Adding new peer without removing cmap from interface.

I have a frustrating issue with a dynamic VPN head end running IOS 15.2 on 2900's. I have existing keyrings, and isakmp profiles (both main and agressive) running. When I add in a new peer, by adding in a keyring prechared statement and a match identity in the isakmp profile, phase 1 biulds but phase 2 only gets right to the end and the Cisco side resets the connection because it did not get back a response to it's Phase 2 proposal.
I have tried a number of soft clear commands to remedy this (I do have 16 other production tunnels I do not want to take down) and no avail. This is very consistent. We had this happen last week in the same manner, and the TAC finally said I must reboot the system. So I removed the cmap from the interface, and reapplied it (using notepad to do it all at once). All the tunnels dropped, and after a few manual restarts on the far end for thos etunnels that are tempermental, all tunnels came back up, including my new add.
I have a pair of 3900's running 15.1 code in the US that terminate the same tunnels, and I can add and remove PEERS all day long without resetting anything. Has anyone one encountered this before? Could there be a more polite way of resetting what ever it is that removing the CMAP does to allow my new peer to get the full treatment here?
(I am not asking for VPN peer config help, as I know this tunnel template I am using works, but if you want to see it)
Nick
crypto pki token default removal timeout 0
crypto keyring Site-to-Site 
  pre-shared-key address a.a.a.a key lkdshjfhjkdsfkjfsjkddedswdes
  pre-shared-key address b.b.b.b key lkdshjfhjkdsfkjfsjkddedswdes
  pre-shared-key address c.c.c.c key lkdshjfhjkdsfkjfsjkddedswdes
  pre-shared-key address d.d.d.d key lkdshjfhjkdsfkjfsjkddedswdes <- old sonicwall VPN KEY
  pre-shared-key hostname BOB key lkdshjfhjkdsfkjfsjkddedswdes
  pre-shared-key hostname BILL key lkdshjfhjkdsfkjfsjkddedswdes
  pre-shared-key hostname JILL key lkdshjfhjkdsfkjfsjkddedswdes
crypto keyring Site-to-Site_PAN 
  description Keyring used for AES256 Palo Alto config, using IP's
  pre-shared-key address e.e.e.e key uiopadsbfjkahfga;lkdj
  pre-shared-key address f.f.f.f key uiopadsbfjkahfga;lkdj
  pre-shared-key address d.d.d.d key uiopadsbfjkahfga;lkdj <- my new add for Palo
crypto isakmp policy 5
encr aes 256
hash sha256
authentication pre-share
group 2
lifetime 28800
crypto isakmp policy 10
encr 3des
authentication pre-share
group 2
lifetime 28800
crypto isakmp policy 20
encr aes 256
authentication pre-share
group 2
lifetime 28800
crypto isakmp policy 30
encr aes
authentication pre-share
group 2
lifetime 28800
crypto isakmp invalid-spi-recovery
crypto isakmp keepalive 60 3 periodic
crypto isakmp nat keepalive 20
crypto isakmp profile Site-to-Site-Main
   keyring Site-to-Site
   self-identity user-fqdn ASIA
   match identity address a.a.a.a 255.255.255.255
   match identity address b.b.b.b 255.255.255.255
   match identity address c.c.c.c 255.255.255.255
   (Removed SonicWall peer match for d.d.d.d)
   keepalive 60 retry 3
crypto isakmp profile Site-to-Site-Aggressive
   keyring Site-to-Site
   self-identity user-fqdn ASIA
   match identity user-fqdn BOB
   match identity user-fqdn BILL
   match identity user-fqdn JILL
   keepalive 60 retry 3
   initiate mode aggressive
crypto isakmp profile Site-to-Site-Aggressive_PAN
   keyring Site-to-Site_PAN
   self-identity address
   match identity address e.e.e.e 255.255.255.255
   match identity address f.f.f.f 255.255.255.255
   match identity address d.d.d.d 255.255.255.255 <- My new add
   keepalive 10 retry 3
   initiate mode aggressive
crypto ipsec transform-set CSC-TS1 esp-3des esp-sha-hmac
crypto ipsec transform-set CSC-TS2 esp-aes 256 esp-sha-hmac
crypto ipsec transform-set CSC-TS3 esp-des esp-md5-hmac
crypto ipsec transform-set CSC-TS4 esp-aes esp-sha-hmac
crypto ipsec transform-set CSC-TS5 esp-aes 256 esp-sha256-hmac
crypto dynamic-map CSC-DMAP 5
set security-association lifetime kilobytes disable
set security-association lifetime seconds 28800
set transform-set CSC-TS5
set reverse-route distance 240
set reverse-route tag 240
set isakmp-profile Site-to-Site-Aggressive_PAN
reverse-route
crypto dynamic-map CSC-DMAP 10
set security-association lifetime kilobytes disable
set security-association lifetime seconds 28800
set transform-set CSC-TS1 CSC-TS2 CSC-TS3 CSC-TS4
set reverse-route distance 240
set reverse-route tag 240
set isakmp-profile Site-to-Site-Aggressive
reverse-route
crypto dynamic-map CSC-DMAP 20
set security-association lifetime kilobytes disable
set security-association lifetime seconds 28800
set transform-set CSC-TS1 CSC-TS2 CSC-TS3 CSC-TS4
set reverse-route distance 240
set reverse-route tag 240
set isakmp-profile Site-to-Site-Main
reverse-route
crypto map CSC-CMAP 20 ipsec-isakmp dynamic CSC-DMAP
interface G0/0
crypto map CSC-CMAP redundancy dmzvpn <-- I just negate this and re-add and new peers start working.

