SETUP
032195: May 20 12:01:03.473 EDT: ISAKMP:(0):Sending an IKE IPv4 Packet.
032196: May 20 12:01:03.473 EDT: ISAKMP:(0):Input = IKE_MESG_INTERNAL, 

IKE_PROCESS_COMPLETE
032197: May 20 12:01:03.473 EDT: ISAKMP:(0):Old State = IKE_I_MM2  New State = 

IKE_I_MM3 

032198: May 20 12:01:03.501 EDT: ISAKMP (0): received packet from 

19.16.19.136 dport 500 sport 500 Global (I) MM_SA_SETUP
032199: May 20 12:01:03.505 EDT: ISAKMP:(0):Input = IKE_MESG_FROM_PEER, 

IKE_MM_EXCH
032200: May 20 12:01:03.505 EDT: ISAKMP:(0):Old State = IKE_I_MM3  New State = 

IKE_I_MM4 

032201: May 20 12:01:03.505 EDT: ISAKMP:(0): processing KE payload. message ID 

= 0
032202: May 20 12:01:03.529 EDT: ISAKMP:(0): processing NONCE payload. message 

ID = 0
032203: May 20 12:01:03.529 EDT: ISAKMP:(0):found peer pre-shared key matching 

19.16.19.136
032204: May 20 12:01:03.529 EDT: ISAKMP:(1113): processing vendor id payload
032205: May 20 12:01:03.529 EDT: ISAKMP:(1113): vendor ID is Unity
032206: May 20 12:01:03.529 EDT: ISAKMP:(1113): processing vendor id payload
032207: May 20 12:01:03.529 EDT: ISAKMP:(1113): vendor ID seems Unity/DPD but 

major 9 mismatch
032208: May 20 12:01:03.529 EDT: ISAKMP:(1113): vendor ID is XAUTH
032209: May 20 12:01:03.529 EDT: ISAKMP:(1113): processing vendor id payload
032210: May 20 12:01:03.529 EDT: ISAKMP:(1113): speaking to another IOS box!
032211: May 20 12:01:03.529 EDT: ISAKMP:(1113): processing vendor id payload
032212: May 20 12:01:03.529 EDT: ISAKMP:(1113):vendor ID seems Unity/DPD but 

hash mismatch
032213: May 20 12:01:03.529 EDT: ISAKMP:received payload type 20
032214: May 20 12:01:03.529 EDT: ISAKMP (1113): His hash no match - this node 

outside NAT
032215: May 20 12:01:03.529 EDT: ISAKMP:received payload type 20
032216: May 20 12:01:03.529 EDT: ISAKMP (1113): No NAT Found for self or peer
032217: May 20 12:01:03.529 EDT: ISAKMP:(1113):Input = IKE_MESG_INTERNAL, 

IKE_PROCESS_MAIN_MODE
032218: May 20 12:01:03.529 EDT: ISAKMP:(1113):Old State = IKE_I_MM4  New 

State = IKE_I_MM4 

032219: May 20 12:01:03.533 EDT: ISAKMP:(1113):Send initial contact
032220: May 20 12:01:03.533 EDT: ISAKMP:(1113):SA is doing pre-shared key 

authentication using id type ID_IPV4_ADDR
032221: May 20 12:01:03.533 EDT: ISAKMP (1113): ID payload 
        next-payload : 8
        type         : 1 
        address      : 19.24.11.142 
        protocol     : 17 
        port         : 500 
        length       : 12
032222: May 20 12:01:03.533 EDT: ISAKMP:(1113):Total payload length: 12
032223: May 20 12:01:03.533 EDT: ISAKMP:(1113): sending packet to 

19.16.19.136 my_port 500 peer_port 500 (I) MM_KEY_EXCH
032224: May 20 12:01:03.533 EDT: ISAKMP:(1113):Sending an IKE IPv4 Packet.
032225: May 20 12:01:03.533 EDT: ISAKMP:(1113):Input = IKE_MESG_INTERNAL, 

IKE_PROCESS_COMPLETE
032226: May 20 12:01:03.533 EDT: ISAKMP:(1113):Old State = IKE_I_MM4  New 

State = IKE_I_MM5 

032227: May 20 12:01:03.561 EDT: ISAKMP (1113): received packet from 

19.16.19.136 dport 500 sport 500 Global (I) MM_KEY_EXCH
032228: May 20 12:01:03.561 EDT: ISAKMP:(1113): processing ID payload. message 

ID = 0
032229: May 20 12:01:03.561 EDT: ISAKMP (1113): ID payload 
        next-payload : 8
        type         : 1 
        address      : 19.16.19.136 
        protocol     : 17 
        port         : 0 
        length       : 12
032230: May 20 12:01:03.561 EDT: ISAKMP:(0):: peer matches *none* of the 

profiles
032231: May 20 12:01:03.561 EDT: ISAKMP:(1113): processing HASH payload. 

message ID = 0
032232: May 20 12:01:03.561 EDT: ISAKMP:received payload type 17
032233: May 20 12:01:03.561 EDT: ISAKMP:(1113): processing vendor id payload
032234: May 20 12:01:03.561 EDT: ISAKMP:(1113): vendor ID is DPD
032235: May 20 12:01:03.561 EDT: ISAKMP:(1113):SA authentication status:
        authenticated
032236: May 20 12:01:03.561 EDT: ISAKMP:(1113):SA has been authenticated with 

19.16.19.136
032237: May 20 12:01:03.561 EDT: ISAKMP: Trying to insert a peer 

19.24.11.142/19.16.19.136/500/,  and inserted successfully 313D3120.
032238: May 20 12:01:03.561 EDT: ISAKMP:(1113):Input = IKE_MESG_FROM_PEER, 

IKE_MM_EXCH
032239: May 20 12:01:03.561 EDT: ISAKMP:(1113):Old State = IKE_I_MM5  New 

State = IKE_I_MM6 

032240: May 20 12:01:03.561 EDT: ISAKMP:(1113):Input = IKE_MESG_INTERNAL, 

IKE_PROCESS_MAIN_MODE
032241: May 20 12:01:03.561 EDT: ISAKMP:(1113):Old State = IKE_I_MM6  New 

State = IKE_I_MM6 

032242: May 20 12:01:03.561 EDT: ISAKMP:(1113):Input = IKE_MESG_INTERNAL, 

IKE_PROCESS_COMPLETE
032243: May 20 12:01:03.561 EDT: ISAKMP:(1113):Old State = IKE_I_MM6  New 

State = IKE_P1_COMPLETE 

032244: May 20 12:01:03.561 EDT: ISAKMP:(1113):beginning Quick Mode exchange, 

M-ID of 2581849008
032245: May 20 12:01:03.565 EDT: ISAKMP:(1113):QM Initiator gets spi
032246: May 20 12:01:03.565 EDT: ISAKMP:(1113): sending packet to 

19.16.19.136 my_port 500 peer_port 500 (I) QM_IDLE      
032247: May 20 12:01:03.565 EDT: ISAKMP:(1113):Sending an IKE IPv4 Packet.
032248: May 20 12:01:03.565 EDT: ISAKMP:(1113):Node 2581849008, Input = 

IKE_MESG_INTERNAL, IKE_INIT_QM
032249: May 20 12:01:03.565 EDT: ISAKMP:(1113):Old State = IKE_QM_READY  New 

State = IKE_QM_I_QM1
032250: May 20 12:01:03.565 EDT: ISAKMP:(1113):Input = IKE_MESG_INTERNAL, 

IKE_PHASE1_COMPLETE
032251: May 20 12:01:03.565 EDT: ISAKMP:(1113):Old State = IKE_P1_COMPLETE  

New State = IKE_P1_COMPLETE 

032252: May 20 12:01:03.597 EDT: ISAKMP (1113): received packet from 

19.16.19.136 dport 500 sport 500 Global (I) QM_IDLE      
032253: May 20 12:01:03.597 EDT: ISAKMP: set new node 1341887425 to QM_IDLE    

  
032254: May 20 12:01:03.597 EDT: ISAKMP:(1113): processing HASH payload. 

message ID = 1341887425
032255: May 20 12:01:03.597 EDT: ISAKMP:(1113): processing NOTIFY 

PROPOSAL_NOT_CHOSEN protocol 3
        spi 0, message ID = 1341887425, sa = 0x30038454
032256: May 20 12:01:03.597 EDT: ISAKMP:(1113):deleting node 1341887425 error 

FALSE reason "Informational (in) state 1"
032257: May 20 12:01:03.597 EDT: ISAKMP:(1113):Input = IKE_MESG_FROM_PEER, 

IKE_INFO_NOTIFY
032258: May 20 12:01:03.597 EDT: ISAKMP:(1113):Old State = IKE_P1_COMPLETE  

New State = IKE_P1_COMPLETE 

032259: May 20 12:01:03.597 EDT: ISAKMP (1113): received packet from 

19.16.19.136 dport 500 sport 500 Global (I) QM_IDLE      
032260: May 20 12:01:03.597 EDT: ISAKMP: set new node 1837926342 to QM_IDLE    

  
032261: May 20 12:01:03.597 EDT: ISAKMP:(1113): processing HASH payload. 

message ID = 1837926342
032262: May 20 12:01:03.597 EDT: ISAKMP:received payload type 18
032263: May 20 12:01:03.597 EDT: ISAKMP:(1113):Processing delete with reason 

payload
032264: May 20 12:01:03.597 EDT: ISAKMP:(1113):delete doi = 1
032265: May 20 12:01:03.597 EDT: ISAKMP:(1113):delete protocol id = 1
032266: May 20 12:01:03.597 EDT: ISAKMP:(1113):delete spi_size =  16
032267: May 20 12:01:03.597 EDT: ISAKMP:(1113):delete num spis = 1
032268: May 20 12:01:03.597 EDT: ISAKMP:(1113):delete_reason = 10
032269: May 20 12:01:03.597 EDT: ISAKMP:(1113): processing DELETE_WITH_REASON 

payload, message ID = 1837926342, reason: Unknown delete reason!
032270: May 20 12:01:03.597 EDT: ISAKMP:(1113):peer does not do paranoid 

keepalives.

032271: May 20 12:01:03.597 EDT: ISAKMP:(1113):deleting SA reason "IKE SA 

Lifetime Exceeded" state (I) QM_IDLE       (peer 19.16.19.136)
032272: May 20 12:01:03.597 EDT: ISAKMP:(1113):deleting node 1837926342 error 

FALSE reason "Informational (in) state 1"
032273: May 20 12:01:03.601 EDT: ISAKMP: set new node -577632662 to QM_IDLE    

  
032274: May 20 12:01:03.601 EDT: ISAKMP:(1113): sending packet to 

19.16.19.136 my_port 500 peer_port 500 (I) QM_IDLE      
032275: May 20 12:01:03.601 EDT: ISAKMP:(1113):Sending an IKE IPv4 Packet.
032276: May 20 12:01:03.601 EDT: ISAKMP:(1113):purging node -577632662
032277: May 20 12:01:03.601 EDT: ISAKMP:(1113):Input = IKE_MESG_INTERNAL, 

IKE_PHASE1_DEL
032278: May 20 12:01:03.601 EDT: ISAKMP:(1113):Old State = IKE_P1_COMPLETE  

New State = IKE_DEST_SA 

032279: May 20 12:01:03.601 EDT: ISAKMP:(1113):deleting SA reason "IKE SA 

Lifetime Exceeded" state (I) QM_IDLE       (peer 19.16.19.136) 
032280: May 20 12:01:03.601 EDT: ISAKMP: Unlocking peer struct 0x313D3120 for 

isadb_mark_sa_deleted(), count 0
032281: May 20 12:01:03.601 EDT: ISAKMP: Deleting peer node by peer_reap for 

19.16.19.136: 313D3120
032282: May 20 12:01:03.601 EDT: ISAKMP:(1113):deleting node -1713118288 error 

FALSE reason "IKE deleted"
032283: May 20 12:01:03.601 EDT: ISAKMP:(1113):Input = IKE_MESG_FROM_PEER, 

IKE_MM_EXCH
032284: May 20 12:01:03.601 EDT: ISAKMP:(1113):Old State = IKE_DEST_SA  New 

State = IKE_DEST_SA 

R1-IPSEC1#
032285: May 20 12:01:03.601 EDT: IPSEC(key_engine): got a queue event with 1 

