IOS VPN will not respond to Cisco VPN Client connections.
Hi all,
I am about to set my routers on fire here.
I have two 2921 ISRs both with Security licenses on separate leased lines. I have configured one to accept VPN connections from our Cisco VPN Client remote workers.
I have followed the set up process I used on another site with an 1841/Sec router and the same clients and I have also checked against the config given in the latest IOS15 EasyVPN guide.
With all debugs active, all I see is
038062: Dec 8 14:03:04.519: ISAKMP (0): received packet from x.y.z.z dport 500 sport 60225 Global (N) NEW SA
038063: Dec 8 14:03:04.519: ISAKMP: Created a peer struct for x.y.z.z, peer port 60225
038064: Dec 8 14:03:04.519: ISAKMP: New peer created peer = 0x3972090C peer_handle = 0x8001D881
038065: Dec 8 14:03:04.523: ISAKMP: Locking peer struct 0x3972090C, refcount 1 for crypto_isakmp_process_block
038066: Dec 8 14:03:04.523: ISAKMP:(0):Setting client config settings 3E156D70
038067: Dec 8 14:03:10.027: ISAKMP (0): received packet from x.y.z.z dport 500 sport 60225 Global (R) MM_NO_STATE
Below is the abridged config.
System image file is "flash0:c2900-universalk9-mz.SPA.154-1.T1.bin"
aaa new-model
aaa authentication login default local
aaa authentication login VPNAUTH local
aaa authorization exec default local
aaa authorization network VPN local
aaa session-id common
crypto isakmp policy 10
encr aes
authentication pre-share
group 14
crypto isakmp client configuration group VPN
key ****-****-****-****
dns 192.168.177.207 192.168.177.3
domain xxx.local
pool VPNADDRESSES
acl REVERSEROUTE
crypto ipsec transform-set HASH esp-aes esp-sha-hmac
mode tunnel
crypto ipsec profile IPSECPROFILE
set transform-set HASH
crypto dynamic-map VPN 1
set transform-set HASH
reverse-route
crypto map VPN client authentication list VPNAUTH
crypto map VPN isakmp authorization list VPN
crypto map VPN client configuration address respond
crypto map VPN 65535 ipsec-isakmp dynamic VPN
ip local pool VPNADDRESSES 172.16.198.16 172.16.198.31
ip access-list extended REVERSEROUTE
permit ip 192.168.0.0 0.0.255.255 any
permit ip 10.0.0.0 0.0.0.255 any
ip access-list extended FIREWALL
2 permit udp any host a.b.c.d eq non500-isakmp
3 permit udp any host a.b.c.d eq isakmp
4 permit ahp any host a.b.c.d
5 permit esp any host a.b.c.d
If anyone can see anything wrong, I would be so pleased and it would save the destruction of an ostensibly innocent router.
Thanks,
Paul
> I actually love you. Thank you so much.
Sorry, I'm married ... ;-)
> Im not using a virtual template. Can I get away without the Crypto Map if I use one...? All my tunnels are VTIs
oh yes, I could have seen that ...
crypto isakmp profile VPN-RA
match identity group VPN
client authentication list VPNAUTH
isakmp authorization list VPN
client configuration address respond
virtual-template 1
interface Virtual-Template1 type tunnel
description Tunnel fuer Cisco VPN-Client
ip unnumbered GigabitEthernet0/0
ip virtual-reassembly in
tunnel mode ipsec ipv4
tunnel protection ipsec profile IPSECPROFILE
Your isakmp-config and ipsec profile stays the same.
Similar Messages
-
Help, I have a iPhone 5s, plugged it in for the night, and the next day it wont respond. I mean to anything. It wont charge add volume power connecting to itunes anything. I can't plug it in to iTunes, non of the buttons work, power +home, anything!
Hey Ashtonfr!
I have an article for you that will help you fully troubleshoot this issue:
iPhone: Hardware troubleshooting
http://support.apple.com/kb/ts2802
Will not turn on, will not turn on unless connected to power, or unexpected power off
Verify that the Sleep/Wake button functions. If it does not function, inspect it for signs of damage. If the button is damaged or is not functioning when pressed, seek service.
