Re: [pfSense] PFS 2.3.1-RELEASE-p5 and Cisco 5520 IPSEC

2016-07-15 Thread Chris Buechler
On Fri, Jul 15, 2016 at 2:08 PM, Marc R. Meshurle Jr. wrote: > x.x.x.x is the PFSense and y.y.y.y is the Cisco > > Jul 16 00:05:54 charon: 11[IKE] deleting IKE_SA con2000[673] > between x.x.x.x[x.x.x.x]...y.y.y.y[y.y.y.y] > Jul 16 00:05:54 charon: 11[IKE] received DELETE for IKE_SA > con2000[6

Re: [pfSense] PFS 2.3.1-RELEASE-p5 and Cisco 5520 IPSEC

2016-07-15 Thread Eero Volotinen
st 0 > [ SA V V V V V V ] > Jul 16 00:05:53 charon: 15[IKE] initiating Main Mode IKE_SA > con2000[671] to y.y.y.y > Jul 16 00:05:53 charon: 11[CFG] received stroke: initiate 'con2001' > Jul 16 00:05:53 charon: 15[CFG] no IKE_SA named 'con2000' found > Jul 16 00

Re: [pfSense] PFS 2.3.1-RELEASE-p5 and Cisco 5520 IPSEC

2016-07-15 Thread Marc R. Meshurle Jr.
behalf of Chris Buechler Sent: Friday, July 15, 2016 14:29 To: pfSense Support and Discussion Mailing List Subject: Re: [pfSense] PFS 2.3.1-RELEASE-p5 and Cisco 5520 IPSEC On Fri, Jul 15, 2016 at 11:32 AM, Marc R. Meshurle Jr. wrote: > I'm having an issue connecting to a Cisco ASA5520 w

Re: [pfSense] PFS 2.3.1-RELEASE-p5 and Cisco 5520 IPSEC

2016-07-15 Thread Chris Buechler
On Fri, Jul 15, 2016 at 11:32 AM, Marc R. Meshurle Jr. wrote: > I'm having an issue connecting to a Cisco ASA5520 with IPSEC. The vendor with > the Cisco states that Phase 1 is good, but dropping out on Phase 2. We've > matched the Phase 2 proposals up and it still fails on the Phase 2 side. I'v

[pfSense] PFS 2.3.1-RELEASE-p5 and Cisco 5520 IPSEC

2016-07-15 Thread Marc R. Meshurle Jr.
I'm having an issue connecting to a Cisco ASA5520 with IPSEC. The vendor with the Cisco states that Phase 1 is good, but dropping out on Phase 2. We've matched the Phase 2 proposals up and it still fails on the Phase 2 side. I've tried every combination of SA protocols and none stay connected.