KMI message(s)
R1-IPSEC1#
032286: May 20 12:01:23.601 EDT: ISAKMP:(1112):purging node 497356209
032287: May 20 12:01:23.605 EDT: ISAKMP:(1112):purging node 309704327
032288: May 20 12:01:23.605 EDT: ISAKMP:(1112):purging node -472341339
R1-IPSEC1#
032289: May 20 12:01:33.441 EDT: IPSEC(key_engine): request timer fired: count 

= 2,
  (identity) local= 19.24.11.142:0, remote= 19.16.19.136:0, 
    local_proxy= 19.24.11.59/255.255.255.255/0/0 (type=1), 
    remote_proxy= 19.16.19.158/255.255.255.255/0/0 (type=1)
032290: May 20 12:01:33.605 EDT: ISAKMP:(1112):purging SA., sa=2A271B9C, 

delme=2A271B9C
R1-IPSEC1#
032291: May 20 12:01:53.597 EDT: ISAKMP:(1113):purging node 1341887425
032292: May 20 12:01:53.597 EDT: ISAKMP:(1113):purging node 1837926342
032293: May 20 12:01:53.601 EDT: ISAKMP:(1113):purging node -1713118288
R1-IPSEC1#
032294: May 20 12:02:03.601 EDT: ISAKMP:(1113):purging SA., sa=30038454, 

delme=30038454
R1-IPSEC1#
032295: May 20 12:02:21.009 EDT: %SEC-6-IPACCESSLOGP: list 101 permitted tcp 

19.24.11.9(47889) -> 0.0.0.0(22), 1 packet  

R1-IPSEC1#
R1-IPSEC1#
031993: May 20 12:00:33.442 EDT: IPSEC(sa_request): ,
  (key eng. msg.) OUTBOUND local= 19.24.11.142:500, remote= 

19.16.19.136:500, 
    local_proxy= 19.24.11.59/255.255.255.255/0/0 (type=1), 
    remote_proxy= 19.16.19.158/255.255.255.255/0/0 (type=1),
    protocol= ESP, transform= esp-aes 256 esp-sha-hmac  (Tunnel), 
    lifedur= 3600s and 4608000kb, 
    spi= 0x0(0), conn_id= 0, keysize= 256, flags= 0x0
031994: May 20 12:00:33.442 EDT: ISAKMP:(0): SA request profile is (NULL)
031995: May 20 12:00:33.442 EDT: ISAKMP: Created a peer struct for 

19.16.19.136, peer port 500
031996: May 20 12:00:33.442 EDT: ISAKMP: New peer created peer = 0x313D5AA8 

peer_handle = 0x80000049
031997: May 20 12:00:33.442 EDT: ISAKMP: Locking peer struct 0x313D5AA8, 

refcount 1 for isakmp_initiator
031998: May 20 12:00:33.446 EDT: ISAKMP: local port 500, remote port 500
031999: May 20 12:00:33.446 EDT: ISAKMP: set new node 0 to QM_IDLE      
032000: May 20 12:00:33.446 EDT: ISAKMP:(0):insert sa successfully sa = 

2A271B9C
032001: May 20 12:00:33.446 EDT: %CRYPTO-5-IKMP_AG_MODE_DISABLED: Unable to 

initiate or respond to Aggressive Mode while disabled
032002: May 20 12:00:33.446 EDT: ISAKMP:(0):Can not start Aggressive mode, 

trying Main mode.
032003: May 20 12:00:33.446 EDT: ISAKMP:(0):found peer pre-shared key matching 

19.16.19.136
032004: May 20 12:00:33.446 EDT: ISAKMP:(0): constructed NAT-T vendor-rfc3947 

ID
032005: May 20 12:00:33.446 EDT: ISAKMP:(0): constructed NAT-T vendor-07 ID
032006: May 20 12:00:33.446 EDT: ISAKMP:(0): constructed NAT-T vendor-03 ID
032007: May 20 12:00:33.446 EDT: ISAKMP:(0): constructed NAT-T vendor-02 ID
032008: May 20 12:00:33.446 EDT: ISAKMP:(0):Input = IKE_MESG_FROM_IPSEC, 

IKE_SA_REQ_MM
032009: May 20 12:00:33.446 EDT: ISAKMP:(0):Old State = IKE_READY  New State = 

IKE_I_MM1 

032010: May 20 12:00:33.446 EDT: ISAKMP:(0): beginning Main Mode exchange
032011: May 20 12:00:33.446 EDT: ISAKMP:(0): sending packet to 19.16.19.136 

my_port 500 peer_port 500 (I) MM_NO_STATE
032012: May 20 12:00:33.446 EDT: ISAKMP:(0):Sending an IKE IPv4 Packet.
032013: May 20 12:00:33.474 EDT: ISAKMP (0): received packet from 

19.16.19.136 dport 500 sport 500 Global (I) MM_NO_STATE
032014: May 20 12:00:33.474 EDT: ISAKMP:(0):Input = IKE_MESG_FROM_PEER, 

IKE_MM_EXCH
032015: May 20 12:00:33.474 EDT: ISAKMP:(0):Old State = IKE_I_MM1  New State = 

IKE_I_MM2 

032016: May 20 12:00:33.474 EDT: ISAKMP:(0): processing SA payload. message ID 

= 0
032017: May 20 12:00:33.474 EDT: ISAKMP:(0): processing vendor id payload
032018: May 20 12:00:33.474 EDT: ISAKMP:(0): vendor ID seems Unity/DPD but 

major 69 mismatch
032019: May 20 12:00:33.474 EDT: ISAKMP (0): vendor ID is NAT-T RFC 3947
032020: May 20 12:00:33.474 EDT: ISAKMP:(0): processing vendor id payload
032021: May 20 12:00:33.474 EDT: ISAKMP:(0): processing IKE frag vendor id 

payload
032022: May 20 12:00:33.474 EDT: ISAKMP:(0):Support for IKE Fragmentation not 

enabled
032023: May 20 12:00:33.474 EDT: ISAKMP:(0):found peer pre-shared key matching 

19.16.19.136
032024: May 20 12:00:33.478 EDT: ISAKMP:(0): local preshared key found
032025: May 20 12:00:33.478 EDT: ISAKMP : Scanning profiles for xauth ...
032026: May 20 12:00:33.478 EDT: ISAKMP:(0):Checking ISAKMP transform 1 

against priority 1 policy
032027: May 20 12:00:33.478 EDT: ISAKMP:      encryption 3DES-CBC
032028: May 20 12:00:33.478 EDT: ISAKMP:      hash SHA
032029: May 20 12:00:33.478 EDT: ISAKMP:      default group 2
032030: May 20 12:00:33.478 EDT: ISAKMP:      auth pre-share
032031: May 20 12:00:33.478 EDT: ISAKMP:      life type in seconds
032032: May 20 12:00:33.478 EDT: ISAKMP:      life duration (basic) of 3600
032033: May 20 12:00:33.478 EDT: ISAKMP:(0):atts are acceptable. Next payload 

is 0
032034: May 20 12:00:33.478 EDT: ISAKMP:(0):Acceptable atts:actual life: 0
032035: May 20 12:00:33.478 EDT: ISAKMP:(0):Acceptable atts:life: 0
032036: May 20 12:00:33.478 EDT: ISAKMP:(0):Basic life_in_seconds:3600
032037: May 20 12:00:33.478 EDT: ISAKMP:(0):Returning Actual lifetime: 3600
032038: May 20 12:00:33.478 EDT: ISAKMP:(0)::Started lifetime timer: 3600.

032039: May 20 12:00:33.478 EDT: ISAKMP:(0): processing vendor id payload
032040: May 20 12:00:33.478 EDT: ISAKMP:(0): vendor ID seems Unity/DPD but 

major 69 mismatch
032041: May 20 12:00:33.478 EDT: ISAKMP (0): vendor ID is NAT-T RFC 3947
032042: May 20 12:00:33.478 EDT: ISAKMP:(0): processing vendor id payload
032043: May 20 12:00:33.478 EDT: ISAKMP:(0): processing IKE frag vendor id 

payload
032044: May 20 12:00:33.478 EDT: ISAKMP:(0):Support for IKE Fragmentation not 

enabled
032045: May 20 12:00:33.478 EDT: ISAKMP:(0):Input = IKE_MESG_INTERNAL, 

IKE_PROCESS_MAIN_MODE
032046: May 20 12:00:33.478 EDT: ISAKMP:(0):Old State = IKE_I_MM2  New State = 

IKE_I_MM2 

032047: May 20 12:00:33.478 EDT: ISAKMP:(0): sending packet to 19.16.19.136 

my_port 500 peer_port 500 (I) MM_SA_SETUP
032048: May 20 12:00:33.478 EDT: ISAKMP:(0):Sending an IKE IPv4 Packet.
032049: May 20 12:00:33.478 EDT: ISAKMP:(0):Input = IKE_MESG_INTERNAL, 

IKE_PROCESS_COMPLETE
032050: May 20 12:00:33.478 EDT: ISAKMP:(0):Old State = IKE_I_MM2  New State = 

IKE_I_MM3 

032051: May 20 12:00:33.506 EDT: ISAKMP (0): received packet from 

19.16.19.136 dport 500 sport 500 Global (I) MM_SA_SETUP
032052: May 20 12:00:33.506 EDT: ISAKMP:(0):Input = IKE_MESG_FROM_PEER, 

IKE_MM_EXCH
032053: May 20 12:00:33.506 EDT: ISAKMP:(0):Old State = IKE_I_MM3  New State = 

IKE_I_MM4 

032054: May 20 12:00:33.510 EDT: ISAKMP:(0): processing KE payload. message ID 

= 0
032055: May 20 12:00:33.534 EDT: ISAKMP:(0): processing NONCE payload. message 

ID = 0
032056: May 20 12:00:33.534 EDT: ISAKMP:(0):found peer pre-shared key matching 

19.16.19.136
032057: May 20 12:00:33.534 EDT: ISAKMP:(1112): processing vendor id payload
032058: May 20 12:00:33.534 EDT: ISAKMP:(1112): vendor ID is Unity
032059: May 20 12:00:33.534 EDT: ISAKMP:(1112): processing vendor id payload
032060: May 20 12:00:33.534 EDT: ISAKMP:(1112): vendor ID seems Unity/DPD but 

major 245 mismatch
032061: May 20 12:00:33.534 EDT: ISAKMP:(1112): vendor ID is XAUTH
032062: May 20 12:00:33.534 EDT: ISAKMP:(1112): processing vendor id payload
032063: May 20 12:00:33.534 EDT: ISAKMP:(1112): speaking to another IOS box!
032064: May 20 12:00:33.534 EDT: ISAKMP:(1112): processing vendor id payload
032065: May 20 12:00:33.534 EDT: ISAKMP:(1112):vendor ID seems Unity/DPD but 

hash mismatch
032066: May 20 12:00:33.534 EDT: ISAKMP:received payload type 20
032067: May 20 12:00:33.534 EDT: ISAKMP (1112): His hash no match - this node 

outside NAT
032068: May 20 12:00:33.534 EDT: ISAKMP:received payload type 20
032069: May 20 12:00:33.534 EDT: ISAKMP (1112): No NAT Found for self or peer
032070: May 20 12:00:33.534 EDT: ISAKMP:(1112):Input = IKE_MESG_INTERNAL, 

IKE_PROCESS_MAIN_MODE
032071: May 20 12:00:33.534 EDT: ISAKMP:(1112):Old State = IKE_I_MM4  New 

State = IKE_I_MM4 

032072: May 20 12:00:33.538 EDT: ISAKMP:(1112):Send initial contact
032073: May 20 12:00:33.538 EDT: ISAKMP:(1112):SA is doing pre-shared key 

authentication using id type ID_IPV4_ADDR
032074: May 20 12:00:33.538 EDT: ISAKMP (1112): ID payload 
        next-payload : 8
        type         : 1 
        address      : 19.24.11.142 
        protocol     : 17 
        port         : 500 
        length       : 12
032075: May 20 12:00:33.538 EDT: ISAKMP:(1112):Total payload length: 12
032076: May 20 12:00:33.538 EDT: ISAKMP:(1112): sending packet to 