This is where the connection sits...
show crypto session detail
Interface: GigabitEthernet0/0
Profile: Site-to-Site-Aggressive_PAN
Session status: UP-IDLE
Peer: d.d.d.d port 4500 fvrf: (none) ivrf: (none)
      Phase1_id: d.d.d.d
      Desc: (none)
  IKEv1 SA: local 192.168.221.2/4500 remote d.d.d.d/4500 Active
          Capabilities:DN connid:1473 lifetime:07:31:02

Similar Messages

  • Sync iphone with new computer without removing items from iphone

    When trying to transfer library from iPhone to my new computer, it wants to delete the library from my iPhone. How can I transfer without removing from my phone?

    If you do not have access to the iTunes Library on your Old computer... or its Backup...
    See these 2 Links...
    Syncing to a New Computer...
    https://discussions.apple.com/docs/DOC-3141
    Recovering your iTunes library from your iPod or iOS device
    https://discussions.apple.com/docs/DOC-3991
    If you do have access... See Here...
    iTunes: How to move your music to a new computer
    Or...
    From your OLD computer...
    Copy your ENTIRE iTunes FOLDER to an External Drive... and then from the External Drive to your New Computer..
    Full Details Here  >  http://support.apple.com/kb/HT1751

  • HT204025 Can I remove files from my computer without removing them from iCloud?

    Can I remove files from my computer without removing them from iCloud?

    Reason I'm asking: I did move a folder over, and then went to iCloud.com, and looked in that folder, and it said it was empty. Thanks
    When you move a folder to iCloud Drive, it will upload the contents of this folder to iCloud Drive, but it may take a long tome, even for small items. You may see progress bars, while the contents is uploading.  And the folder may look empty, until it will be updated from iCloud.  For example - shortly after adding the folder "neueBilder" to iCloud Drive.

  • Removing songs from itunes without removing them from ipod

    Is it possible to remove songs from iTunes without removing them from iPod? When I attempt to delete songs from iTunes I get a warning that they'll be deleted from iPod as well. I've got Manually manage music and videos checked under Options in the Summary window.

