Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

site2site vpn

hi expert,

I'm configuring site2site vpn bet ASG 425 ver8.306 and Cisco RV042. Tunnel is UP but I cant ping both sides.

here's what Ive got under asg ipsec vpn live logs.

2013:04:04-16:04:49 asg425 pluto[2694]: packet from x.x.7.240:500: unsupported exchange type ISAKMP_XCHG_AGGR in message
2013:04:04-16:04:49 asg425 pluto[2694]: packet from x.x.7.240:500: sending notification UNSUPPORTED_EXCHANGE_TYPE to x.x.7.240:500
2013:04:04-16:04:59 asg425 pluto[2694]: packet from x.x.7.240:500: unsupported exchange type ISAKMP_XCHG_AGGR in message
2013:04:04-16:04:59 asg425 pluto[2694]: packet from x.x.7.240:500: sending notification UNSUPPORTED_EXCHANGE_TYPE to x.x.7.240:500
2013:04:04-16:05:19 asg425 pluto[2694]: "S_Main" #13: max number of retransmissions (2) reached STATE_QUICK_I1
2013:04:04-16:05:19 asg425 pluto[2694]: "S_Main" #13: starting keying attempt 4 of an unlimited number
2013:04:04-16:05:19 asg425 pluto[2694]: "S_Main" #14: initiating Quick Mode PSK+ENCRYPT+TUNNEL+PFS+UP to replace #13 {using isakmp#8}
2013:04:04-16:05:19 asg425 pluto[2694]: packet from x.x.7.240:500: unsupported exchange type ISAKMP_XCHG_AGGR in message
2013:04:04-16:05:19 asg425 pluto[2694]: packet from x.x.7.240:500: sending notification UNSUPPORTED_EXCHANGE_TYPE to x.x.7.240:500
2013:04:04-16:05:20 asg425 pluto[2694]: "S_Main" #8: ignoring informational payload, type NO_PROPOSAL_CHOSEN
2013:04:04-16:05:49 asg425 pluto[2694]: "S_Main" #8: ignoring informational payload, type INVALID_MESSAGE_ID 

Pls share any docs if somebody tried this setup before.TIA


This thread was automatically locked due to age.
Parents
  • Aggressive Mode is not supported.  Configure the Cisco to use Main Mode.

    Cheers - Bob
     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Reply
  • Aggressive Mode is not supported.  Configure the Cisco to use Main Mode.

    Cheers - Bob
     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Children
No Data
Share Feedback
×

Submitted a Tech Support Case lately from the Support Portal?