19.16.19.136 my_port 500 peer_port 500 (I) MM_KEY_EXCH
032077: May 20 12:00:33.538 EDT: ISAKMP:(1112):Sending an IKE IPv4 Packet.
032078: May 20 12:00:33.538 EDT: ISAKMP:(1112):Input = IKE_MESG_INTERNAL, 

IKE_PROCESS_COMPLETE
032079: May 20 12:00:33.538 EDT: ISAKMP:(1112):Old State = IKE_I_MM4  New 

State = IKE_I_MM5 

032080: May 20 12:00:33.566 EDT: ISAKMP (1112): received packet from 

19.16.19.136 dport 500 sport 500 Global (I) MM_KEY_EXCH
032081: May 20 12:00:33.566 EDT: ISAKMP:(1112): processing ID payload. message 

ID = 0
032082: May 20 12:00:33.566 EDT: ISAKMP (1112): ID payload 
        next-payload : 8
        type         : 1 
        address      : 19.16.19.136 
        protocol     : 17 
        port         : 0 
        length       : 12
032083: May 20 12:00:33.566 EDT: ISAKMP:(0):: peer matches *none* of the 

profiles
032084: May 20 12:00:33.566 EDT: ISAKMP:(1112): processing HASH payload. 

message ID = 0
032085: May 20 12:00:33.566 EDT: ISAKMP:received payload type 17
032086: May 20 12:00:33.566 EDT: ISAKMP:(1112): processing vendor id payload
032087: May 20 12:00:33.566 EDT: ISAKMP:(1112): vendor ID is DPD
032088: May 20 12:00:33.566 EDT: ISAKMP:(1112):SA authentication status:
        authenticated
032089: May 20 12:00:33.566 EDT: ISAKMP:(1112):SA has been authenticated with 

19.16.19.136
032090: May 20 12:00:33.566 EDT: ISAKMP: Trying to insert a peer 

19.24.11.142/19.16.19.136/500/,  and inserted successfully 313D5AA8.
032091: May 20 12:00:33.566 EDT: ISAKMP:(1112):Input = IKE_MESG_FROM_PEER, 

IKE_MM_EXCH
032092: May 20 12:00:33.566 EDT: ISAKMP:(1112):Old State = IKE_I_MM5  New 

State = IKE_I_MM6 

032093: May 20 12:00:33.566 EDT: ISAKMP:(1112):Input = IKE_MESG_INTERNAL, 

IKE_PROCESS_MAIN_MODE
032094: May 20 12:00:33.566 EDT: ISAKMP:(1112):Old State = IKE_I_MM6  New 

State = IKE_I_MM6 

032095: May 20 12:00:33.566 EDT: ISAKMP:(1112):Input = IKE_MESG_INTERNAL, 

IKE_PROCESS_COMPLETE
032096: May 20 12:00:33.566 EDT: ISAKMP:(1112):Old State = IKE_I_MM6  New 

State = IKE_P1_COMPLETE 

032097: May 20 12:00:33.570 EDT: ISAKMP:(1112):beginning Quick Mode exchange, 

M-ID of 3822625957
032098: May 20 12:00:33.570 EDT: ISAKMP:(1112):QM Initiator gets spi
032099: May 20 12:00:33.570 EDT: ISAKMP:(1112): sending packet to 

19.16.19.136 my_port 500 peer_port 500 (I) QM_IDLE      
032100: May 20 12:00:33.570 EDT: ISAKMP:(1112):Sending an IKE IPv4 Packet.
032101: May 20 12:00:33.570 EDT: ISAKMP:(1112):Node 3822625957, Input = 

IKE_MESG_INTERNAL, IKE_INIT_QM
032102: May 20 12:00:33.570 EDT: ISAKMP:(1112):Old State = IKE_QM_READY  New 

State = IKE_QM_I_QM1
032103: May 20 12:00:33.570 EDT: ISAKMP:(1112):Input = IKE_MESG_INTERNAL, 

IKE_PHASE1_COMPLETE
032104: May 20 12:00:33.570 EDT: ISAKMP:(1112):Old State = IKE_P1_COMPLETE  

New State = IKE_P1_COMPLETE 

032105: May 20 12:00:33.602 EDT: ISAKMP (1112): received packet from 

19.16.19.136 dport 500 sport 500 Global (I) QM_IDLE      
032106: May 20 12:00:33.602 EDT: ISAKMP: set new node 497356209 to QM_IDLE     

032107: May 20 12:00:33.602 EDT: ISAKMP:(1112): processing HASH payload. 

message ID = 497356209
032108: May 20 12:00:33.602 EDT: ISAKMP:(1112): processing NOTIFY 

PROPOSAL_NOT_CHOSEN protocol 3
        spi 0, message ID = 497356209, sa = 0x2A271B9C
032109: May 20 12:00:33.602 EDT: ISAKMP:(1112):deleting node 497356209 error 

FALSE reason "Informational (in) state 1"
032110: May 20 12:00:33.602 EDT: ISAKMP:(1112):Input = IKE_MESG_FROM_PEER, 

IKE_INFO_NOTIFY
032111: May 20 12:00:33.602 EDT: ISAKMP:(1112):Old State = IKE_P1_COMPLETE  

New State = IKE_P1_COMPLETE 

032112: May 20 12:00:33.602 EDT: ISAKMP (1112): received packet from 

19.16.19.136 dport 500 sport 500 Global (I) QM_IDLE      
032113: May 20 12:00:33.602 EDT: ISAKMP: set new node 309704327 to QM_IDLE     

032114: May 20 12:00:33.602 EDT: ISAKMP:(1112): processing HASH payload. 

message ID = 309704327
032115: May 20 12:00:33.602 EDT: ISAKMP:received payload type 18
032116: May 20 12:00:33.602 EDT: ISAKMP:(1112):Processing delete with reason 

payload
032117: May 20 12:00:33.602 EDT: ISAKMP:(1112):delete doi = 1
032118: May 20 12:00:33.602 EDT: ISAKMP:(1112):delete protocol id = 1
032119: May 20 12:00:33.602 EDT: ISAKMP:(1112):delete spi_size =  16
032120: May 20 12:00:33.602 EDT: ISAKMP:(1112):delete num spis = 1
032121: May 20 12:00:33.602 EDT: ISAKMP:(1112):delete_reason = 10
032122: May 20 12:00:33.606 EDT: ISAKMP:(1112): processing DELETE_WITH_REASON 

payload, message ID = 309704327, reason: Unknown delete reason!
032123: May 20 12:00:33.606 EDT: ISAKMP:(1112):peer does not do paranoid 

keepalives.

032124: May 20 12:00:33.606 EDT: ISAKMP:(1112):deleting SA reason "IKE SA 

Lifetime Exceeded" state (I) QM_IDLE       (peer 19.16.19.136)
032125: May 20 12:00:33.606 EDT: ISAKMP:(1112):deleting node 309704327 error 

FALSE reason "Informational (in) state 1"
032126: May 20 12:00:33.606 EDT: ISAKMP: set new node -1825006387 to QM_IDLE   

   
032127: May 20 12:00:33.606 EDT: ISAKMP:(1112): sending packet to 

19.16.19.136 my_port 500 peer_port 500 (I) QM_IDLE      
032128: May 20 12:00:33.606 EDT: ISAKMP:(1112):Sending an IKE IPv4 Packet.
032129: May 20 12:00:33.606 EDT: ISAKMP:(1112):purging node -1825006387
032130: May 20 12:00:33.606 EDT: ISAKMP:(1112):Input = IKE_MESG_INTERNAL, 

IKE_PHASE1_DEL
032131: May 20 12:00:33.606 EDT: ISAKMP:(1112):Old State = IKE_P1_COMPLETE  

New State = IKE_DEST_SA 

032132: May 20 12:00:33.606 EDT: ISAKMP:(1112):deleting SA reason "IKE SA 

Lifetime Exceeded" state (I) QM_IDLE       (peer 19.16.19.136) 
032133: May 20 12:00:33.606 EDT: ISAKMP: Unlocking peer struct 0x313D5AA8 for 

isadb_mark_sa_deleted(), count 0
032134: May 20 12:00:33.606 EDT: ISAKMP: Deleting peer node by peer_reap for 

19.16.19.136: 313D5AA8
032135: May 20 12:00:33.606 EDT: ISAKMP:(1112):deleting node -472341339 error 

FALSE reason "IKE deleted"
032136: May 20 12:00:33.606 EDT: ISAKMP:(1112):Input = IKE_MESG_FROM_PEER, 

IKE_MM_EXCH
032137: May 20 12:00:33.606 EDT: ISAKMP:(1112):Old State = IKE_DEST_SA  New 

State = IKE_DEST_SA 

R1-IPSEC1#
032138: May 20 12:00:33.606 EDT: IPSEC(key_engine): got a queue event with 1 

KMI message(s)
R1-IPSEC1#
032139: May 20 12:01:03.441 EDT: IPSEC(key_engine): request timer fired: count 

= 1,
  (identity) local= 19.24.11.142:0, remote= 19.16.19.136:0, 
    local_proxy= 19.24.11.59/255.255.255.255/0/0 (type=1), 
    remote_proxy= 19.16.19.158/255.255.255.255/0/0 (type=1)
032140: May 20 12:01:03.441 EDT: IPSEC(sa_request): ,
  (key eng. msg.) OUTBOUND local= 19.24.11.142:500, remote= 

19.16.19.136:500, 
    local_proxy= 19.24.11.59/255.255.255.255/0/0 (type=1), 
    remote_proxy= 19.16.19.158/255.255.255.255/0/0 (type=1),
    protocol= ESP, transform= esp-aes 256 esp-sha-hmac  (Tunnel), 
    lifedur= 3600s and 4608000kb, 
    spi= 0x0(0), conn_id= 0, keysize= 256, flags= 0x0
032141: May 20 12:01:03.441 EDT: ISAKMP:(0): SA request profile is (NULL)
032142: May 20 12:01:03.441 EDT: ISAKMP: Created a peer struct for 

19.16.19.136, peer port 500
032143: May 20 12:01:03.441 EDT: ISAKMP: New peer created peer = 0x313D3120 

peer_handle = 0x8000004B
032144: May 20 12:01:03.441 EDT: ISAKMP: Locking peer struct 0x313D3120, 

refcount 1 for isakmp_initiator
032145: May 20 12:01:03.441 EDT: ISAKMP: local port 500, remote port 500
032146: May 20 12:01:03.441 EDT: ISAKMP: set new node 0 to QM_IDLE      
032147: May 20 12:01:03.441 EDT: ISAKMP: Find a dup sa in the avl tree during 

calling isadb_insert sa = 30038454
032148: May 20 12:01:03.441 EDT: %CRYPTO-5-IKMP_AG_MODE_DISABLED: Unable to 

initiate or respond to Aggressive Mode while disabled
032149: May 20 12:01:03.441 EDT: ISAKMP:(0):Can not start Aggressive mode, 

trying Main mode.
032150: May 20 12:01:03.441 EDT: ISAKMP:(0):found peer pre-shared key matching 

19.16.19.136
032151: May 20 12:01:03.441 EDT: ISAKMP:(0): constructed NAT-T vendor-rfc3947 

ID
032152: May 20 12:01:03.441 EDT: ISAKMP:(0): constructed NAT-T vendor-07 ID
032153: May 20 12:01:03.441 EDT: ISAKMP:(0): constructed NAT-T vendor-03 ID
032154: May 20 12:01:03.441 EDT: ISAKMP:(0): constructed NAT-T vendor-02 ID
032155: May 20 12:01:03.441 EDT: ISAKMP:(0):Input = IKE_MESG_FROM_IPSEC, 

IKE_SA_REQ_MM
032156: May 20 12:01:03.441 EDT: ISAKMP:(0):Old State = IKE_READY  New State = 

IKE_I_MM1 

032157: May 20 12:01:03.441 EDT: ISAKMP:(0): beginning Main Mode exchange
032158: May 20 12:01:03.441 EDT: ISAKMP:(0): sending packet to 19.16.19.136 

my_port 500 peer_port 500 (I) MM_NO_STATE
032159: May 20 12:01:03.441 EDT: ISAKMP:(0):Sending an IKE IPv4 Packet.
032160: May 20 12:01:03.469 EDT: ISAKMP (0): received packet from 

19.16.19.136 dport 500 sport 500 Global (I) MM_NO_STATE
032161: May 20 12:01:03.469 EDT: ISAKMP:(0):Input = IKE_MESG_FROM_PEER, 

