Folks, thanks for the suggestions. I have to check it. Am 06.01.2010 um 14:59 schrieb Ian Castleman:
> Sounds like one side doesn't have the vpn access-list configured properly so > it doesn't know to tunnel that traffic... > > ------- Original message ------- >> From: Simon Baumann <[email protected]> >> Sent: 6.1.'10, 14:08 >> >> >> Hi, >> I'm working on the VPN labs, struggeling with task 4.4 >> >> When I want to verify my configuration (pining 8.9.2.2 so f0/1 from R5), I >> get this err when I do a "gebug cry isa" >> >> 6 11:54:30.579: ISAKMP:(1001): sending packet to 8.9.50.2 my_port 500 >> peer_port 500 (I) AG_INIT_EXCH >> *Jan 6 11:54:30.579: ISAKMP:(1001):Sending an IKE IPv4 Packet. >> *Jan 6 11:54:31.139: ISAKMP (1001): received packet from 8.9.50.2 dport 500 >> sport 500 Global (I) AG_INIT_EXCH >> *Jan 6 11:54:31.139: %CRYPTO-6-IKMP_NOT_ENCRYPTED: IKE packet from 8.9.50.2 >> was not encrypted and it should've been. >> >> Cisco lists this "solution": >> Error Message >> >> >> %CRYPTO-6-IKMP_NOT_ENCRYPTED : IKE packet from [IP_address] was not >> encrypted and it should've been. >> >> Explanation A portion of the IKE is unencrypted, and a portion is >> encrypted. This message should have been encrypted but was not. >> >> Recommended Action Contact the remote peer. >> >> >> >> Could you geive me an hint what to check? TIA! >> >> >> >> Cheers >> >> Simon >> >> > _______________________________________________ For more information regarding industry leading CCIE Lab training, please visit www.ipexpert.com