Check if a Liquid Contact Indicator (LCI) is activated or there are signs of corrosion. Learn about LCIsand corrosion.
Connect the iPhone to the iPhone's USB power adapter and let it charge for at least ten minutes.
After at least 30 minutes, if:
The home screen appears: The iPhone should be working. Update to the latest version of iOS if necessary. Continue charging it until it is completely charged and you see this battery icon in the upper-right corner of the screen . Then unplug the phone from power. If it immediately turns off, seek service.
The low-battery image appears, even after the phone has charged for at least 20 minutes: See "iPhone displays the low-battery image and is unresponsive" symptom in this article.
Something other than the Home screen or Low Battery image appears, continue with this article for further troubleshooting steps.
If the iPhone did not turn on, reset it while connected to the iPhone USB power adapter.
If the display turns on, go to step 4.
If the display remains black, go to next step.
Connect the iPhone to a computer and open iTunes. If iTunes recognizes the iPhone and indicates that it is in recovery mode, attempt to restore the iPhone. If the iPhone doesn't appear in iTunes or if you have difficulties in restoring the iPhone, see this article for further assistance.
If restoring the iPhone resolved the issue, go to step 4. If restoring the iPhone did not solve the issue, seek service.
Thanks for using the Apple Support Communities. Have a good one!
-Braden -
My iPad mini was working fine then screen black and will not. Respond to any buttons or connect to iTunes
Plug it into the wall charger an wait for at least 30 minutes.
Try this - Reset the iPad by holding down on the Sleep and Home buttons at the same time for about 10-15 seconds until the Apple Logo appears - ignore the red slider - let go of the buttons. (This is equivalent to rebooting your computer.) No data/files will be erased. http://support.apple.com/kb/ht1430
Frozen or unresponsive iPad
Resolve these most common issues:
• Display remains black or blank
• Touch screen not responding
• Application unexpectedly closes or freezes
http://www.apple.com/support/ipad/assistant/ipad/
iPad Frozen, not responding, how to fix
http://appletoolbox.com/2012/07/ipad-frozen-not-responding-how-to-fix/
iPad Frozen? How to Force Quit an App, Reset or Restart Your iPad
http://ipadacademy.com/2010/11/ipad-frozen-how-to-force-quit-an-app-reset-or-res tart-your-ipad
Black or Blank Screen on iPad or iPhone
http://appletoolbox.com/2012/10/black-or-blank-screen-on-ipad-or-iphone/
What to Do When Your iPad Won't Turn On
http://ipad.about.com/od/iPad_Troubleshooting/ss/What-To-Do-When-Your-Ipad-Wo-No t-Turn-On.htm
iOS: Not responding or does not turn on
http://support.apple.com/kb/TS3281
iPad: Basic troubleshooting
http://support.apple.com/kb/TS3274
Cheers, Tom -
Hello, so today I realized that my iPhone with iOS 6 is frozen on the music. I can get back to the home screen but I can't get the music player to work because its frozen on the w's and will not respond to touch. I would be grateful for any help on this.
Hi deamayfield,
Thanks for visiting Apple Support Communities.
If your Music app is unresponsive, try restarting/resetting your iPhone:
iOS: Turning off and on (restarting) and resetting
http://support.apple.com/kb/ht1430
Best,
Jeremy -
IOS 8 upgrade caused me to lose the games I paid for; apple says I hafta restore, which means losing a week of work; are there other options. the game app hooked on words will not respond to several emails
Funny you should ask... At about the same time that the Xserve was discontinued, we also lost our channel rep of nearly 14 years. Right now we are not sure who our rep is. I have however, sent this to as many people in Apple that I could think of. And I plan on continuing to reach out to as many as possible.
The sad reality is that this decision is impacting customer deployments and the future of customer installations. Apple strives for market share and loves to tout those numbers. But the numbers we fought for over these last eight years are going to disappear.