IKE_MM_EXCH
032162: May 20 12:01:03.469 EDT: ISAKMP:(0):Old State = IKE_I_MM1  New State = 

IKE_I_MM2 

032163: May 20 12:01:03.469 EDT: ISAKMP:(0): processing SA payload. message ID 

= 0
032164: May 20 12:01:03.469 EDT: ISAKMP:(0): processing vendor id payload
032165: May 20 12:01:03.469 EDT: ISAKMP:(0): vendor ID seems Unity/DPD but 

major 69 mismatch
032166: May 20 12:01:03.469 EDT: ISAKMP (0): vendor ID is NAT-T RFC 3947
032167: May 20 12:01:03.469 EDT: ISAKMP:(0): processing vendor id payload
032168: May 20 12:01:03.473 EDT: ISAKMP:(0): processing IKE frag vendor id 

payload
032169: May 20 12:01:03.473 EDT: ISAKMP:(0):Support for IKE Fragmentation not 

enabled
032170: May 20 12:01:03.473 EDT: ISAKMP:(0):found peer pre-shared key matching 

19.16.19.136
032171: May 20 12:01:03.473 EDT: ISAKMP:(0): local preshared key found
032172: May 20 12:01:03.473 EDT: ISAKMP : Scanning profiles for xauth ...
032173: May 20 12:01:03.473 EDT: ISAKMP:(0):Checking ISAKMP transform 1 

against priority 1 policy
032174: May 20 12:01:03.473 EDT: ISAKMP:      encryption 3DES-CBC
032175: May 20 12:01:03.473 EDT: ISAKMP:      hash SHA
032176: May 20 12:01:03.473 EDT: ISAKMP:      default group 2
032177: May 20 12:01:03.473 EDT: ISAKMP:      auth pre-share
032178: May 20 12:01:03.473 EDT: ISAKMP:      life type in seconds
032179: May 20 12:01:03.473 EDT: ISAKMP:      life duration (basic) of 3600
032180: May 20 12:01:03.473 EDT: ISAKMP:(0):atts are acceptable. Next payload 

is 0
032181: May 20 12:01:03.473 EDT: ISAKMP:(0):Acceptable atts:actual life: 0
032182: May 20 12:01:03.473 EDT: ISAKMP:(0):Acceptable atts:life: 0
032183: May 20 12:01:03.473 EDT: ISAKMP:(0):Basic life_in_seconds:3600
032184: May 20 12:01:03.473 EDT: ISAKMP:(0):Returning Actual lifetime: 3600
032185: May 20 12:01:03.473 EDT: ISAKMP:(0)::Started lifetime timer: 3600.

032186: May 20 12:01:03.473 EDT: ISAKMP:(0): processing vendor id payload
032187: May 20 12:01:03.473 EDT: ISAKMP:(0): vendor ID seems Unity/DPD but 

major 69 mismatch
032188: May 20 12:01:03.473 EDT: ISAKMP (0): vendor ID is NAT-T RFC 3947
032189: May 20 12:01:03.473 EDT: ISAKMP:(0): processing vendor id payload
032190: May 20 12:01:03.473 EDT: ISAKMP:(0): processing IKE frag vendor id 

payload
032191: May 20 12:01:03.473 EDT: ISAKMP:(0):Support for IKE Fragmentation not 

enabled
032192: May 20 12:01:03.473 EDT: ISAKMP:(0):Input = IKE_MESG_INTERNAL, 

IKE_PROCESS_MAIN_MODE
032193: May 20 12:01:03.473 EDT: ISAKMP:(0):Old State = IKE_I_MM2  New State = 

IKE_I_MM2 

032194: May 20 12:01:03.473 EDT: ISAKMP:(0): sending packet to 19.16.19.136 

my_port 500 peer_port 500 (I) MM_SA_SETUP
032195: May 20 12:01:03.473 EDT: ISAKMP:(0):Sending an IKE IPv4 Packet.
032196: May 20 12:01:03.473 EDT: ISAKMP:(0):Input = IKE_MESG_INTERNAL, 

IKE_PROCESS_COMPLETE
032197: May 20 12:01:03.473 EDT: ISAKMP:(0):Old State = IKE_I_MM2  New State = 

IKE_I_MM3 

032198: May 20 12:01:03.501 EDT: ISAKMP (0): received packet from 

19.16.19.136 dport 500 sport 500 Global (I) MM_SA_SETUP
032199: May 20 12:01:03.505 EDT: ISAKMP:(0):Input = IKE_MESG_FROM_PEER, 

IKE_MM_EXCH
032200: May 20 12:01:03.505 EDT: ISAKMP:(0):Old State = IKE_I_MM3  New State = 

IKE_I_MM4 

032201: May 20 12:01:03.505 EDT: ISAKMP:(0): processing KE payload. message ID 

= 0
032202: May 20 12:01:03.529 EDT: ISAKMP:(0): processing NONCE payload. message 

ID = 0
032203: May 20 12:01:03.529 EDT: ISAKMP:(0):found peer pre-shared key matching 

19.16.19.136
032204: May 20 12:01:03.529 EDT: ISAKMP:(1113): processing vendor id payload
032205: May 20 12:01:03.529 EDT: ISAKMP:(1113): vendor ID is Unity
032206: May 20 12:01:03.529 EDT: ISAKMP:(1113): processing vendor id payload
032207: May 20 12:01:03.529 EDT: ISAKMP:(1113): vendor ID seems Unity/DPD but 

major 9 mismatch
032208: May 20 12:01:03.529 EDT: ISAKMP:(1113): vendor ID is XAUTH
032209: May 20 12:01:03.529 EDT: ISAKMP:(1113): processing vendor id payload
032210: May 20 12:01:03.529 EDT: ISAKMP:(1113): speaking to another IOS box!
032211: May 20 12:01:03.529 EDT: ISAKMP:(1113): processing vendor id payload
032212: May 20 12:01:03.529 EDT: ISAKMP:(1113):vendor ID seems Unity/DPD but 

hash mismatch
032213: May 20 12:01:03.529 EDT: ISAKMP:received payload type 20
032214: May 20 12:01:03.529 EDT: ISAKMP (1113): His hash no match - this node 

outside NAT
032215: May 20 12:01:03.529 EDT: ISAKMP:received payload type 20
032216: May 20 12:01:03.529 EDT: ISAKMP (1113): No NAT Found for self or peer
032217: May 20 12:01:03.529 EDT: ISAKMP:(1113):Input = IKE_MESG_INTERNAL, 

IKE_PROCESS_MAIN_MODE
032218: May 20 12:01:03.529 EDT: ISAKMP:(1113):Old State = IKE_I_MM4  New 

State = IKE_I_MM4 

032219: May 20 12:01:03.533 EDT: ISAKMP:(1113):Send initial contact
032220: May 20 12:01:03.533 EDT: ISAKMP:(1113):SA is doing pre-shared key 

authentication using id type ID_IPV4_ADDR
032221: May 20 12:01:03.533 EDT: ISAKMP (1113): ID payload 
        next-payload : 8
        type         : 1 
        address      : 19.24.11.142 
        protocol     : 17 
        port         : 500 
        length       : 12
032222: May 20 12:01:03.533 EDT: ISAKMP:(1113):Total payload length: 12
032223: May 20 12:01:03.533 EDT: ISAKMP:(1113): sending packet to 

19.16.19.136 my_port 500 peer_port 500 (I) MM_KEY_EXCH
032224: May 20 12:01:03.533 EDT: ISAKMP:(1113):Sending an IKE IPv4 Packet.
032225: May 20 12:01:03.533 EDT: ISAKMP:(1113):Input = IKE_MESG_INTERNAL, 

IKE_PROCESS_COMPLETE
032226: May 20 12:01:03.533 EDT: ISAKMP:(1113):Old State = IKE_I_MM4  New 

State = IKE_I_MM5 

032227: May 20 12:01:03.561 EDT: ISAKMP (1113): received packet from 

19.16.19.136 dport 500 sport 500 Global (I) MM_KEY_EXCH
032228: May 20 12:01:03.561 EDT: ISAKMP:(1113): processing ID payload. message 

ID = 0
032229: May 20 12:01:03.561 EDT: ISAKMP (1113): ID payload 
        next-payload : 8
        type         : 1 
        address      : 19.16.19.136 
        protocol     : 17 
        port         : 0 
        length       : 12
032230: May 20 12:01:03.561 EDT: ISAKMP:(0):: peer matches *none* of the 

profiles
032231: May 20 12:01:03.561 EDT: ISAKMP:(1113): processing HASH payload. 

message ID = 0
032232: May 20 12:01:03.561 EDT: ISAKMP:received payload type 17
032233: May 20 12:01:03.561 EDT: ISAKMP:(1113): processing vendor id payload
032234: May 20 12:01:03.561 EDT: ISAKMP:(1113): vendor ID is DPD
032235: May 20 12:01:03.561 EDT: ISAKMP:(1113):SA authentication status:
        authenticated
032236: May 20 12:01:03.561 EDT: ISAKMP:(1113):SA has been authenticated with 

19.16.19.136
032237: May 20 12:01:03.561 EDT: ISAKMP: Trying to insert a peer 

19.24.11.142/19.16.19.136/500/,  and inserted successfully 313D3120.
032238: May 20 12:01:03.561 EDT: ISAKMP:(1113):Input = IKE_MESG_FROM_PEER, 

IKE_MM_EXCH
032239: May 20 12:01:03.561 EDT: ISAKMP:(1113):Old State = IKE_I_MM5  New 

State = IKE_I_MM6 

032240: May 20 12:01:03.561 EDT: ISAKMP:(1113):Input = IKE_MESG_INTERNAL, 

IKE_PROCESS_MAIN_MODE
032241: May 20 12:01:03.561 EDT: ISAKMP:(1113):Old State = IKE_I_MM6  New 

State = IKE_I_MM6 

032242: May 20 12:01:03.561 EDT: ISAKMP:(1113):Input = IKE_MESG_INTERNAL, 

IKE_PROCESS_COMPLETE
032243: May 20 12:01:03.561 EDT: ISAKMP:(1113):Old State = IKE_I_MM6  New 

State = IKE_P1_COMPLETE 

032244: May 20 12:01:03.561 EDT: ISAKMP:(1113):beginning Quick Mode exchange, 

M-ID of 2581849008
032245: May 20 12:01:03.565 EDT: ISAKMP:(1113):QM Initiator gets spi
032246: May 20 12:01:03.565 EDT: ISAKMP:(1113): sending packet to 

19.16.19.136 my_port 500 peer_port 500 (I) QM_IDLE      
032247: May 20 12:01:03.565 EDT: ISAKMP:(1113):Sending an IKE IPv4 Packet.
032248: May 20 12:01:03.565 EDT: ISAKMP:(1113):Node 2581849008, Input = 

IKE_MESG_INTERNAL, IKE_INIT_QM
032249: May 20 12:01:03.565 EDT: ISAKMP:(1113):Old State = IKE_QM_READY  New 

State = IKE_QM_I_QM1
032250: May 20 12:01:03.565 EDT: ISAKMP:(1113):Input = IKE_MESG_INTERNAL, 

IKE_PHASE1_COMPLETE
032251: May 20 12:01:03.565 EDT: ISAKMP:(1113):Old State = IKE_P1_COMPLETE  

New State = IKE_P1_COMPLETE 

032252: May 20 12:01:03.597 EDT: ISAKMP (1113): received packet from 

19.16.19.136 dport 500 sport 500 Global (I) QM_IDLE      
032253: May 20 12:01:03.597 EDT: ISAKMP: set new node 1341887425 to QM_IDLE    

  
032254: May 20 12:01:03.597 EDT: ISAKMP:(1113): processing HASH payload. 

message ID = 1341887425
032255: May 20 12:01:03.597 EDT: ISAKMP:(1113): processing NOTIFY 

PROPOSAL_NOT_CHOSEN protocol 3
        spi 0, message ID = 1341887425, sa = 0x30038454
032256: May 20 12:01:03.597 EDT: ISAKMP:(1113):deleting node 1341887425 error 

FALSE reason "Informational (in) state 1"
032257: May 20 12:01:03.597 EDT: ISAKMP:(1113):Input = IKE_MESG_FROM_PEER, 

IKE_INFO_NOTIFY
032258: May 20 12:01:03.597 EDT: ISAKMP:(1113):Old State = IKE_P1_COMPLETE  

New State = IKE_P1_COMPLETE 

032259: May 20 12:01:03.597 EDT: ISAKMP (1113): received packet from 

19.16.19.136 dport 500 sport 500 Global (I) QM_IDLE      
032260: May 20 12:01:03.597 EDT: ISAKMP: set new node 1837926342 to QM_IDLE    

  
032261: May 20 12:01:03.597 EDT: ISAKMP:(1113): processing HASH payload. 

message ID = 1837926342
032262: May 20 12:01:03.597 EDT: ISAKMP:received payload type 18
032263: May 20 12:01:03.597 EDT: ISAKMP:(1113):Processing delete with reason 

payload
032264: May 20 12:01:03.597 EDT: ISAKMP:(1113):delete doi = 1
032265: May 20 12:01:03.597 EDT: ISAKMP:(1113):delete protocol id = 1
032266: May 20 12:01:03.597 EDT: ISAKMP:(1113):delete spi_size =  16
032267: May 20 12:01:03.597 EDT: ISAKMP:(1113):delete num spis = 1
032268: May 20 12:01:03.597 EDT: ISAKMP:(1113):delete_reason = 10
032269: May 20 12:01:03.597 EDT: ISAKMP:(1113): processing DELETE_WITH_REASON 

payload, message ID = 1837926342, reason: Unknown delete reason!
032270: May 20 12:01:03.597 EDT: ISAKMP:(1113):peer does not do paranoid 

keepalives.

