We have the following topology:

A-router(IPSec) 
<---LAN-->(inside)ASA5505(outside)<-----internet------>B-router(IPSec)


B-router has the following "debug crypto isakmp error" messages keep repeating.

========
*Apr  8 07:23:25.772: ISAKMP:(1316):peer 22x.x.x.y not responding!
*Apr  8 07:23:40.788: ISAKMP:(1316):deleting SA reason "Death by retransmission 
throw" state (R) QM_IDLE       (peer 220.227.43.225)
*Apr  8 07:23:40.788: ISAKMP:(1316):deleting SA reason "Death by retransmission 
throw" state (R) QM_IDLE       (peer 220.227.43.225) 
*Apr  8 07:23:40.788: ISAKMP:(0):Can't decrement IKE Call Admission Control 
stat incoming_active since it's already 0.
*Apr  8 07:24:10.700: ISAKMP:(1319): no outgoing phase 1 packet to retransmit. 
QM_IDLE      
*Apr  8 07:24:10.892: ISAKMP:(1319): no outgoing phase 1 packet to retransmit. 
QM_IDLE      
*Apr  8 07:24:20.892: ISAKMP:(1319): no outgoing phase 1 packet to retransmit. 
QM_IDLE      
==========


ASA5505 has IPSec passthrough configured and NAT for A-router.
B-router is using public IP.
22x.x.x.y is ASA5505 public IP.

Then, what will be the root causes for the above error messages ?

Thanks!


_______________________________________________
cisco-nsp mailing list  [email protected]
https://puck.nether.net/mailman/listinfo/cisco-nsp
archive at http://puck.nether.net/pipermail/cisco-nsp/

Reply via email to