Networking Forums

Networking Forums > Computer Networking > Windows Networking > Win2K3sp1 Server: IPSec tunnel drops out for some reason, pls help

Reply
Thread Tools Display Modes

Win2K3sp1 Server: IPSec tunnel drops out for some reason, pls help

 
 
ponga
Guest
Posts: n/a

 
      11-16-2005, 03:26 PM
Hello, we have an IPSec tunnel from a Cisco PIX -to- the endpoint, a
Win2k3sp1 Server. We use pre-shared keys. The Windows server is behind
a PIX of our own, and l2tp pass-though is enabled.
Connections can be made successfully and it is working, on the whole.
Our problem is, once in a while, the tunnel will fail, and the only
this that shows up in the log is this:
-*-*-*-
From: Security Log (on Windows server)
Source: Security
Event ID: 547


IKE security association negotiation failed.
Mode:
Data Protection Mode (Quick Mode)

Filter:
Source IP Address 172.16.34.0
Source IP Address Mask 255.0.0.0
Destination IP Address 10.0.0.0
Destination IP Address Mask 255.255.255.0
Protocol 0
Source Port 0
Destination Port 0
IKE Local Addr 192.168.0.33
IKE Peer Addr 206.171.x.x
IKE Source Port 4500
IKE Destination Port 4500
Peer Private Addr

Peer Identity:
Preshared key ID.
Peer IP Address: 206.171.x.x

Failure Point:
Me

Failure Reason:
IKE SA deleted by peer before establishment completed
Negotiation timed out

Extra Status:
Processed Quick Mode payload
Responder. Delta Time 39
0x0 0x0


For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.
-*-*-*-

Any help is VERY much appreciated!!

-Mike

 
Reply With Quote
 
 
 
 
ponga
Guest
Posts: n/a

 
      11-16-2005, 03:36 PM
Also this error:

-*-*-*-
IKE security association negotiation failed.
Mode:
Data Protection Mode (Quick Mode)

Filter:
Source IP Address 172.16.34.0
Source IP Address Mask 255.0.0.0
Destination IP Address 10.0.0.0
Destination IP Address Mask 255.255.255.0
Protocol 0
Source Port 0
Destination Port 0
IKE Local Addr 192.168.0.33
IKE Peer Addr 206.171.160.1
IKE Source Port 4500
IKE Destination Port 4500
Peer Private Addr

Peer Identity:
Preshared key ID.
Peer IP Address: 206.171.160.1

Failure Point:
Me

Failure Reason:
Negotiation timed out

Extra Status:
Processed Quick Mode payload
Responder. Delta Time 62
0x0 0x0


For more information, see Help and Support Center at
-*-*-*-

Again, any help is much appreciated!!
-Mike

 
Reply With Quote
 
chrispsg
Guest
Posts: n/a

 
      11-16-2005, 06:26 PM
Are all clients on the Source side of things on the 172.16.34.x subnet or
are they on a 172.x.x.x subnet?

psg

"ponga" <(E-Mail Removed)> wrote in message
news:(E-Mail Removed) oups.com...
> Also this error:
>
> -*-*-*-
> IKE security association negotiation failed.
> Mode:
> Data Protection Mode (Quick Mode)
>
> Filter:
> Source IP Address 172.16.34.0
> Source IP Address Mask 255.0.0.0
> Destination IP Address 10.0.0.0
> Destination IP Address Mask 255.255.255.0
> Protocol 0
> Source Port 0
> Destination Port 0
> IKE Local Addr 192.168.0.33
> IKE Peer Addr 206.171.160.1
> IKE Source Port 4500
> IKE Destination Port 4500
> Peer Private Addr
>
> Peer Identity:
> Preshared key ID.
> Peer IP Address: 206.171.160.1
>
> Failure Point:
> Me
>
> Failure Reason:
> Negotiation timed out
>
> Extra Status:
> Processed Quick Mode payload
> Responder. Delta Time 62
> 0x0 0x0
>
>
> For more information, see Help and Support Center at
> -*-*-*-
>
> Again, any help is much appreciated!!
> -Mike
>



 
Reply With Quote
 
ponga
Guest
Posts: n/a

 
      11-16-2005, 06:57 PM
No, the 172.16.34.0\24 network is the IP the vpn endpoint uses. Thus,
the tunnel is requested from the Internet to our outside address, then
the PIX does NAT magic and forwards it to 192.168.0.33. Once that's up
- The remote side can talk to 172.16.34.x via the tunnel. The source
(remote) is whatever, 10.x.x.x - they have a PIX that forwards requests
for 172.16.34.x through the tunnel.

Although looking at this error again... it does appear that were are
trying to get traffic BACK to them... and then it fails. Interesting..
I just dont understand this error at all. Can anyone shed some light??


-Mike

 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Ipsec tunnel mode vs ip in ip with ipsec transport Reji Linux Networking 1 09-20-2011 04:29 PM
IPsec tunnel up but no traffic wamsterdam@zesgoes.nl Linux Networking 6 08-14-2008 09:05 AM
IPSEC tunnel problem Sandro Linux Networking 2 03-19-2008 11:33 AM
IPsec in the tunnel mode salildangi@gmail.com Linux Networking 0 09-25-2007 08:53 PM
IPsec tunnel using racoon dee Linux Networking 2 07-16-2007 08:53 AM



1 2 3 4 5 6 7 8 9 10 11