Folks, thanks for the suggestions. I have to check it.

Am 06.01.2010 um 14:59 schrieb Ian Castleman:

> Sounds like one side doesn't have the vpn access-list configured properly so 
> it doesn't know to tunnel that traffic...
> 
> ------- Original message -------
>> From: Simon Baumann <[email protected]>
>> Sent: 6.1.'10,  14:08
>> 
>> 
>> Hi,
>> I'm working on the VPN labs, struggeling with task 4.4
>> 
>> When I want to verify my configuration (pining 8.9.2.2 so f0/1 from R5), I 
>> get this err when I do a "gebug cry isa"
>> 
>> 6 11:54:30.579: ISAKMP:(1001): sending packet to 8.9.50.2 my_port 500 
>> peer_port 500 (I) AG_INIT_EXCH
>> *Jan  6 11:54:30.579: ISAKMP:(1001):Sending an IKE IPv4 Packet.
>> *Jan  6 11:54:31.139: ISAKMP (1001): received packet from 8.9.50.2 dport 500 
>> sport 500 Global (I) AG_INIT_EXCH
>> *Jan  6 11:54:31.139: %CRYPTO-6-IKMP_NOT_ENCRYPTED: IKE packet from 8.9.50.2 
>> was not encrypted and it should've been.
>> 
>> Cisco lists this "solution":
>> Error Message
>> 
>> 
>> %CRYPTO-6-IKMP_NOT_ENCRYPTED : IKE packet from [IP_address] was not 
>> encrypted and it should've been.
>> 
>> Explanation    A portion of the IKE is unencrypted, and a portion is 
>> encrypted. This message should have been encrypted but was not.
>> 
>> Recommended Action    Contact the remote peer.
>> 
>> 
>> 
>> Could you geive me an hint what to check? TIA!
>> 
>> 
>> 
>> Cheers
>> 
>> Simon
>> 
>>  
> 

_______________________________________________
For more information regarding industry leading CCIE Lab training, please visit 
www.ipexpert.com

Reply via email to