032271: May 20 12:01:03.597 EDT: ISAKMP:(1113):deleting SA reason "IKE SA 

Lifetime Exceeded" state (I) QM_IDLE       (peer 19.16.19.136)
032272: May 20 12:01:03.597 EDT: ISAKMP:(1113):deleting node 1837926342 error 

FALSE reason "Informational (in) state 1"
032273: May 20 12:01:03.601 EDT: ISAKMP: set new node -577632662 to QM_IDLE    

  
032274: May 20 12:01:03.601 EDT: ISAKMP:(1113): sending packet to 

19.16.19.136 my_port 500 peer_port 500 (I) QM_IDLE      
032275: May 20 12:01:03.601 EDT: ISAKMP:(1113):Sending an IKE IPv4 Packet.
032276: May 20 12:01:03.601 EDT: ISAKMP:(1113):purging node -577632662
032277: May 20 12:01:03.601 EDT: ISAKMP:(1113):Input = IKE_MESG_INTERNAL, 

IKE_PHASE1_DEL
032278: May 20 12:01:03.601 EDT: ISAKMP:(1113):Old State = IKE_P1_COMPLETE  

New State = IKE_DEST_SA 

032279: May 20 12:01:03.601 EDT: ISAKMP:(1113):deleting SA reason "IKE SA 

Lifetime Exceeded" state (I) QM_IDLE       (peer 19.16.19.136) 
032280: May 20 12:01:03.601 EDT: ISAKMP: Unlocking peer struct 0x313D3120 for 

isadb_mark_sa_deleted(), count 0
032281: May 20 12:01:03.601 EDT: ISAKMP: Deleting peer node by peer_reap for 

19.16.19.136: 313D3120
032282: May 20 12:01:03.601 EDT: ISAKMP:(1113):deleting node -1713118288 error 

FALSE reason "IKE deleted"
032283: May 20 12:01:03.601 EDT: ISAKMP:(1113):Input = IKE_MESG_FROM_PEER, 

IKE_MM_EXCH
032284: May 20 12:01:03.601 EDT: ISAKMP:(1113):Old State = IKE_DEST_SA  New 

State = IKE_DEST_SA 

R1-IPSEC1#
032285: May 20 12:01:03.601 EDT: IPSEC(key_engine): got a queue event with 1 

KMI message(s)
R1-IPSEC1#
032286: May 20 12:01:23.601 EDT: ISAKMP:(1112):purging node 497356209
032287: May 20 12:01:23.605 EDT: ISAKMP:(1112):purging node 309704327
032288: May 20 12:01:23.605 EDT: ISAKMP:(1112):purging node -472341339
R1-IPSEC1#
032289: May 20 12:01:33.441 EDT: IPSEC(key_engine): request timer fired: count 

= 2,
  (identity) local= 19.24.11.142:0, remote= 19.16.19.136:0, 
    local_proxy= 19.24.11.59/255.255.255.255/0/0 (type=1), 
    remote_proxy= 19.16.19.158/255.255.255.255/0/0 (type=1)
032290: May 20 12:01:33.605 EDT: ISAKMP:(1112):purging SA., sa=2A271B9C, 

delme=2A271B9C
R1-IPSEC1#
032291: May 20 12:01:53.597 EDT: ISAKMP:(1113):purging node 1341887425
032292: May 20 12:01:53.597 EDT: ISAKMP:(1113):purging node 1837926342
032293: May 20 12:01:53.601 EDT: ISAKMP:(1113):purging node -1713118288
R1-IPSEC1#
032294: May 20 12:02:03.601 EDT: ISAKMP:(1113):purging SA., sa=30038454, 

delme=30038454

R1-IPSEC1#



Since remote site is customer site which the configuration is not able to check. But customer confirmed the vpn tunnel is able to built when initiated from their end. It seems phase 1 and phase 2 configuration should be right since tunnel can be built.


There is similar post regarding this issue "Cisco IOS VPN Error: Peer Does Not Do Paranoid Keepalives"

Here are some good explanation about the error message "peer does not do paranoid keepalives"

I see this router going through each of the MM states.
IKE_I_MM2 –> IKE_I_MM3 –> IKE_I_MM4 –> IKE_I_MM5 –> IKE_I_MM6 –> QM_IDLE
This looks great. It’s completing the entire Phase one key exchange process. So I know nothing is wrong with my ISAKMP settings.
Shortly after it becomes QM_IDLE it starts deleting SAs and says:
ISAKMP:(9577):peer does not do paranoid keepalives.

Basically, after P1 completed, P2 failed will have following reasons:

1. PFS configuration is not consistent on both ends
2. IPSEC SA life time is not same on both ends

In my case, it was PFS group number did not matched in both end. Once group number corrected, tunnel was able to build without problem.



Wednesday, April 27, 2016

Troubleshooting Cisco IPSec Site to Site VPN - "IPSec policy invalidated proposal with error 32"

There was vpn set up recently using Cisco Router to connect Check Point firewall. It seems quite simple task but "IPSec policy invalidated proposal with error 32" made me go through all troubleshooting steps which shows below.

Other examples to troubleshoot IPSec VPN issue:


    Topology is quite simple:



    Remote Site is using Check Point Firewall do to vpn gateway, and it has been used to all kinds of vpn connection.

    Here is my original vpn configuration.

    interface GigabitEthernet0/0
     ip address 19.24.11.142 255.255.255.0
     duplex auto
     speed auto
     crypto map vpn



    crypto isakmp policy 1
     encr 3des
     authentication pre-share
     group 2
     lifetime 3600
    crypto isakmp key cisco123 address 19.9.17.1
    crypto isakmp aggressive-mode disable
    !
    !
    crypto ipsec transform-set VPN-Set ah-sha-hmac esp-3des
    !
    crypto map vpn 10 ipsec-isakmp
     description VPN VPN
     set peer 198.96.178.1
     set transform-set VPN-Set
     set pfs group2
     match address VPN-VPN


     ip access-list extended VPN-VPN
     permit ip host 19.24.11.53 host 19.9.17.41
     permit ip host 19.24.11.245 host 19.9.17.41

    Check Point Firewall is at remote and I am not managing. From the collected information, here is Check Point configuration looks like:
    • Center gateways: the object representing the Check Point enforcement point
    • Satellite gateways: the object representing the Cisco router - CiscoVPN
    • Encryption:
      • Encryption Method: IKEv1 Only
      • Encryption Suite: Custom with the following properties
      • IKE (Phase 1) Properties
      • Perform key exchange encryption with: 3Des
      • Perform data integrity with: SHA-1
      • IPSec (Phase 2) Properties
      • Perform IPSec data encryption with: 3Des
      • Perform data integrity with: SHA-1
    • Tunnel Management: VPN Tunnel sharing: One VPN tunnel per subnet pair
    • Advanced settings
      • VPN Routing: To center only
      • Shared Secret: Use only Shared Secret for all external members, then add the shared secret to CiscoVPN
      • Advanced VPN Properties:IKE (Phase 1): Use Diffie-Helman Group: Group 2


    Looks like quite straighforward and it should not has any surprise.

    Unfortunately the tunnel did not come up as expected. I got following debugging messages:



    000421: Apr 26 21:40:20.568 EDT: ISAKMP (0): received packet from 19.9.17.1 dport 500 sport 500 Global (N) NEW SA
    000422: Apr 26 21:40:20.568 EDT: ISAKMP: Created a peer struct for 19.9.17.1, peer port 500
    000423: Apr 26 21:40:20.568 EDT: ISAKMP: New peer created peer = 0x2B149B28 peer_handle = 0x8000000D
    000424: Apr 26 21:40:20.568 EDT: ISAKMP: Locking peer struct 0x2B149B28, refcount 1 for crypto_isakmp_process_block
    000425: Apr 26 21:40:20.568 EDT: ISAKMP: local port 500, remote port 500
    000426: Apr 26 21:40:20.568 EDT: ISAKMP:(0):insert sa successfully sa = 2A25BEAC
    000427: Apr 26 21:40:20.568 EDT: ISAKMP:(0):Input = IKE_MESG_FROM_PEER, IKE_MM_EXCH
    000428: Apr 26 21:40:20.568 EDT: ISAKMP:(0):Old State = IKE_READY  New State = IKE_R_MM1

    000429: Apr 26 21:40:20.568 EDT: ISAKMP:(0): processing SA payload. message ID = 0
    000430: Apr 26 21:40:20.568 EDT: ISAKMP:(0): processing vendor id payload
    000431: Apr 26 21:40:20.568 EDT: ISAKMP:(0): vendor ID seems Unity/DPD but major 175 mismatch
    000432: Apr 26 21:40:20.568 EDT: ISAKMP:(0): processing vendor id payload
    000433: Apr 26 21:40:20.568 EDT: ISAKMP:(0): vendor ID seems Unity/DPD but major 194 mismatch
    000434: Apr 26 21:40:20.568 EDT: ISAKMP:(0):found peer pre-shared key matching 19.9.17.1
    000435: Apr 26 21:40:20.568 EDT: ISAKMP:(0): local preshared key found
    000436: Apr 26 21:40:20.568 EDT: ISAKMP : Scanning profiles for xauth ...
    000437: Apr 26 21:40:20.568 EDT: ISAKMP:(0):Checking ISAKMP transform 1 against priority 1 policy
    000438: Apr 26 21:40:20.568 EDT: ISAKMP:      encryption 3DES-CBC
    000439: Apr 26 21:40:20.568 EDT: ISAKMP:      hash SHA
    000440: Apr 26 21:40:20.568 EDT: ISAKMP:      auth pre-share
    000441: Apr 26 21:40:20.568 EDT: ISAKMP:      default group 2
    000442: Apr 26 21:40:20.568 EDT: ISAKMP:      life type in seconds
    000443: Apr 26 21:40:20.568 EDT: ISAKMP:      life duration (VPI) of  0x0 0x0 0xE 0x10
    000444: Apr 26 21:40:20.568 EDT: ISAKMP:(0):atts are acceptable. Next payload is 0
    000445: Apr 26 21:40:20.568 EDT: ISAKMP:(0):Acceptable atts:actual life: 0
    000446: Apr 26 21:40:20.568 EDT: ISAKMP:(0):Acceptable atts:life: 0
    000447: Apr 26 21:40:20.568 EDT: ISAKMP:(0):Fill atts in sa vpi_length:4
    000448: Apr 26 21:40:20.568 EDT: ISAKMP:(0):Fill atts in sa life_in_seconds:3600
    000449: Apr 26 21:40:20.568 EDT: ISAKMP:(0):Returning Actual lifetime: 3600
    000450: Apr 26 21:40:20.568 EDT: ISAKMP:(0)::Started lifetime timer: 3600.