As much as this impacts our business, we are making up for it in enterprise deployment of systems. We will survive and lead in our geographic area. I do not fear that. But OS X Server is a UNIX server and with it has come all of the benefits of a UNIX system, including legitimacy in a data center. The Intel Xserve cemented this reality because of its hardware configuration and form factor. Yes, we have G4 and G5s still in service. But those are mostly in all Mac shops that understand the benefits and can work around the buzz word limitations. But fortune 100/500 IT departments did not really get on board until the release of the Intel server.
Still beating the drum to raise awareness. Spread the word and talk to your Apple reps.
Also, ask about the direction that Apple's Enterprise team is going. If the news I hear is correct, then our fears about all things pro and enterprise going away are likely true. -
Vlan interface will not respond to ping
cisco 2651xm router
IOS: c2600-ipbasek9-mz.124-9.T1.bin
I have two vlans configured on this router as follows:
interface Vlan1
ip address 172.16.1.30 255.255.0.0
ip nat inside
interface Vlan2
ip address 192.168.0.1 255.255.255.0
ip nat inside
from a pc on 172.16.1.x I can ping 172.16.1.30 and get a response.
But from a pc on 192.168.0.x if i ping 192.168.0.1 I get failure, and I've tried this on more than one pc. The 192.168.0.1 vlan will not respond. This is baffling and I can't work out why. Thanks if anyone can help.thanks for your response:
#show run
Building configuration...
Current configuration : 7859 bytes
! Last configuration change at 16:56:37 gmt Tue Mar 3 2015
version 12.4
no service timestamps debug uptime
no service timestamps log uptime
no service password-encryption
hostname ipbase
boot-start-marker
boot system flash c2600-ipbasek9-mz.124-17.bin
boot-end-marker
no logging buffered
no logging console
enable secret 5 <secret>
enable password <password>
no aaa new-model
resource policy
clock timezone gmt 0
clock summer-time gmt date Mar 30 2011 0:00 Sep 30 2011 0:00
no network-clock-participate slot 1
no network-clock-participate wic 0
ip cef
ip name-server 156.154.70.22
ip name-server 156.154.71.22
archive
log config
hidekeys
interface ATM0/0
mtu 1478
no ip address
ip tcp adjust-mss 1452
no ip mroute-cache
no atm ilmi-keepalive
dsl operating-mode auto
clock rate aal5 7000000
hold-queue 224 in
pvc 0/38
encapsulation aal5mux ppp dialer
dialer pool-member 1
interface ATM0/0.1 point-to-point
ip tcp adjust-mss 1452
no snmp trap link-status
pvc 8/35
pppoe-client dial-pool-number 1
interface FastEthernet0/0
no ip address
shutdown
duplex auto
speed auto
interface FastEthernet0/1
no ip address
shutdown
duplex auto
speed auto
interface FastEthernet1/0
interface FastEthernet1/1
interface FastEthernet1/2e
interface FastEthernet1/3
interface FastEthernet1/4
interface FastEthernet1/5
interface FastEthernet1/6
interface FastEthernet1/7
interface FastEthernet1/8
interface FastEthernet1/9
interface FastEthernet1/10
interface FastEthernet1/11
interface FastEthernet1/12
description cable to 192.168.0.0
switchport access vlan 2
interface FastEthernet1/13
description cable to 192.168.0.0
switchport access vlan 2
interface FastEthernet1/14
interface FastEthernet1/15
interface Vlan1
ip address 172.16.1.30 255.255.0.0
ip nat inside
interface Vlan2
ip address 192.168.0.1 255.255.255.0
ip nat inside
interface Dialer0
bandwidth 6144
ip address negotiated previous
no ip redirects
no ip proxy-arp
ip nbar protocol-discovery
ip flow egress
ip nat outside
encapsulation ppp
dialer pool 1
dialer idle-timeout 0
dialer persistent
dialer-group 1
no cdp enable
ppp authentication chap callin
ppp chap hostname <username>
ppp chap password 0 <password>
ip route 0.0.0.0 0.0.0.0 Dialer0
ip route 10.8.0.0 255.255.255.0 172.16.1.43
ip http server
no ip http secure-server
