Sounds like one side doesn't have the vpn access-list configured properly so it doesn't know to tunnel that traffic...
------- Original message ------- > From: Simon Baumann <[email protected]> > Sent: 6.1.'10, 14:08 > > > Hi, > I'm working on the VPN labs, struggeling with task 4.4 > > When I want to verify my configuration (pining 8.9.2.2 so f0/1 from R5), I > get this err when I do a "gebug cry isa" > > 6 11:54:30.579: ISAKMP:(1001): sending packet to 8.9.50.2 my_port 500 > peer_port 500 (I) AG_INIT_EXCH > *Jan 6 11:54:30.579: ISAKMP:(1001):Sending an IKE IPv4 Packet. > *Jan 6 11:54:31.139: ISAKMP (1001): received packet from 8.9.50.2 dport 500 > sport 500 Global (I) AG_INIT_EXCH > *Jan 6 11:54:31.139: %CRYPTO-6-IKMP_NOT_ENCRYPTED: IKE packet from 8.9.50.2 > was not encrypted and it should've been. > > Cisco lists this "solution": > Error Message > > > %CRYPTO-6-IKMP_NOT_ENCRYPTED : IKE packet from [IP_address] was not encrypted > and it should've been. > > Explanation A portion of the IKE is unencrypted, and a portion is > encrypted. This message should have been encrypted but was not. > > Recommended Action Contact the remote peer. > > > > Could you geive me an hint what to check? TIA! > > > > Cheers > > Simon > > _______________________________________________ For more information regarding industry leading CCIE Lab training, please visit www.ipexpert.com
