Tunnel of the phase 2's not going up between Watchguard and PIX 525

Hi people,

Can you please help me to know where is the problem liying, currently I am trying to establish a VPN tunnel between the PIX firewall and Watchguard, all settings of the two devices are the same, but tunnel Phase two is not coming.

Here is the fix:

crypto_isakmp_process_block:src:212.37.17.43, dest:212.118.128.233 spt:500 dpt:500

Exchange OAK_MM

ISAKMP (0): processing KE payload. Message ID = 0

ISAKMP (0): processing NONCE payload. Message ID = 0

ISAKMP (0:0): payload detected NAT - D

ISAKMP (0:0): NAT does not match hash MINE

received hash: b3 8f bb 0 93 3 b 65 e8 35 54 6 c4 cc 59 6f 6f

My nat hash: dd 9 70 35 58 40 ac da 3 b 5 b 1 b 4 c 87 d2 11 fc

ISAKMP (0:0): payload detected NAT - D

ISAKMP (0:0): NAT does not match THE hash

received hash: ba 72 c5 e 5 b fb 88 f0 1e ba c9 c6 c1 cc 8A f7

its nat hash: c 4 c 89 a5 66 dd 80 76 48 3f f0 56 ed b0 a5 c1

ISAKMP (0:0): built HIS NAT - D

ISAKMP (0:0): built MINE NAT - D

to return to the State is IKMP_NO_ERROR

crypto_isakmp_process_block:src:212.37.17.43, dest:212.118.128.233 spt:4500 dpt:4500

Exchange OAK_MM

ISAKMP (0): processing ID payload. Message ID = 0

ISAKMP (0): HASH payload processing. Message ID = 0

ISAKMP (0): SA has been authenticated.

ISAKMP: Created a struct 212.37.17.43, peer port 37905 peer

ISAKMP: Lock struct UDP_ENC crypto_ikmp_udp_enc_ike_init 0x3cbb634, 1

ISAKMP (0): ID payload

next payload: 8

type: 2

Protocol: 17

Port: 0

Length: 23

ISAKMP (0): the total payload length: 27

to return to the State is IKMP_NO_ERROR

ISAKMP (0): send to notify INITIAL_CONTACT

ISAKMP (0): sending message 24578 NOTIFY 1 protocol

Peer VPN: ISAKMP: approved new addition: ip:212.37.17.43/4500 Total VPN peer: 16

Peer VPN: ISAKMP: ip:212.37.17.43/4500 Ref cnt is incremented to peers: 1 Total VPN peer: 16

crypto_isakmp_process_block:src:212.37.17.43, dest:212.118.128.233 spt:4500 dpt:4500

ISAKMP (0): processing NOTIFY payload Protocol 24578 1

SPI 0, message ID = 3168983470

ISAKMP (0): treatment notify INITIAL_CONTACT

to return to the State is IKMP_NO_ERR_NO_TRANS

crypto_isakmp_process_block:src:212.37.17.43, dest:212.118.128.233 spt:4500 dpt:4500

Exchange OAK_QM

oakley_process_quick_mode:

OAK_QM_IDLE

ISAKMP (0): treatment ITS payload. Message ID = 484086886

ISAKMP: Check IPSec proposal 1

ISAKMP: turn 1, ESP_3DES

ISAKMP: attributes of transformation:

ISAKMP: Life Type SA in seconds

ISAKMP: Lifetime of HIS (basic) of 28800

ISAKMP: Type of life HIS enKo

ISAKMP: Lifetime of HIS (basic) 32000

ISAKMP: program is 61433

ISAKMP: authenticator is HMAC-MD5

ISAKMP (0): atts are not acceptable. Next payload is 0

ISAKMP (0): Security Association is not acceptable!

ISAKMP (0): 14 NOTIFY message protocol sending 0

to return to the State is IKMP_ERR_NO_RETRANS

crypto_isakmp_process_block:src:212.37.17.43, dest:212.118.128.233 spt:4500 dpt:4500

ISAKMP: phase 2 package is a duplicate of a previous package

ISAKMP: last reply reference

ISAKMP (0:0): sending of NAT - T vendor ID - rev 2 & 3

crypto_isakmp_process_block:src:212.37.17.43, dest:212.118.128.233 spt:4500 dpt:4500

ISAKMP: phase 2 package is a duplicate of a previous package

ISAKMP: last reply reference

crypto_isakmp_process_block:src:213.210.211.82, dest:212.118.128.233 spt:500 dpt:500

ISAKMP (0): processing NOTIFY payload Protocol 36136 1

SPI 0, message ID = 287560609

ISAMKP (0): DPD_R_U_THERE received from the peer 213.210.211.82

ISAKMP (0): sending message 36137 NOTIFY 1 protocol

to return to the State is IKMP_NO_ERR_NO_TRANSdebug

ISAKMP (0): retransmission of the phase 1 (0)...