    000451: Apr 26 21:40:20.588 EDT: ISAKMP:(0): processing vendor id payload
    000452: Apr 26 21:40:20.588 EDT: ISAKMP:(0): vendor ID seems Unity/DPD but major 175 mismatch
    000453: Apr 26 21:40:20.588 EDT: ISAKMP:(0): processing vendor id payload
    000454: Apr 26 21:40:20.588 EDT: ISAKMP:(0): vendor ID seems Unity/DPD but major 194 mismatch
    000455: Apr 26 21:40:20.588 EDT: ISAKMP:(0):Input = IKE_MESG_INTERNAL, IKE_PROCESS_MAIN_MODE
    000456: Apr 26 21:40:20.588 EDT: ISAKMP:(0):Old State = IKE_R_MM1  New State = IKE_R_MM1

    000457: Apr 26 21:40:20.588 EDT: ISAKMP:(0): sending packet to 19.9.17.1 my_port 500 peer_port 500 (R) MM_SA_SETUP
    000458: Apr 26 21:40:20.588 EDT: ISAKMP:(0):Sending an IKE IPv4 Packet.
    000459: Apr 26 21:40:20.588 EDT: ISAKMP:(0):Input = IKE_MESG_INTERNAL, IKE_PROCESS_COMPLETE
    000460: Apr 26 21:40:20.588 EDT: ISAKMP:(0):Old State = IKE_R_MM1  New State = IKE_R_MM2

    000461: Apr 26 21:40:20.616 EDT: ISAKMP (0): received packet from 19.9.17.1 dport 500 sport 500 Global (R) MM_SA_SETUP
    000462: Apr 26 21:40:20.616 EDT: ISAKMP:(0):Input = IKE_MESG_FROM_PEER, IKE_MM_EXCH
    000463: Apr 26 21:40:20.616 EDT: ISAKMP:(0):Old State = IKE_R_MM2  New State = IKE_R_MM3

    000464: Apr 26 21:40:20.620 EDT: ISAKMP:(0): processing KE payload. message ID = 0
    000465: Apr 26 21:40:20.644 EDT: ISAKMP:(0): processing NONCE payload. message ID = 0
    000466: Apr 26 21:40:20.644 EDT: ISAKMP:(0):found peer pre-shared key matching 19.9.17.1
    000467: Apr 26 21:40:20.644 EDT: ISAKMP:(1006):Input = IKE_MESG_INTERNAL, IKE_PROCESS_MAIN_MODE
    000468: Apr 26 21:40:20.644 EDT: ISAKMP:(1006):Old State = IKE_R_MM3  New State = IKE_R_MM3

    000469: Apr 26 21:40:20.644 EDT: ISAKMP:(1006): sending packet to 19.9.17.1 my_port 500 peer_port 500 (R) MM_KEY_EXCH
    000470: Apr 26 21:40:20.644 EDT: ISAKMP:(1006):Sending an IKE IPv4 Packet.
    000471: Apr 26 21:40:20.648 EDT: ISAKMP:(1006):Input = IKE_MESG_INTERNAL, IKE_PROCESS_COMPLETE
    000472: Apr 26 21:40:20.648 EDT: ISAKMP:(1006):Old State = IKE_R_MM3  New State = IKE_R_MM4

    000473: Apr 26 21:40:20.676 EDT: ISAKMP (1006): received packet from 19.9.17.1 dport 500 sport 500 Global (R) MM_KEY_EXCH
    000474: Apr 26 21:40:20.676 EDT: ISAKMP:(1006):Input = IKE_MESG_FROM_PEER, IKE_MM_EXCH
    000475: Apr 26 21:40:20.676 EDT: ISAKMP:(1006):Old State = IKE_R_MM4  New State = IKE_R_MM5

    000476: Apr 26 21:40:20.680 EDT: ISAKMP:(1006): processing ID payload. message ID = 0
    000477: Apr 26 21:40:20.680 EDT: ISAKMP (1006): ID payload
            next-payload : 8
            type         : 1
            address      : 19.9.17.1
            protocol     : 0
            port         : 0
            length       : 12
    000478: Apr 26 21:40:20.680 EDT: ISAKMP:(0):: peer matches *none* of the profiles
    000479: Apr 26 21:40:20.680 EDT: ISAKMP:(1006): processing HASH payload. message ID = 0
    000480: Apr 26 21:40:20.680 EDT: ISAKMP:(1006):SA authentication status:
            authenticated
    000481: Apr 26 21:40:20.680 EDT: ISAKMP:(1006):SA has been authenticated with 19.9.17.1
    000482: Apr 26 21:40:20.680 EDT: ISAKMP: Trying to insert a peer 19.24.11.142/19.9.17.1/500/,  and inserted successfully 2B149B28.
    000483: Apr 26 21:40:20.680 EDT: ISAKMP:(1006):Input = IKE_MESG_INTERNAL, IKE_PROCESS_MAIN_MODE
    000484: Apr 26 21:40:20.680 EDT: ISAKMP:(1006):Old State = IKE_R_MM5  New State = IKE_R_MM5

    000485: Apr 26 21:40:20.680 EDT: ISAKMP:(1006):SA is doing pre-shared key authentication using id type ID_IPV4_ADDR
    000486: Apr 26 21:40:20.680 EDT: ISAKMP (1006): ID payload
            next-payload : 8
            type         : 1
            address      : 19.24.11.142
            protocol     : 17
            port         : 500
            length       : 12
    000487: Apr 26 21:40:20.680 EDT: ISAKMP:(1006):Total payload length: 12
    000488: Apr 26 21:40:20.680 EDT: ISAKMP:(1006): sending packet to 19.9.17.1 my_port 500 peer_port 500 (R) MM_KEY_EXCH
    000489: Apr 26 21:40:20.680 EDT: ISAKMP:(1006):Sending an IKE IPv4 Packet.
    000490: Apr 26 21:40:20.680 EDT: ISAKMP:(1006):Input = IKE_MESG_INTERNAL, IKE_PROCESS_COMPLETE
    000491: Apr 26 21:40:20.680 EDT: ISAKMP:(1006):Old State = IKE_R_MM5  New State = IKE_P1_COMPLETE

    000492: Apr 26 21:40:20.680 EDT: ISAKMP:(1006):Input = IKE_MESG_INTERNAL, IKE_PHASE1_COMPLETE
    000493: Apr 26 21:40:20.680 EDT: ISAKMP:(1006):Old State = IKE_P1_COMPLETE  New State = IKE_P1_COMPLETE

    000494: Apr 26 21:40:20.708 EDT: ISAKMP (1006): received packet from 19.9.17.1 dport 500 sport 500 Global (R) QM_IDLE     
    000495: Apr 26 21:40:20.708 EDT: ISAKMP: set new node 565784744 to QM_IDLE     
    000496: Apr 26 21:40:20.708 EDT: ISAKMP:(1006): processing HASH payload. message ID = 565784744
    000497: Apr 26 21:40:20.708 EDT: ISAKMP:(1006): processing SA payload. message ID = 565784744
    000498: Apr 26 21:40:20.708 EDT: ISAKMP:(1006):Checking IPSec proposal 1
    000499: Apr 26 21:40:20.708 EDT: ISAKMP: transform 1, ESP_3DES
    000500: Apr 26 21:40:20.708 EDT: ISAKMP:   attributes in transform:
    000501: Apr 26 21:40:20.708 EDT: ISAKMP:      group is 2
    000502: Apr 26 21:40:20.708 EDT: ISAKMP:      SA life type in seconds
    000503: Apr 26 21:40:20.708 EDT: ISAKMP:      SA life duration (VPI) of  0x0 0x0 0xE 0x10
    000504: Apr 26 21:40:20.708 EDT: ISAKMP:      authenticator is HMAC-SHA
    000505: Apr 26 21:40:20.708 EDT: ISAKMP:      encaps is 1 (Tunnel)
    000506: Apr 26 21:40:20.708 EDT: ISAKMP:(1006):atts are acceptable.
    000507: Apr 26 21:40:20.708 EDT: ISAKMP:(1006): IPSec policy invalidated proposal with error 32
    000508: Apr 26 21:40:20.708 EDT: ISAKMP:(1006): phase 2 SA policy not acceptable! (local 19.24.11.142 remote 19.9.17.1)
    000509: Apr 26 21:40:20.708 EDT: ISAKMP: set new node -1495049782 to QM_IDLE     
    000510: Apr 26 21:40:20.708 EDT: ISAKMP:(1006):Sending NOTIFY PROPOSAL_NOT_CHOSEN protocol 3
            spi 820964128, message ID = 2799917514
    000511: Apr 26 21:40:20.708 EDT: ISAKMP:(1006): sending packet to 19.9.17.1 my_port 500 peer_port 500 (R) QM_IDLE     
    000512: Apr 26 21:40:20.708 EDT: ISAKMP:(1006):Sending an IKE IPv4 Packet.
    000513: Apr 26 21:40:20.708 EDT: ISAKMP:(1006):purging node -1495049782
    000514: Apr 26 21:40:20.708 EDT: ISAKMP:(1006):deleting node 565784744 error TRUE reason "QM rejected"
    000515: Apr 26 21:40:20.708 EDT: ISAKMP:(1006):Node 565784744, Input = IKE_MESG_FROM_PEER, IKE_QM_EXCH
    000516: Apr 26 21:40:20.708 EDT: ISAKMP:(1006):Old State = IKE_QM_READY  New State = IKE_QM_READY

    R-IPSEC1#show crypto isakmp sa
    IPv4 Crypto ISAKMP SA
    dst             src             state          conn-id status
    19.24.11.142 19.9.17.1    QM_IDLE           1006 ACTIVE
     
    There is "IPSec policy invalidated proposal with error 32". It is not having enough details for me to conclude the cause. L2L VPN TroubleShooting :"IPSec policy invalidated proposal with error 32" situation is not applying to me.

    After second thought, I am thinking it may relates to access-list mis-mirrored on both end since that was common issue happened between Check Point and Cisco. Remote site vpn may use wider vpn encryption domain such as /24 network. But I am using /32 instead. So I changed my access-list to following:

    R-IPSEC1(config-ext-nacl)#do sh access-list VPN-VPN
    Extended IP access list VPN-VPN
        50 permit ip host 19.24.11.245 19.9.17.0 0.0.0.255
        60 permit ip host 19.24.11.53 19.9.17.0 0.0.0.255


    Got a little better result but still similar messages.

    001319: Apr 26 22:26:41.310 EDT: ISAKMP:(1010):Input = IKE_MESG_INTERNAL, IKE_PHASE1_COMPLETE
    001320: Apr 26 22:26:41.310 EDT: ISAKMP:(1010):Old State = IKE_P1_COMPLETE  New State = IKE_P1_COMPLETE

    001321: Apr 26 22:26:41.362 EDT: ISAKMP (1010): received packet from 19.9.17.1 dport 500 sport 500 Global (R) QM_IDLE     
    001322: Apr 26 22:26:41.362 EDT: ISAKMP: set new node 1351243089 to QM_IDLE     
    001323: Apr 26 22:26:41.362 EDT: ISAKMP:(1010): processing HASH payload. message ID = 1351243089
    001324: Apr 26 22:26:41.362 EDT: ISAKMP:(1010): processing SA payload. message ID = 1351243089
    001325: Apr 26 22:26:41.362 EDT: ISAKMP:(1010):Checking IPSec proposal 1
    001326: Apr 26 22:26:41.362 EDT: ISAKMP: transform 1, ESP_3DES
    001327: Apr 26 22:26:41.362 EDT: ISAKMP:   attributes in transform:
    001328: Apr 26 22:26:41.362 EDT: ISAKMP:      group is 2
    001329: Apr 26 22:26:41.362 EDT: ISAKMP:      SA life type in seconds
    001330: Apr 26 22:26:41.362 EDT: ISAKMP:      SA life duration (VPI) of  0x0 0x0 0xE 0x10
    001331: Apr 26 22:26:41.362 EDT: ISAKMP:      authenticator is HMAC-SHA
    001332: Apr 26 22:26:41.362 EDT: ISAKMP:      encaps is 1 (Tunnel)
    001333: Apr 26 22:26:41.362 EDT: ISAKMP:(1010):atts are acceptable.
    001334: Apr 26 22:26:41.366 EDT: IPSEC(validate_proposal_request): proposal part #1
    001335: Apr 26 22:26:41.366 EDT: IPSEC(validate_proposal_request): proposal part #1,
      (key eng. msg.) INBOUND local= 19.24.11.142:0, remote= 19.9.17.1:0,
        local_proxy= 19.24.11.245/255.255.255.255/0/0 (type=1),
        remote_proxy= 198.96.176.41/255.255.255.255/0/0 (type=1),
        protocol= ESP, transform= NONE  (Tunnel),
        lifedur= 0s and 0kb,
        spi= 0x0(0), conn_id= 0, keysize= 0, flags= 0x0
    001336: Apr 26 22:26:41.366 EDT: IPSEC(ipsec_process_proposal): proxy identities not supported
    001337: Apr 26 22:26:41.366 EDT: ISAKMP:(1010): IPSec policy invalidated proposal with error 32
    001338: Apr 26 22:26:41.366 EDT: ISAKMP:(1010): phase 2 SA policy not acceptable! (local 19.24.11.142 remote 19.9.17.1)
    001339: Apr 26 22:26:41.366 EDT: ISAKMP: set new node 1666670311 to QM_IDLE     
    001340: Apr 26 22:26:41.366 EDT: ISAKMP:(1010):Sending NOTIFY PROPOSAL_NOT_CHOSEN protocol 3
            spi 820964128, message ID = 1666670311
    001341: Apr 26 22:26:41.366 EDT: ISAKMP:(1010): sending packet to 19.9.17.1 my_port 500 peer_port 500 (R) QM_IDLE     
    001342: Apr 26 22:26:41.366 EDT: ISAKMP:(1010):Sending an IKE IPv4 Packet.