ip nat inside source list 1 interface Dialer0 overload
ip nat inside source static tcp 172.16.1.54 1194 interface Dialer0 1194
ip nat inside source static tcp 172.16.1.54 80 interface Dialer0 80
ip nat inside source static tcp 172.16.1.57 1937 interface Dialer0 1937
ip nat inside source static tcp 172.16.1.56 1936 interface Dialer0 1936
ip nat inside source static tcp 172.16.1.58 1938 interface Dialer0 1938
ip nat inside source static udp 172.16.1.43 514 interface Dialer0 514
ip nat inside source static udp 172.16.1.43 5060 interface Dialer0 5060
ip nat inside source static udp 172.16.1.43 10050 interface Dialer0 10050
ip nat inside source static udp 172.16.1.43 10049 interface Dialer0 10049
ip nat inside source static udp 172.16.1.43 10048 interface Dialer0 10048
ip nat inside source static udp 172.16.1.43 10047 interface Dialer0 10047
ip nat inside source static udp 172.16.1.43 10046 interface Dialer0 10046
ip nat inside source static udp 172.16.1.43 10045 interface Dialer0 10045
ip nat inside source static udp 172.16.1.43 10044 interface Dialer0 10044
ip nat inside source static udp 172.16.1.43 10043 interface Dialer0 10043
ip nat inside source static udp 172.16.1.43 10042 interface Dialer0 10042
ip nat inside source static udp 172.16.1.43 10041 interface Dialer0 10041
ip nat inside source static udp 172.16.1.43 10040 interface Dialer0 10040
ip nat inside source static udp 172.16.1.43 10039 interface Dialer0 10039
ip nat inside source static udp 172.16.1.43 10038 interface Dialer0 10038
ip nat inside source static udp 172.16.1.43 10037 interface Dialer0 10037
ip nat inside source static udp 172.16.1.43 10036 interface Dialer0 10036
ip nat inside source static udp 172.16.1.43 10035 interface Dialer0 10035
ip nat inside source static udp 172.16.1.43 10034 interface Dialer0 10034
ip nat inside source static udp 172.16.1.43 10033 interface Dialer0 10033
ip nat inside source static udp 172.16.1.43 10032 interface Dialer0 10032
ip nat inside source static udp 172.16.1.43 10031 interface Dialer0 10031
ip nat inside source static udp 172.16.1.43 10030 interface Dialer0 10030
ip nat inside source static udp 172.16.1.43 10029 interface Dialer0 10029
ip nat inside source static udp 172.16.1.43 10028 interface Dialer0 10028
ip nat inside source static udp 172.16.1.43 10027 interface Dialer0 10027
ip nat inside source static udp 172.16.1.43 10026 interface Dialer0 10026
ip nat inside source static udp 172.16.1.43 10025 interface Dialer0 10025
ip nat inside source static udp 172.16.1.43 10024 interface Dialer0 10024
ip nat inside source static udp 172.16.1.43 10023 interface Dialer0 10023
ip nat inside source static udp 172.16.1.43 10022 interface Dialer0 10022
ip nat inside source static udp 172.16.1.43 10021 interface Dialer0 10021
ip nat inside source static udp 172.16.1.43 10020 interface Dialer0 10020
ip nat inside source static udp 172.16.1.43 10019 interface Dialer0 10019
ip nat inside source static udp 172.16.1.43 10018 interface Dialer0 10018
ip nat inside source static udp 172.16.1.43 10017 interface Dialer0 10017
ip nat inside source static udp 172.16.1.43 10016 interface Dialer0 10016
ip nat inside source static udp 172.16.1.43 10015 interface Dialer0 10015
ip nat inside source static udp 172.16.1.43 10014 interface Dialer0 10014
ip nat inside source static udp 172.16.1.43 10013 interface Dialer0 10013
ip nat inside source static udp 172.16.1.43 10012 interface Dialer0 10012
ip nat inside source static udp 172.16.1.43 10011 interface Dialer0 10011
ip nat inside source static udp 172.16.1.43 10010 interface Dialer0 10010
ip nat inside source static udp 172.16.1.43 10009 interface Dialer0 10009
ip nat inside source static udp 172.16.1.43 10008 interface Dialer0 10008
ip nat inside source static udp 172.16.1.43 10007 interface Dialer0 10007
ip nat inside source static udp 172.16.1.43 10006 interface Dialer0 10006