Thank you

Ismail

Hello

The debug version, it seems that the parameters are not same on devices:

ISAKMP (0): atts are not acceptable. Next payload is 0

Please check the settings of the Phase 2 and also make sure that you have PFS disabled Watchguard.

* Please rate if helped.

-Kanishka

Tags: Cisco Security

Similar Questions

  • "Error while interacting with the scanner: the selected scanner was not found." Called brother and my MFC 7360N works very well with other programs to scan - only problem with Adobe Acrobat Pro 11.

    "Error while interacting with the scanner: the selected scanner was not found." Called brother and my MFC 7360N works very well with other programs to scan - only problem with Adobe Acrobat Pro 11.

    Hi davidd67669685,

    Please provide the exact point of the software & OS installed on your system. Also check if it is there any update available for the software after going through "help > check updates.

    Follow this thread to reset the Acrobat preferences:- How to reset preference settings in format Acrobat.

    You can check after connecting this scanner locally to the system if asked its connected on network & then look for the same thing.

    Please refer to this article:- of the troubleshooting tips for scanning questions when using Acrobat

    If the problem persists ask please check with another user account.

    Kind regards

    Christian

  • Why the original image does not appear on my desktop and not Wo one?

    Why the original image does not appear on my desktop and not Wo one?

    I made adjustments to an image that shows himself such that adjusted with the symbols at the bottom right of the image.
    I tried to drag and drop and he transferred the original image.

    The adjusted picture can be transferred and what I need to do or I do something wrong?

    Thank you

    Greg,

    Claes has pretty much nailed. You will do well to spend time to learn how Lightroom works. He is not like most software that you've used before, and if you don't understand what it does and how it does, you stand a good chance of losing your images.

    Try googling 'Lightroom tutorials' or 'get started in Lightroom. It's not rocket science, but it's different.

    HAL

  • I recently bought a new camera from Sony a7 - ii.  the first time I tried to import raw images taken with it (with a. Suffix ARW) the program says "Preview not available for this file" and then "files are not recognized by the raw format support in Lightr

    I recently bought a new camera from Sony a7 - ii.  the first time I tried to import raw images taken with it (with a. Suffix ARW) the program says "Preview not available for this file" and then "files are not recognized by the raw format support in Lightroom" I have the most updated version, I think as 5.7.  What should I do to get these files imported as raw files?

    Hi Bobsirkus,

    The camera you have is compatible with the latest version of Lightroom, which is Lightroom 6/CC.

    Please see the list of the camera supported by Lightroom: supported by Adobe Camera Raw devices

    You can use the DNG Converter, converts images and then import them into DNG in Lightroom.

    Kind regards

    Tanuj

  • Accidentally, I bought the Mac in December and contacted support which helped me to get the right version installed, but now the PC version is not in my account downloads and I need to add it to a new computer. I don't know how to get help with this.

    Accidentally, I bought the Mac in December and contacted support which helped me to get the right version installed, but now the PC version is not in my account downloads and I need to add it to a new computer. I don't know how to get help with this. I don't remember how I got the PC version, I think I have access to my computer remotely and she sent, but I can't find any record of it.

    Since this is an open forum, not Adobe support... you must contact Adobe personnel to help
    Chat/phone: Mon - Fri 05:00-19:00 (US Pacific Time)

    Creative cloud support (all creative cloud customer service problems)
    http://helpx.Adobe.com/x-productkb/global/service-CCM.html

  • Do not click on in the VM and can not move files between hosts and virtual

    Do not click on in the VM and can not move files between hosts and virtual

    Home - Windows XP x 64 Edition

    Virtual - Windows 2003 Web Edition

    -vmware.log

    ...

    sept 23 14:10:17.875: mks | Setting size 40 pile of thread to 1048576.
    sept 23 14:10:17.875: mks | Adjusting size of 41 of the stack of the thread to 1048576.
    sept 23 14:10:17.890: mks | USBGW: Writing referee op: 13 len:36
    sept 23 14:10:21.718: vcpu-0 | Unified TOOLS loop capacity requested by 'box to tools-MDN; now sending via the TECO
    sept 23 14:10:21.718: vcpu-0 | GuestRpc: Channel 7, toolbox-MDN app reviews.
    sept 23 14:10:21.718: vmx | DnDRegisterRpc: Rpc of DND already set to 1
    sept 23 14:10:21.718: vmx | CopyPasteRegisterRpc: already the value 1
    sept 23 14:10:21.890: vcpu-0 | VMXVmdb_LoadRawConfig: Loading of raw configuration
    sept 23 14:10:22.000: vmx | DnDRegisterRpc: Rpc of DND already set to 1
    sept 23 14:10:22.000: vmx | CopyPasteRegisterRpc: already the value 1
    sept 23 14:10:23.750: mks | USBGW: Writing referee op: 13 len:36
    sept 23 14:10:30.703: mks | Setting size 40 pile of thread to 1048576.
    sept 23 14:10:30.718: mks | Adjusting size of 41 of the stack of the thread to 1048576.