    You can delete songs from your iTunes/computer hard drive after transferring them to the iPod, and for this you need to set your iPod to manage the iPod content manually.
    However, this is an extremely risky option because when (and not if) there comes a time to restore your iPod, which is a very common fix for iPod problems, then all the music would be erased. If you no longer have the music in iTunes (or any other back up), then all that music would be lost.
    What if the iPod were lost/stolen/needed repair? Again, the music would lost. I strongly recommend a back up, and if computer hard drive space is in short supply, you should seriously consider an external hard drive. They are not expensive, and the cost is well worth it when compared to the loss of all your precious music.
    At the very least back up your music to either cd or dvd before deleting it, particularly any purchased music/videos, as this would have to be bought again if it were lost. See these about backing up media.
    How to back up your media in iTunes.
    Buegie's complete back up strategy.
    To move music from iPod to computer, check out the instructions/suggestions here.
    Music from iPod to computer (using option 2). This a manual method using "hidden folders" and although it works, it can be messy.
    Much easier ways are to use one of the many 3rd party programs that copy music from the iPod to the computer.
    One of the most recommended is Yamipod. This is a free program that transfers music and playlists etc from iPod back to the computer. However, it does not transfer playcounts/ratings etc.
    Another free program is Pod Player.
    There is also CopyPod. This does preserve ratings/playcounts etc if those are important to you but this program is not free. It also supports video transfer.
    If you are using iTunes version 7 or later, then you can transfer purchased iTunes store music from the iPod to an authorized computer by using the "file/transfer purchases from iPod" menu. Note that the maximum of 5 authorized computers applies here.

  • How do I remove a song from an album without removing it from my computer library or another album?

    How do I remove a song from an itunes album on my MacBook without removing it from my library or from another album. It ended up in the wrong album

    When you delete the song, a menu will come up and ask you if you want to trash or keep the file. Select "keep file."   It will no longer be in your song list but it will remain on your harddrive. To add it back in use the --"add to library"--  command in the  drop down "File" Menu (you have to navigagte to where the song is stored on your hard drive and select it-- to add it back in.
    Re: it ended up in the wrong album
    If your songs are going in the wrong place go to the "Get Info" command and check the information under all the tabs (look at a song that's in the right album to see how it's listed) -- one or more of the boxes is incorrect or empty.  Just put  in the right information and close the info window. That should put it back in the right spot for you.

  • HT204053 my boyfriend and i are using the same apple account, i was wondering if there is a way for him to stop recieving txt msgs thats are sent to me through email accounts without removing him from my account altogether?

    my boyfriend and i are using the same apple account, i was wondering if there is a way to stop him recieveing txt msgs that are sent through email addresses without removing him from my account altogether?

    gemmie87 wrote:
    my boyfriend and i are using the same apple account, i was wondering if there is a way to stop him recieveing txt msgs that are sent through email addresses without removing him from my account altogether?
    Or remove you from his, it's moot because You and He are the same account, either get him his own (they are free) or live with this cozy but privacy compromised method.

  • I bought a license for Lr a few years back and installed it on a mac laptop.  I want to move that license to my new iMac and remove it from my old laptop. How?  Thanks!!!

    I bought a license for Lr a few years back and installed it on a mac laptop.  I want to move that license to my new iMac and remove it from my old laptop. How? 
    I downloaded Lr on the new iMac but there does not seem to be a way of "registering" the software to give it functionality. 
    Thanks!!!

    Your Lightroom License key is,
    1. Cross platform Mac and or Win.
    2. It is a single user / owner.
    3. You can have two installations active with one in use at any point in time.
    4. There is no deactivate process like other Photoshop products.
    5. You can uninstall / install as many times as you need as long as you keep the spirit of the license.
    6. The license key is specific to the Lightroom version, i.e License key for LR 4 will not work for LR 5.
    7. You can upgrade i.e. purchase from any version of Lightroom 1,2,3,4 to the latest LR 5.

  • I want to erase my iPod without removing it from my Apple ID so I can restore my iPod 5. But there is no option to do so.

    How do I erase my iPod 5 without removing it from my Apple ID? I want to do this because I need to restore my iPod because I was making someone a clash of clans account and I had to wipe my iPod to do so.

    You have to remove the ID. Go to Settings>General>Reset>Erase all content and settings. You will have to enter your ID to do that.
    The setup the iPod with any ID you want

  • How to sync different image folders from pc without removing images from ipad

    how to sync different image folders from pc without removing images from ipad as ipad asks to replace the already existing images in ipad with the pc folder.