    001343: Apr 26 22:26:41.366 EDT: ISAKMP:(1010):purging node 1666670311
    001344: Apr 26 22:26:41.366 EDT: ISAKMP:(1010):deleting node 1351243089 error TRUE reason "QM rejected"
    001345: Apr 26 22:26:41.366 EDT: ISAKMP:(1010):Node 1351243089, Input = IKE_MESG_FROM_PEER, IKE_QM_EXCH
    001346: Apr 26 22:26:41.366 EDT: ISAKMP:(1010):Old State = IKE_QM_READY  New State = IKE_QM_READY


    After third thought and discussed with remote firewall administrator, I changed my access-list again to have all since his encryption domains includes specific ip and whole network.

    R-IPSEC1(config-ext-nacl)#do show access-list VPN-VPN
    Extended IP access list VPN-VPN
        110 permit ip host 19.24.11.53 host 19.9.17.41
        120 permit ip host 19.24.11.245 host 19.9.17.41
        130 permit ip host 19.24.11.53 19.9.17.0 0.0.0.255
        140 permit ip host 19.24.11.245 19.9.17.0 0.0.0.255


    Debugging result shows much more details this time:

    001565: Apr 26 22:40:20.200 EDT: ISAKMP:(1012):SA is doing pre-shared key authentication using id type ID_IPV4_ADDR
    001566: Apr 26 22:40:20.200 EDT: ISAKMP (1012): ID payload
            next-payload : 8
            type         : 1
            address      : 19.24.11.142
            protocol     : 17
            port         : 500
            length       : 12
    001567: Apr 26 22:40:20.200 EDT: ISAKMP:(1012):Total payload length: 12
    001568: Apr 26 22:40:20.200 EDT: ISAKMP:(1012): sending packet to 19.9.17.1 my_port 500 peer_port 500 (R) MM_KEY_EXCH
    001569: Apr 26 22:40:20.200 EDT: ISAKMP:(1012):Sending an IKE IPv4 Packet.
    001570: Apr 26 22:40:20.200 EDT: ISAKMP:(1012):Input = IKE_MESG_INTERNAL, IKE_PROCESS_COMPLETE
    001571: Apr 26 22:40:20.200 EDT: ISAKMP:(1012):Old State = IKE_R_MM5  New State = IKE_P1_COMPLETE

    001572: Apr 26 22:40:20.200 EDT: ISAKMP:(1012):Input = IKE_MESG_INTERNAL, IKE_PHASE1_COMPLETE
    001573: Apr 26 22:40:20.200 EDT: ISAKMP:(1012):Old State = IKE_P1_COMPLETE  New State = IKE_P1_COMPLETE

    001574: Apr 26 22:40:20.264 EDT: ISAKMP (1012): received packet from 19.9.17.1 dport 500 sport 500 Global (R) QM_IDLE     
    001575: Apr 26 22:40:20.264 EDT: ISAKMP: set new node -1828063596 to QM_IDLE     
    001576: Apr 26 22:40:20.264 EDT: ISAKMP:(1012): processing HASH payload. message ID = 2466903700
    001577: Apr 26 22:40:20.264 EDT: ISAKMP:(1012): processing SA payload. message ID = 2466903700
    001578: Apr 26 22:40:20.264 EDT: ISAKMP:(1012):Checking IPSec proposal 1
    001579: Apr 26 22:40:20.264 EDT: ISAKMP: transform 1, ESP_3DES
    001580: Apr 26 22:40:20.264 EDT: ISAKMP:   attributes in transform:
    001581: Apr 26 22:40:20.264 EDT: ISAKMP:      group is 2
    001582: Apr 26 22:40:20.264 EDT: ISAKMP:      SA life type in seconds
    001583: Apr 26 22:40:20.264 EDT: ISAKMP:      SA life duration (VPI) of  0x0 0x0 0xE 0x10
    001584: Apr 26 22:40:20.264 EDT: ISAKMP:      authenticator is HMAC-SHA
    001585: Apr 26 22:40:20.264 EDT: ISAKMP:      encaps is 1 (Tunnel)
    001586: Apr 26 22:40:20.264 EDT: ISAKMP:(1012):atts are acceptable.
    001587: Apr 26 22:40:20.264 EDT: IPSEC(validate_proposal_request): proposal part #1
    001588: Apr 26 22:40:20.264 EDT: IPSEC(validate_proposal_request): proposal part #1,
      (key eng. msg.) INBOUND local= 19.24.11.142:0, remote= 19.9.17.1:0,
        local_proxy= 19.24.11.245/255.255.255.255/0/0 (type=1),
        remote_proxy= 19.9.17.41/255.255.255.255/0/0 (type=1),
        protocol= ESP, transform= NONE  (Tunnel),
        lifedur= 0s and 0kb,
        spi= 0x0(0), conn_id= 0, keysize= 0, flags= 0x0
    001589: Apr 26 22:40:20.264 EDT: Crypto mapdb : proxy_match
            src addr     : 19.24.11.245
            dst addr     : 19.9.17.41
            protocol     : 0
            src port     : 0
            dst port     : 0
    001590: Apr 26 22:40:20.264 EDT: IPSEC(ipsec_process_proposal): transform proposal not supported for identity:
        {esp-3des esp-sha-hmac }

    001591: Apr 26 22:40:20.264 EDT: ISAKMP:(1012): IPSec policy invalidated proposal with error 256
    001592: Apr 26 22:40:20.264 EDT: ISAKMP:(1012): phase 2 SA policy not acceptable! (local 19.24.11.142 remote 19.9.17.1)
    001593: Apr 26 22:40:20.264 EDT: ISAKMP: set new node -760845603 to QM_IDLE     
    001594: Apr 26 22:40:20.264 EDT: ISAKMP:(1012):Sending NOTIFY PROPOSAL_NOT_CHOSEN protocol 3
            spi 820964128, message ID = 3534121693
    001595: Apr 26 22:40:20.264 EDT: ISAKMP:(1012): sending packet to 19.9.17.1 my_port 500 peer_port 500 (R) QM_IDLE     
    001596: Apr 26 22:40:20.264 EDT: ISAKMP:(1012):Sending an IKE IPv4 Packet.
    001597: Apr 26 22:40:20.264 EDT: ISAKMP:(1012):purging node -760845603
    001598: Apr 26 22:40:20.264 EDT: ISAKMP:(1012):deleting node -1828063596 error TRUE reason "QM rejected"
    001599: Apr 26 22:40:20.264 EDT: ISAKMP:(1012):Node 2466903700, Input = IKE_MESG_FROM_PEER, IKE_QM_EXCH
    R-IPSEC1#debu
    001600: Apr 26 22:40:20.264 EDT: ISAKMP:(1012):Old State = IKE_QM_READY  New State = IKE_QM_READY
    R-IPSEC1#   
    001601: Apr 26 22:41:10.264 EDT: ISAKMP:(1012):purging node -1828063596

    "IPSEC(ipsec_process_proposal): transform proposal not supported for identity:
        {esp-3des esp-sha-hmac }" shows I used wrong transform set. I am using ah-sha-hmac.



    Quickly changed to esp-sha-hmac:
    crypto ipsec transform-set VPN-Set esp-3des esp-sha-hmac 

    This time, finally vpn tunnel get fully up in phase 1 and phase 2. From output of "show crypto ipsec sa", encrypt and decrypt numbers are increasing when test it.



    test 
    001701: Apr 26 22:46:39.512 EDT: ISAKMP:(1013):Input = IKE_MESG_INTERNAL, IKE_PHASE1_COMPLETE
    001702: Apr 26 22:46:39.512 EDT: ISAKMP:(1013):Old State = IKE_P1_COMPLETE  New State = IKE_P1_COMPLETE

    001703: Apr 26 22:46:39.560 EDT: ISAKMP (1013): received packet from 19.9.17.1 dport 500 sport 500 Global (R) QM_IDLE     
    001704: Apr 26 22:46:39.560 EDT: ISAKMP: set new node -963038103 to QM_IDLE     
    001705: Apr 26 22:46:39.560 EDT: ISAKMP:(1013): processing HASH payload. message ID = 3331929193
    001706: Apr 26 22:46:39.560 EDT: ISAKMP:(1013): processing SA payload. message ID = 3331929193
    001707: Apr 26 22:46:39.560 EDT: ISAKMP:(1013):Checking IPSec proposal 1
    001708: Apr 26 22:46:39.560 EDT: ISAKMP: transform 1, ESP_3DES
    001709: Apr 26 22:46:39.560 EDT: ISAKMP:   attributes in transform:
    001710: Apr 26 22:46:39.560 EDT: ISAKMP:      group is 2
    001711: Apr 26 22:46:39.560 EDT: ISAKMP:      SA life type in seconds
    001712: Apr 26 22:46:39.560 EDT: ISAKMP:      SA life duration (VPI) of  0x0 0x0 0xE 0x10
    001713: Apr 26 22:46:39.560 EDT: ISAKMP:      authenticator is HMAC-SHA
    001714: Apr 26 22:46:39.560 EDT: ISAKMP:      encaps is 1 (Tunnel)
    001715: Apr 26 22:46:39.560 EDT: ISAKMP:(1013):atts are acceptable.
    001716: Apr 26 22:46:39.560 EDT: IPSEC(validate_proposal_request): proposal part #1
    001717: Apr 26 22:46:39.560 EDT: IPSEC(validate_proposal_request): proposal part #1,
      (key eng. msg.) INBOUND local= 19.24.11.142:0, remote= 19.9.17.1:0,
        local_proxy= 19.24.11.245/255.255.255.255/0/0 (type=1),
        remote_proxy= 198.96.176.41/255.255.255.255/0/0 (type=1),
        protocol= ESP, transform= NONE  (Tunnel),
        lifedur= 0s and 0kb,
        spi= 0x0(0), conn_id= 0, keysize= 0, flags= 0x0
    001718: Apr 26 22:46:39.560 EDT: Crypto mapdb : proxy_match
            src addr     : 19.24.11.245
            dst addr     : 198.96.176.41
            protocol     : 0
            src port     : 0
            dst port     : 0
    001719: Apr 26 22:46:39.580 EDT: ISAKMP:(1013): processing NONCE payload. message ID = 3331929193
    001720: Apr 26 22:46:39.580 EDT: ISAKMP:(1013): processing KE payload. message ID = 3331929193
    001721: Apr 26 22:46:39.608 EDT: ISAKMP:(1013): processing ID payload. message ID = 3331929193
    001722: Apr 26 22:46:39.608 EDT: ISAKMP:(1013): processing ID payload. message ID = 3331929193
    001723: Apr 26 22:46:39.608 EDT: ISAKMP:(1013):QM Responder gets spi
    001724: Apr 26 22:46:39.608 EDT: ISAKMP:(1013):Node 3331929193, Input = IKE_MESG_FROM_PEER, IKE_QM_EXCH
    001725: Apr 26 22:46:39.608 EDT: ISAKMP:(1013):Old State = IKE_QM_READY  New State = IKE_QM_SPI_STARVE
    001726: Apr 26 22:46:39.608 EDT: ISAKMP:(1013): Creating IPSec SAs
    001727: Apr 26 22:46:39.608 EDT:         inbound SA from 19.9.17.1 to 19.24.11.142 (f/i)  0/ 0
            (proxy 198.96.176.41 to 19.24.11.245)
    001728: Apr 26 22:46:39.608 EDT:         has spi 0x4F77DACA and conn_id 0
    001729: Apr 26 22:46:39.608 EDT:         lifetime of 3600 seconds
    001730: Apr 26 22:46:39.608 EDT:         outbound SA from 19.24.11.142 to 19.9.17.1 (f/i) 0/0
            (proxy 19.24.11.245 to 198.96.176.41)
    001731: Apr 26 22:46:39.608 EDT:         has spi  0x990B6255 and conn_id 0
    001732: Apr 26 22:46:39.608 EDT:         lifetime of 3600 seconds
    001733: Apr 26 22:46:39.608 EDT: ISAKMP:(1013): sending packet to 19.9.17.1 my_port 500 peer_port 500 (R) QM_IDLE     
    001734: Apr 26 22:46:39.608 EDT: ISAKMP:(1013):Sending an IKE IPv4 Packet.
    001735: Apr 26 22:46:39.608 EDT: ISAKMP:(1013):Node 3331929193, Input = IKE_MESG_INTERNAL, IKE_GOT_SPI
    001736: Apr 26 22:46:39.608 EDT: ISAKMP:(1013):Old State = IKE_QM_SPI_STARVE  New State = IKE_QM_R_QM2
    001737: Apr 26 22:46:39.608 EDT: IPSEC(key_engine): got a queue event with 1 KMI message(s)
    001738: Apr 26 22:46:39.608 EDT: Crypto mapdb : proxy_match
            src addr     : 19.24.11.245
            dst addr     : 198.96.176.41
            protocol     : 0
            src port     : 0
            dst port     : 0
    001739: Apr 26 22:46:39.612 EDT: IPSEC(crypto_ipsec_sa_find_ident_head): reconnecting with the same proxies and peer 19.9.17.1
    001740: Apr 26 22:46:39.612 EDT: IPSEC(policy_db_add_ident): src 19.24.11.245, dest 198.96.176.41, dest_port 0