    ...

    Any ideas?

    Thank you

    If your license key allows, update your VMware Workstation version 7.1.4

    Otherwise, at least upgrade your VMware Workstation to version 7.0.1

    In the menu bar, help-> Check for Updates on the Web.

  • ios7.1.2 of the iPhone 4's not going to happen to ios8

    iPhone 4 ios 7.1.2 won't move to ios8, can anyone help?

    Message informs you that your iphone software is updated, I tried using iTunes and the same message appears.

    It's not supposed to. iOS 8 and newer require a dual-core CPU, which is not the iPhone 4.

    (137818)

  • Windows Update - it gets to the final stage of the update every time it goes to "Starting Windows" and then it all comes back to the update

    Original title: Windows Update keeps reseting

    My computer had a mandatory update that began when turned on. Happens to the last step of the update every time, it goes to the "starting Windows" and then it all comes back to the update. Turn on the computer and then next turn has not changed anything either, and I can't after that.

    Hi Reilly,

    Thank you for the update on that.

    Please follow the steps in method 1, by our Support Engineer Ganesh Achar B replied on 12 February 2015 on the last response.

    If you are able to start the computer in safe mode, take note of the number of KB updates which fails to install.
     

    Also you can restore the system in safe mode.

    Check out the link below to perform a restore of the system.

    http://Windows.Microsoft.com/en-us/Windows7/products/features/system-restore

    Warning: System Restore affects file system of Windows, programs and registry settings. It can also make changes to scripts, files, batch and other types of executable files created under any user account on your computer. System Restore does not affect personal files, such as e-mail, documents, or photos, so it cannot help you restore a deleted file. If you have backups of your files, you can restore files from a backup.

    Please answer us with the State to proceed to further troubleshooting.

  • R510 'or foreign patterns found on the map.' do not accept C or F and can not in small groups

    Hi all

    I have a misconduct R510 who complains of ' or configurations foreign adapter.»  Normally I can erase it import with F or going to config with C.  However, this machine does not accept the F or C (despite the offer) and I can't get out early with all BIOS or Ctrl-R options.  Any advice on how to escape from it?  The keyboard works (I can get into the stuff of enet with Ctrl-S), but otherwise he's stuck.

    Thank you

    Jack

    Try disconnecting the drives and see if it moves beyond this error, one of the disks may be suspended the controller. If it moves no doubt spent is not a problem of controller and you can try to reinsert the readers.

  • Receiving the message window is not authentic... key and activation error is not true.

    I bought Microsoft Window 7 Home premium with my Dell laptop in 2011. I had window installed on the laptop, as well as real Cd of Windows 7 and the key of window number is printed on the back of my laptop.  I reinstalled the window on my laptop with the windows cd and inserted the right key. But I get the message window is not genuine. I tried a lot of things... updated bio, fast memory of intel and also all the latest driver of my laptop from the Dell Web site. But still unable to activate the it.followed all the intruction provided in dell as microsoft community community, but still no result.

    Someone can help me. I'm also pasting the result of MGA diagnostic tools.

    Diagnostic report (1.9.0027.0):
    -----------------------------------------
    Validation of Windows data-->

    Validation code: 0
    Code of Validation caching online: 0x0
    Windows product key: *-* - MK7JP - GHTB6-DV923
    The Windows Product Key hash: lrFcCyr + 9u2QtE6FEcrgsGPEtnc =
    Windows product ID: 00359-OEM-9902994-74509
    Windows product ID type: 8
    Windows license type: COA SLP
    The Windows OS version: 6.1.7601.2.00010300.1.0.003
    ID: {1AE2237D-E3B3-49F8-A756-C8E5AFF4CF33} (3)
    Admin: Yes
    TestCab: 0x0
    LegitcheckControl ActiveX: N/a, hr = 0 x 80070002
    Signed by: n/a, hr = 0 x 80070002
    Product name: Windows 7 Home Premium
    Architecture: 0 x 00000009
    Build lab: 7601.win7sp1_gdr.150525 - 0603
    TTS error:
    Validation of diagnosis:
    Resolution state: n/a