ip nat inside source static udp 172.16.1.43 10005 interface Dialer0 10005
ip nat inside source static udp 172.16.1.43 10004 interface Dialer0 10004
ip nat inside source static udp 172.16.1.43 10003 interface Dialer0 10003
ip nat inside source static udp 172.16.1.43 10002 interface Dialer0 10002
ip nat inside source static udp 172.16.1.43 10001 interface Dialer0 10001
ip nat inside source static udp 172.16.1.43 10000 interface Dialer0 10000
ip nat inside source static tcp 172.16.1.43 25 interface Dialer0 25
ip nat inside source static tcp 172.16.1.250 1935 interface Dialer0 1935
logging trap debugging
logging facility local6
logging 172.16.1.43
access-list 1 permit 192.168.0.0 0.0.0.255
access-list 1 permit 172.16.0.0 0.0.255.255
access-list 2 permit 172.16.0.0 0.0.255.255
access-list 10 permit 172.16.1.43
access-list 10 permit 172.16.1.13
access-list 10 deny any
dialer-list 1 protocol ip permit
snmp-server community public RO 10
control-plane
bridge 1 protocol ieee
line con 0
line aux 0
line vty 0 4
access-class 2 in
password <password>
login
ntp authenticate
ntp clock-period 17208300
ntp source Dialer0
ntp server 129.215.160.240
ntp server 78.129.239.26
ntp server 143.210.16.201
ntp server 82.219.4.31
end -
Itunes will not respond to my ipod touch, i have re-installed countless times and it still is not working. i have also tried different USB's and nothing. please help!
- Try here:
iOS: Device not recognized in iTunes for Windows
- Next try a different computer to help determine if you have a computer or iPod problem. -
HT5457 I have added this latest download to my iPad and now the iPad will not respond
I have updated my iPad with the latest version iOS 6 download and now my iPad only has the Apple icon displayed. I have attempted to to hold both buttons at the same time and the screen bounces a strange lined gray pic for seconds and bounces back to the Apple icon. any ideas why the iPad will not respond?
I have updated my iPad with the latest version iOS 6 download and now my iPad only has the Apple icon displayed. I have attempted to to hold both buttons at the same time and the screen bounces a strange lined gray pic for seconds and bounces back to the Apple icon. any ideas why the iPad will not respond?
-
My iPad is frozen with the message not enough storage. Options are close and settings but it will not respond to buttons and will not allow me to turn it completely off. How do I get past that message?
Delete some apps, files, photos, videos, movies, etc to free up some space.
How much space is your Other using? You may be able to reduce.
How Do I Get Rid Of The “Other” Data Stored On My iPad Or iPhone?
http://tinyurl.com/85w6xwn
With an iOS device, the “Other” space in iTunes is used to store things like documents, settings, caches, and a few other important items. If you sync lots of documents to apps like GoodReader, DropCopy, or anything else that reads external files, your storage use can skyrocket. With iOS 5/6, you can see exactly which applications are taking up the most space. Just head to Settings > General > Usage, and tap the button labeled Show All Apps. The storage section will show you the app and how much storage space it is taking up. Tap on the app name to get a description of the additional storage space being used by the app’s documents and data. You can remove the storage-hogging application and all of its data directly from this screen, or manually remove the data by opening the app. Some applications, especially those designed by Apple, will allow you to remove stored data by swiping from left to right on the item to reveal a Delete button.
Cheers, Tom -
TS1398 my wi fi on my i touch 3rd gen will not respond any suggentions as what to do?
need help with i touch 3rd generation wi fi is grey and will not respond, any suggestion?
