5.1

Table Of Contents
IKE Peer: 10.20.129.80
Type : L2L Role : responder
Rekey : no State : MM_ACTIVE
Encrypt : 3des Hash : SHA
Auth : preshared Lifetime: 28800
Lifetime Remaining: 28379
Phase 1 Policy Not Matching
The following lists Phase 1 Policy Not Matching Error logs.
vShield Edge
vShield Edge hangs in STATE_MAIN_I1 state. Look in /var/log/messages for information showing that, the
peer sent back an IKE message with "NO_PROPOSAL_CHOSEN" set.
000 #1: "s1-c1":500 STATE_MAIN_I1 (sent MI1,
expecting MR1); EVENT_RETRANSMIT in 7s; nodpd; idle;
import:admin initiate
000 #1: pending Phase 2 for "s1-c1" replacing #0
Aug 26 12:31:25 weiqing-desktop pluto[6569]:
| got payload 0x800(ISAKMP_NEXT_N) needed: 0x0 opt: 0x0
Aug 26 12:31:25 weiqing-desktop pluto[6569]:
| ***parse ISAKMP Notification Payload:
Aug 26 12:31:25 weiqing-desktop pluto[6569]:
| next payload type: ISAKMP_NEXT_NONE
Aug 26 12:31:25 weiqing-desktop pluto[6569]: | length: 96
Aug 26 12:31:25 weiqing-desktop pluto[6569]:
| DOI: ISAKMP_DOI_IPSEC
Aug 26 12:31:25 weiqing-desktop pluto[6569]: | protocol ID: 0
Aug 26 12:31:25 weiqing-desktop pluto[6569]: | SPI size: 0
Aug 26 12:31:25 weiqing-desktop pluto[6569]:
| Notify Message Type: NO_PROPOSAL_CHOSEN
Aug 26 12:31:25 weiqing-desktop pluto[6569]:
"s1-c1" #1: ignoring informational payload,
type NO_PROPOSAL_CHOSEN msgid=00000000
Cisco
If debug crypto is enabled, error message is printed to show that no proposals were accepted.
ciscoasa# Aug 26 18:17:27 [IKEv1]:
IP = 10.20.129.80, IKE_DECODE RECEIVED
Message (msgid=0) with payloads : HDR + SA (1)
+ VENDOR (13) + VENDOR (13) + NONE (0) total length : 148
Aug 26 18:17:27 [IKEv1 DEBUG]: IP = 10.20.129.80,
processing SA payload
Aug 26 18:17:27 [IKEv1]: Phase 1 failure: Mismatched attribute
types for class Group Description: Rcv'd: Group 5
Cfg'd: Group 2
Aug 26 18:17:27 [IKEv1]: Phase 1 failure: Mismatched attribute
types for class Group Description: Rcv'd: Group 5
Cfg'd: Group 2
Aug 26 18:17:27 [IKEv1]: IP = 10.20.129.80, IKE_DECODE SENDING
Message (msgid=0) with payloads : HDR + NOTIFY (11)
+ NONE (0) total length : 124
Aug 26 18:17:27 [IKEv1 DEBUG]: IP = 10.20.129.80,
vShield Administration Guide
94 VMware, Inc.