    Spare yourself the frustration, use Photo Manager Pro.
    https://itunes.apple.com/sg/app/photo-manager-pro/id393858562?mt=8

  • Removing email from iPhone without removing it from Mobile me server

    I currently have an iPhone and several email accounts on different servers. All these accounts give me to option to remove mail from my iPhone without removing them from the server. With Mobile me there is no option available to do this that I've been able to to locate on my iPhone. Does anyone know how to prevent the emails pushed to my iphone not being removed from the server when I delete them from my iPhone? Thanks.

    Mobile Me uses the IMAP protocol.
    This allows the iPhone + Server + all other PC/Macs you have your account on to remain in sync. Delete an email, it affects all devices with account, read email, read on all devices with account. Etc. Etc.
    This is normal for any IMAP based account. POP are the accounts that will not keep things up to date or the same.
    By any chance are all the other accounts actually POP? or are they also using IMAP?
    Typically you may find a default global settings in Settings - Mail, Contacts, Calenders - On that screen might be some deletion options.

  • I have all my devices connected to iCloud.  I would like a reduced contact list on my iPhone without removing any from my master list on my computer.  How do I delete contact numbers from my phone without disrupting the master list on my computer?

    I have all my devices connected to iCloud.  I would like a reduced contact list on my iPhone without removing any from my master list on my computer.  How do I delete contact numbers from my iphone without disrupting the master list on my computer?

    Are you trying to reduce the visual clutter on the phone, save space on the phone, or limit the security exposure if your phone is stolen?
    If you are only wanting to reduce the visual clutter and make scrolling through the list faster, you could set up a group on the computer containing only the contacts you want to see on my phone (called, for example, "Show on my Phone") and enable only that group inside Contacts on the phone. You might even have one or more existing groups that you could enable that way (maybe "Family" and "Personal").

  • Adding new feature without recompiling

    i have a question
    i have this program in java that translates one language to another now i want to be able to add another translator later if i required at runtime without recompiling the whole thing.that is i should have the provision of adding new translators feature which i dont know now about, later without compiling.
    if anybody could guide me i will really appreciate that
    thanks

    A factory might do the job if you've organized your existing code properly.
    Assume an interface exists:public interface Translator {
       public String translate(String text);
    }Also suppose you already have a single translator:package my.package;
    public class EnglishToDutchTranslator implements Translator {
       public String translate(String text) {
          return translation;
    }Store this fact in a .properties file or preferences or whereever:ENDU= my.package.EnglishToDutchTranslatorHere's the factory:public final class TranslatorFactory {
       // contains the above name -> tranlator class name mappings
       private static Properties translators;
       // don't instantiate this class
       private TranslatorFactory() { }
       public static Translator getTranslator(String name) {
          String clazz= translators.getProperty(name);
          if (clazz == null) return null;
          try {
             return (Translator)Class.forName(clazz).newInstance();
          catch (Exception e) {
             e.printStackTrace();
             return null;
    }Basically all the factory does is 1) get the fully qualified class name
    given the name of the translator and 2) instantiate an object from that
    class. All that it cares about is that the object implements the Translator
    interface. You can build new translators and register them in that
    properties file. A caller should get a translator as follows:Translater t= TranslatorFactory.getTranslator("ENDU");kind regards,
    Jos

  • How do I move a picture so that it can be used in multiple projects without removing it from current location

    I am organizing several hockey pictures and I am trying to make various projects from the pictures and sometimes I want the same picture in more than one project/album/etc.. Each time I duplicate the version in attempts to move just one of the versios, both are moved to new location and removed from current location. I would greatly appreciate help. Thank you

    Piling on  :  read this.  And then read this.
    Think this:
    Projects are _storage_ containers.
    Albums are _viewing_ containers.
    (In mind keep this:  The naming of "Projects" is the worst interface decision made by Aperture's designers.)
    The Image that is created when you import a digicam file is _stored_ in one and in only one container.
    You can _view_ the Image in as many viewing containers as you want.
    Store them by shoot unless you have a better, complete, workflow.  Don't ever move them from their storage container, except to delete them.
    View them by _output project (small "p")_.  Create as many of these as you need.