See:
iOS: Wi-Fi or Bluetooth settings grayed out or dim
It is frequently a hardware problem and an appointment at the Genius Bar of an Apple store is in order. -
TS3274 Screen frozen on an email page; will not respond to touch gestures?
My screen is frozen on a email page; will not respond to hand or finger gestures?
Close the mail app and reset your iPad.
Closing apps in iOS 7 works like this. Drag the app up from the multitasking display. Double tap the home button and you will see apps lined up going left to right across the screen. Swipe to get to the app that you want to close and then swipe "up" on the app preview thumbnail to close it.
Reset the iPad by holding down on the sleep and home buttons at the same time for about 10-15 seconds until the Apple Logo appears - ignore the red slider if it appears on the screen - let go of the buttons. Let the iPad start up. -
my iphone 4s is stuck on lock screen it will not respond to my finger to slide it open but it responds to my finger when itouch the on screen home button ......
Hello samayaa,
Thanks for using Apple Support Communities.
Have you tried either restarting or resetting your iPhone? If not please do so by following the directions in the article below.
Turn your iOS device off and on (restart) and reset
http://support.apple.com/kb/ht1430
Take care,
Alex H. -
my ipod has a black screen. When I hold it at an angle i can see the unlock bar and date/time. It will not respond to my touch to unlock it. Any ideas to what is wrong with it?
Try:
- Reset the iOS device. Nothing will be lost
Reset iOS device: Hold down the On/Off button and the Home button at the same time for at
least ten seconds, until the Apple logo appears.
- Restore from backup. See:
iOS: How to back up
- Restore to factory settings/new iOS device.
- Make an appointment at the Genius Bar of an Apple store.
Apple Retail Store - Genius Bar -
screen went white, then turned blank and will not respond to the buttons i touch. it is also able to open up now somehow, so i can see the inside
Let the battery fully drain. After charging for at least an hour try:
iOS: Not responding or does not turn on
If not successful time for an appointment at the Genius Bar of an Apple store. -
6500 IOS HSRP Gateway not responding to ARP requests
WS-C6509, running Native IOS version 12.2(33)SXH4. Pair of 6500 configured with HSRP serving as Gateway to down stream clients
Ping requests from clients not having a Default Gateway (AIX Server Team recommendation) failing.
Packet capture show ARP requests being received by Gateway 6500, but Gateway will not respond for up to 30 seconds at which point ping requests will start working. But after a period of inactivity, the cycle starts over again - 30 second delay before traffic starts flowing.
Having a Default Gateway is a separate discussion. I'm just interested in being able to provide technical reason why this is occuring.
Anyone experience this?
Any suggestions for addtional troubleshooting measures?
Thanks in advance.Looks to me like a timer problem - maybe a ARP timer on the clients? Check the ARP tables of your clients during your tests.
HTH
Maybe you are looking for
-
Outgoing cash Payment line item account not printed
Hi, In case any cash payment raised through outgoing payment, line item(account name, amount, etc..) table is printed. If check payment, we can get the print(Line item) out. If anybody knows the reason for not printing the table. please tell me. T
-
Best way to handle session timeout
Hello All, oracle 11g, Apex ver 3.1.2 I am bit confused about the sessoin handling mecahnism for the users . Which is the best way to handle session for the users is it programatically or by DBA admin level. What are the pros and cons going DBA Level
-
ERROR: The new SAP tools in /usr/sap/DEV/EHPI/abap/exe cannot connect
Hi All. I am attempting to upgrade my ECC 6.0 EPH3 system to EPH4.(System 'i' V6R1M1) I am hitting an error on phase PREP_INIT/CHECKPROF_INI which states 'ERROR: The new SAP tools in /usr/sap/DEV/EHPI/abap/exe cannot connect to your database.' The l
-
Importing multiple excel sheets into DIAdem
Hello, I have an Excel file with multiple sheets. I am trying to import data from cells on each sheet into DIAdem. I am capable of importing anything I want so far using a VBS Script, but only from one sheet at a time. In order to import from another
-
HELP, i've accidentally emptied my trash with my photos in it
Is there a way that I can restore any of the photos?