    Given Vista WgaER-->
    ThreatID (s): n/a, hr = 0 x 80070002
    Version: N/a, hr = 0 x 80070002

    Windows XP Notifications data-->
    Cached result: n/a, hr = 0 x 80070002
    File: No.
    Version: N/a, hr = 0 x 80070002
    WgaTray.exe signed by: n/a, hr = 0 x 80070002
    WgaLogon.dll signed by: n/a, hr = 0 x 80070002

    OGA Notifications data-->
    Cached result: n/a, hr = 0 x 80070002
    Version: N/a, hr = 0 x 80070002
    OGAExec.exe signed by: n/a, hr = 0 x 80070002
    OGAAddin.dll signed by: n/a, hr = 0 x 80070002

    OGA data-->
    Office status: 109 n/a
    OGA Version: N/a, 0 x 80070002
    Signed by: n/a, hr = 0 x 80070002
    Office Diagnostics: 025D1FF3-364-80041010_025D1FF3-229-80041010_025D1FF3-230-1_025D1FF3-517-80040154_025D1FF3-237-80040154_025D1FF3-238-2_025D1FF3-244-80070002_025D1FF3-258-3

    Data browser-->
    Proxy settings: N/A
    User Agent: Mozilla/4.0 (compatible; MSIE 8.0; Win32)
    Default browser: C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    Download signed ActiveX controls: fast
    Download unsigned ActiveX controls: disabled
    Run ActiveX controls and plug-ins: allowed
    Initialize and script ActiveX controls not marked as safe: disabled
    Allow the Internet Explorer Webbrowser control scripts: disabled
    Active scripting: allowed
    Recognized ActiveX controls safe for scripting: allowed

    Analysis of file data-->

    Other data-->
    Office details: {1AE2237D-E3B3-49F8-A756-C8E5AFF4CF33}1.9.0027.06.1.7601.2.00010300.1.0.003x 64*-*-*-*-DV92300359-OEM-9902994-745098S-1-5-21-1823455569-3041811487-3675979126Dell Inc.. Inspiron N5110 Dell Inc.. A11 20120803000000.000000 + 0007E223807018400FE04090409India Standard Time(GMT+05:30)03DELL WN09 109

    Content Spsys.log: 0 x 80070002

    License data-->
    The software licensing service version: 6.1.7601.17514

    Name: Windows 7 HomePremium edition
    Description: operating system Windows - Windows (r) 7, channel OEM_COA_SLP
    Activation ID: 01f5fc37-a99e-45c5-b65e-d762f3518ead
    ID of the application: 55c92734-d682-4d71-983e-d6ec3f16059f
    Extended PID: 00359-00198-029-974509-02-1033-7601.0000-1812015
    Installation ID: 009794081222872485976195139692296731118475912305979490
    Processor certificate URL: http://go.microsoft.com/fwlink/?LinkID=88338
    The machine certificate URL: http://go.microsoft.com/fwlink/?LinkID=88339
    Use license URL: http://go.microsoft.com/fwlink/?LinkID=88341
    Product key certificate URL: http://go.microsoft.com/fwlink/?LinkID=88340
    Partial product key: DV923
    License status: initial grace period
    Time remaining: 39660 minute (s) on (27 day (s))
    Remaining Windows rearm count: 3
    Trust time: 01/07/2015 23:31:52

    Windows Activation Technologies-->
    HrOffline: 0x00000000
    HrOnline: 0x00000000
    Beyond: 0 x 0000000000000000
    Event timestamp: 7:1:2015 21:22
    ActiveX: Registered, Version: 7.1.7600.16395
    The admin service: recorded, Version: 7.1.7600.16395
    Output beyond bitmask:

    --> HWID data
    Current HWID hash: MAAAAAEAAQABAAIAAAABAAAAAwABAAEAeqgQzST8BobcDgqnnMa8xHjqKt9qJi5z

    Activation 1.0 data OEM-->
    N/A

    Activation 2.0 data OEM-->
    BIOS valid for OA 2.0: Yes
    Windows marker version: 0 x 20001
    OEMID and OEMTableID consistent: Yes
    BIOS information:
    ACPI Table name OEMID value OEMTableID value
    APIC DELL WN09
    FACP DELL WN09
    HPET DELL WN09
    MCFG DELL WN09
    SSDT TrmRef PtidDevc
    WN09 DELL SLIC
    SSDT TrmRef PtidDevc
    SSDT TrmRef PtidDevc
    SSDT TrmRef PtidDevc
    SSDT TrmRef PtidDevc
    OSFR DELL M08

    Have you tried to restart by phone?