    001741: Apr 26 22:46:39.612 EDT: IPSEC(create_sa): sa created,
      (sa) sa_dest= 19.24.11.142, sa_proto= 50,
        sa_spi= 0x4F77DACA(1333254858),
        sa_trans= esp-3des esp-sha-hmac , sa_conn_id= 2001
        sa_lifetime(k/sec)= (4586756/3600)
    001742: Apr 26 22:46:39.612 EDT: IPSEC(create_sa): sa created,
      (sa) sa_dest= 19.9.17.1, sa_proto= 50,
        sa_spi= 0x990B6255(2567660117),
        sa_trans= esp-3des esp-sha-hmac , sa_conn_id= 2002
        sa_lifetime(k/sec)= (4586756/3600)
    001743: Apr 26 22:46:39.656 EDT: ISAKMP (1013): received packet from 19.9.17.1 dport 500 sport 500 Global (R) QM_IDLE     
    001744: Apr 26 22:46:39.656 EDT: ISAKMP:(1013):deleting node -963038103 error FALSE reason "QM done (await)"
    001745: Apr 26 22:46:39.656 EDT: ISAKMP:(1013):Node 3331929193, Input = IKE_MESG_FROM_PEER, IKE_QM_EXCH
    001746: Apr 26 22:46:39.656 EDT: ISAKMP:(1013):Old State = IKE_QM_R_QM2  New State = IKE_QM_PHASE2_COMPLETE
    001747: Apr 26 22:46:39.656 EDT: IPSEC(key_engine): got a queue event with 1 KMI message(s)
    001748: Apr 26 22:46:39.656 EDT: IPSEC(key_engine_enable_outbound): rec'd enable notify from ISAKMP
    001749: Apr 26 22:46:39.656 EDT: IPSEC(key_engine_enable_outbound): enable SA with spi 2567660117/50
    001750: Apr 26 22:46:39.656 EDT: IPSEC(update_current_outbound_sa): get enable SA peer 19.9.17.1 current outbound sa to SPI 990B6255
    001751: Apr 26 22:46:39.656 EDT: IPSEC(update_current_outbound_sa): updated peer 19.9.17.1 current outbound sa to SPI 990B6255
    001752: Apr 26 22:46:39.696 EDT: %AAA-3-BADSERVERTYPEERROR: Cannot process accounting server type tacacs+ (UNKNOWN)
    001753: Apr 26 22:46:39.756 EDT: ISAKMP (1013): received packet from 19.9.17.1 dport 500 sport 500 Global (R) QM_IDLE     
    001754: Apr 26 22:46:39.756 EDT: ISAKMP:(1013): phase 2 packet is a duplicate of a previous packet.
    001755: Apr 26 22:46:39.756 EDT: ISAKMP:(1013): retransmitting due to retransmit phase 2
    001756: Apr 26 22:46:39.756 EDT: ISAKMP:(1013): ignoring retransmission,because phase2 node marked dead -963038103
    001757: Apr 26 22:46:39.856 EDT: ISAKMP (1013): received packet from 19.9.17.1 dport 500 sport 500 Global (R) QM_IDLE     
    001758: Apr 26 22:46:39.856 EDT: ISAKMP:(1013): phase 2 packet is a duplicate of a previous packet.
    [confirm]
    001759: Apr 26 22:46:39.856 EDT: ISAKMP:(1013): retransmitting due to retransmit phase 2
    001760: Apr 26 22:46:39.856 EDT: ISAKMP:(1013): ignoring retransmission,because phase2 node marked dead -963038103
    [confirm]


    Debugging Command:
    • debug crypto engine—Displays debug messages about crypto engines, which perform encryption and decryption.
    • debug crypto isakmp—Displays messages about IKE events.
    • debug crypto ipsec—Displays IPSec events.
    • clear crypto isakmp—Clears all active IKE connections.
    • clear crypto sa—Clears all IPSec SAs.
    •  IPSEC1#show crypto isakmp sa
      IPv4 Crypto ISAKMP SA
      dst                  src              state                conn-id status
      19.24.11.142 19.9.17.1    QM_IDLE           1014 ACTIVE
      19.24.11.142 19.9.17.1    QM_IDLE           1013 ACTIVE
    • clear crypto isakmp 1013—Clears connection id of SA.


    Reference:



    Sunday, April 17, 2016

    Real-Time Cyber Attack Threat Map

    More and more security companies use a webpage to show their monitored global security events such as the  Live Status of Cyber Attacks being launched from where and who is the target of that attack. It is become interesting by watching those websites. Actually those are not games but actually happening globally.


    1.  Kaspersky CYBERTHREAT REAL-TIME MAP





    2. Check Point Live Cyber Attack Threat Map





    3. FireEye Cyber Threat Map


    4. Fortinet Threat Map



    5. Norse Attack Map





    Wednesday, April 13, 2016

    CentOS Basic Configuration

    The CentOS Project is a community-driven free software effort focused on delivering a robust open source ecosystem. For users, CentOS offers a consistent manageable platform that suits a wide variety of deployments. For open source communities, CentOS offers a solid, predictable base to build upon, along with extensive resources to build, test, release, and maintain their code.

    1. Find Out Installed Package


    [john@linux1 /]$ rpm -qa |less
    plymouth-0.8.9-0.24.20140113.el7.centos.x86_64
    libsoup-2.48.1-3.el7.x86_64
    libaio-0.3.109-13.el7.x86_64
    dmidecode-2.12-9.el7.x86_64
    passwd-0.79-4.el7.x86_64
    bind-libs-lite-9.9.4-29.el7_2.2.x86_64
    sed-4.2.2-5.el7.x86_64
    grub2-2.02-0.34.el7.centos.x86_64
    libcom_err-1.42.9-7.el7.x86_64
    rsyslog-7.4.7-12.el7.x86_64
    biosdevname-0.6.2-1.el7.x86_64
    dracut-config-rescue-033-360.el7_2.x86_64
    libacl-2.2.51-12.el7.x86_64
    openssh-clients-6.6.1p1-23.el7_2.x86_64
    xe-guest-utilities-6.5.0-1432.x86_64
    libgcrypt-1.5.3-12.el7_1.1.x86_64
    libpcap-1.5.3-8.el7.x86_64
    cronie-1.4.11-14.el7.x86_64
    iwl6050-firmware-41.28.5.1-43.el7.noarch
    iwl4965-firmware-228.61.2.24-43.el7.noarch
    iwl3160-firmware-22.0.7.0-43.el7.noarch
    libunistring-0.9.3-9.el7.x86_64
    iwl100-firmware-39.31.5.1-43.el7.noarch
    perl-parent-0.225-244.el7.noarch
    newt-0.52.15-4.el7.x86_64
    perl-Pod-Escapes-1.04-286.el7.noarch
    gdbm-1.10-8.el7.x86_64
    perl-libs-5.16.3-286.el7.x86_64

    .......

    [john@linux1 /]$ rpm -qa |grep syslog

    rsyslog-7.4.7-12.el7.x86_64





    2. Network Interface Configuration

    DHCP or Static:
    Step 1 » Check the network interface name by typing below command
    [root@linux1 ~]# ip a
    1: lo: <LOOPBACK,UP,LOWER_UP> mtu 65536 qdisc noqueue state UNKNOWN 
        link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00
        inet 127.0.0.1/8 scope host lo
           valid_lft forever preferred_lft forever
        inet6 ::1/128 scope host 
           valid_lft forever preferred_lft forever
    2: eth0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc pfifo_fast state UP qlen 1000
        link/ether 9a:4a:27:66:a4:4c brd ff:ff:ff:ff:ff:ff
        inet 10.9.1.26/24 brd 10.91.128.255 scope global eth0
           valid_lft forever preferred_lft forever
        inet6 fe80::984a:27ff:fe66:a44c/64 scope link 
           valid_lft forever preferred_lft forever
    Here “lo” is the loopback interface and “eth0” is the network interface that you need to configure .

    Step 2 » you can see the file named ifcfg-eth0 ( Interface name ) in the location “/etc/sysconfig/network-scripts/” , open the file and you can see the lines as below, which is static ip 10.9.1.26 assigned to interface eth0
    Just modify the lines like this
    DEVICE="eth0"
    HWADDR="00:22:19:09:4D:3C"
    NM_CONTROLLED="yes"
    ONBOOT="yes"    # Interface enabled

    BOOTPROTO="dhcp"  #Assigning IP from DHCP
    Step 3 » Start the network service and you can see the status as below .
    [root@linux1~]# service network start
    Bringing up loopback interface:                [  OK  ]
    Bringing up interface p4p1:
    Determining IP information for p4p1... done.   [  OK  ]



    3. Disable IPv6
    There are three different ways to do it. 
    3.1 Edit Sysctl.conf file

    vi /etc/sysctl.conf

    Add following two lines:
    net.ipv6.conf.all.disable_ipv6 =1
    net.ipv6.conf.default.disable_ipv6 =1
    if only want to disable IPv6 for specific network card, such as  enp0s3, add following line instead:
    net.ipv6.conf.enp0s3.disable_ipv6 =1
    Save and exit VI. 
    Run following command to make the change effect:
    sysctl -p
    3.2 
    echo 1>/proc/sys/net/ipv6/conf/all/disable_ipv6echo 1>/proc/sys/net/ipv6/conf/default/disable_ipv6
    3.3 
    sysctl -w net.ipv6.conf.all.disable_ipv6=1sysctl -w net.ipv6.conf.default.disable_ipv6=1
    Note: Some caveats to be aware from How to disable IPv6 on Linux.

    4. Install IPTABLES 
    For Iptables lovers , here are some commands to install it to replace default firewall :
    yum install policycoreutils iptables-services -y
    systemctl stop firewalld.service
    systemctl disable firewalld.service
    service iptables restart

    5. TBC





    Reference: