Sounds like one side doesn't have the vpn access-list configured properly so it 
doesn't know to tunnel that traffic...

------- Original message -------
> From: Simon Baumann <[email protected]>
> Sent: 6.1.'10,  14:08
> 
> 
> Hi,
> I'm working on the VPN labs, struggeling with task 4.4
> 
> When I want to verify my configuration (pining 8.9.2.2 so f0/1 from R5), I 
> get this err when I do a "gebug cry isa"
> 
> 6 11:54:30.579: ISAKMP:(1001): sending packet to 8.9.50.2 my_port 500 
> peer_port 500 (I) AG_INIT_EXCH
> *Jan  6 11:54:30.579: ISAKMP:(1001):Sending an IKE IPv4 Packet.
> *Jan  6 11:54:31.139: ISAKMP (1001): received packet from 8.9.50.2 dport 500 
> sport 500 Global (I) AG_INIT_EXCH
> *Jan  6 11:54:31.139: %CRYPTO-6-IKMP_NOT_ENCRYPTED: IKE packet from 8.9.50.2 
> was not encrypted and it should've been.
> 
> Cisco lists this "solution":
> Error Message 
> 
> 
> %CRYPTO-6-IKMP_NOT_ENCRYPTED : IKE packet from [IP_address] was not encrypted 
> and it should've been.
> 
> Explanation    A portion of the IKE is unencrypted, and a portion is 
> encrypted. This message should have been encrypted but was not.
> 
> Recommended Action    Contact the remote peer.
> 
> 
> 
> Could you geive me an hint what to check? TIA!
> 
> 
> 
> Cheers
> 
> Simon
> 
>  

_______________________________________________
For more information regarding industry leading CCIE Lab training, please visit 
www.ipexpert.com

Reply via email to