    How to activate Windows 7 manually (activate by phone)
     
    1) click Start and in the search for box type: slui.exe 4
     
    (2) press the ENTER"" key.
     
    (3) select your "country" in the list.
     
    (4) choose the option "activate phone".
     
    (5) stay on the phone (do not select/press all options) and wait for a person to help you with the activation.
     
    (6) explain your problem clearly to the support person.
     
    http://support.Microsoft.com/kb/950929/en-us

  • I use an iMac with El Capitan and Photoshop CS6. I'm trying to add a shadow to a text on a picture. I followed the instructions to double the text layer but not dropshadow dialog box appears and I can't. Where would it be?

    Double click on the text on the right side of the display panel does not cause a dialog box open. I just need to know where the dialog box is so I can add the drop shadow

    Please make sure that you double-click on the text layer in the layer panel not the name of the layer. With the text, it can be difficult if the name is too long. You can also right-click on the text layer in the Panel and bring up the contextual menu and select 'blending Options '.

  • Help on the ORA-01841: (full) year must be between-4713 and 9999 and not

    While in the console f? p = 4050 connected in internal/admin in Home-> manage workspaces-> manage developers and users
    Download "ORA-01841: (full) year must be between-4713 and 9999 and not 0" when you try to change a user.
    Unable to reset the password or modify an admin user.
    This just started 2 weeks ago.


    Using Application Express 4.0.2.00.06.

    Someone has seen this.

    I heard of a problem due to a problem with the PASSWORD_LIFE_TIME. Worth giving a try:

    Solution
    The apex_admin app, navigate to home > Service Management > security then enter integer values for:

    -Lifetime account password (days) - enter 11688, for example
    -Apply the changes.

  • Can not scan wireless between mac and photosmart 7515

    Print very well between Mac and a printer wireless

    Can scan correctly when CONNECTED between Mac and a printer

    Have already uninstalled and reinstalled the software

    Message says function 'Enable Scan to Computer' if she goes on to say that with Mac users, it is automatically activated.

    Mac OS 10.7

    Hello

    Adding the printer using the Protocol IP Jetdirect (tab within the intellectual property) only will allow you to print.

    To scan, Mac must communicate with the device as a Hello. The multicast must be supported by the router.

    https://discussions.Apple.com/message/13184615#13184615

    As you can see in bellows Joey post, it seems that the router Actiontec M1000 support not Hello.

    The user said it was confirmed by the manufacturing of router and a firmware update will be available.

    However, any update firmware seems to be available:

    http://www.Actiontec.com/support/product_details.php?PID=38&Typ=all

    I recommend you contact support Actiontec to check all supported multicast router.

    Kind regards

    Shlomi

  • Table does not work correctly between LabView and TestStand

    I'm doing a TestStand program that reads data from a LabView VI.

    If I run the VI in LabView, it works perfectly well and generates a table with 18 points in length, the first 3 are numbers between 0 and 10 and the rest being-1 as I intended. Re-run the VI causes the re - initialize correctly and I get a new table that also meets my specifications.

    When I run the VI of TestStand, it works fine once, producing a table with 18 points, the first 3 are numbers between 0 and 10, and the rest is-1.

    If I run the VI in TestStand once again it increases the length of array in 18 each time. In so doing, it fails to write the new 3 numbers and just add - 1 in table 18 times. If I restart TestStand will work fine once more, he repeats the error if I re - run the VI. I don't understand why this is happening.

    I have re-product the error in a separate VI and the order, and I have attached an example in this post. The VI contains all the necessary information (if not, please say so and I will correct it), and TestStand sequence is configured to put all results, I would find useful in the report (as additional results).

    Your problem is your VI.   Specifically the comment nodes.  They initialize on the first call.  TestStand retains the VI in memory.  So when the VI is called again, the comments always nodes have their last value.  You will get the same results if you have VI your ArrayBuild.vi twice appealed.

    The way you use the feedback nodes, they really replace with Shift Registers.  I like your comment nodes, but since you pass the value of the node in the loop, the SHIFT registers are much more appropriate.  Just make sure you initialize your Shift Registers.

  • Adobe Updater in the Menu bar is not going away (Mac)

    I need help getting rid of Adobe Updater in my menu bar. It won't work to preferences creative cloud. In the menu bar, it displays the logo of adobe with a so-called Cup number 2 off the coast. Please helpp

    Hi Otniel,

    Please click the Update menu and install available updates.

    Once the updates have been installed, the update will not appear.

    Kind regards

    Sheena

Maybe you are looking for