  • I recently signed on with iCloud. I find that the prompts interrupt my workflow and the costs of this feature for someone with 200 gigs of data is not competitive. I want to cancel the mail, contacts, email, etc. without Removing data from my Mac. How?

    I recently signed on for iCloud service, but find that it interrupts my workflow too often (which I know I can reset), but will soon exceed my free storage space. I have 200 gigs of data on my local drive and frankly the cost and benefit of having ICloud access to all of it is not competitive. This particular iCloud offering is overpriced for me. I want to cancel all iCloud services but can't seem to find an easy way to do it without removing the data on my local drive, which would be disaster. Need the communities help. Thanks to all.

    Tried this, but unfortunately there was no way to cancel it even when disconnected from the NET. I'm on WIFI which I turned off.
    I keep getting a pop-up that says:
    The same message comes up when you want to cancel or remove any of the other iCloud storage functions including Contacts and Emails. This is obviously a scary thought. Why would APPLE program in this type of message? I'm already at 50% of my FREE storage on iCloud after only 2 weeks. There is no way I'm going to be held hostage by this clearly unacceptable "pay or die" programming lapse when I get to 100%. I know APPLE loves making money. Who doesn't, but this makes no sense to this devoted "Since 1984" Apple fan.

  • Tutorial: Print index cards without removing paper from tray for Officejet Pro 8000.

    The HP Officejet Pro 8000 and Officejet Pro 8000 wireless do not have a slot for inserting index cards and envelopes.
    If you are wanting to print index cards without removing the paper from the tray, follow these steps.
    The steps below are for 3 x 5 index cards.
    1.) Open Microsoft Word
    2.) Go to the Insert tab and insert a rectangle shape
    3.) Draw a rectangle of any size
    4.) Right click on the rectangle and select "Format Autoshape..."
    5.) Under the Size tab, enter 5" for the height and 3" for the width (make sure "Absolute" is selected)
    6.) Under the Layout tab, select "Center" for the horizontal alignment
    7.) Click OK
    8.) Use the keyboard up arrow key to move the rectangle to the top of the page.  Make sure the top edge of the rectangle touches the top edge of the document.
    9.) Print this document on plain 8.5" x 11" paper
    10.) When you want to print an index card, place this 8.5x11 document in the paper tray printed side face up.  Then place an index card over the rectangle and align with the border of the rectangle.  After you print the index card, remove the 8.5x11 paper for the next time you need to print an index card.
    Note 1: This are USA instructions.  If you live in the UK or other countries you may have different paper size standards.

    I can't tell you how much I HATE this printer.  I will never buy an HP product again.  BROTHERS printers are simply and easy to use.

Maybe you are looking for

  • Opening & Closing Stock in P&L Statement

    Dear All, My client is using Tally software preior to SAP B1 Implementation. In Tally the P/L satatment shows  Opening Stock , purchases and  Closing Stock ledgers.We are not using Purchase Accounts posting system. How to map the existing SAP Ledgers

  • Purchases from one Itunes to another?

    On my old windows, I bought 2 seasons of a TV show, a few ipod touch apps and a movie - i logged into my itunes account on my new mac, and they're not there anymore, but show up on my purchase history. Is there any way to get them back?

  • I need a simple widget to show channels and strenght

    I am looking for a simple widget to help me chart signal strenght, channels used, and interfearance around me (so I can use the best AEBS for me). Any suggestions?

  • Performance problem in ABAP programming

    Hi! Please review the following program, LOOP AT TG_PRICE INTO WA_PRICE.     CLEAR WA_VBELN.     READ TABLE TG_VBELN INTO WA_VBELN WITH KEY KNUMV = WA_PRICE-KNUMV                                                POSNR = WA_PRICE-KPOSN.     IF SY-SUBRC

  • Constant problems with size of windows

    Guys, I am having this problem for 2 months already and it would be great if you could help... Maybe I just don't know something simple but anyway - I can't understand what's going on with size of the windows - in all programs, not just Safari. Befor