Velocity Reviews - Computer Hardware Reviews

Velocity Reviews > Newsgroups > Computing > Cisco > PIX ISAKMP: invalid udp len

Reply
Thread Tools

PIX ISAKMP: invalid udp len

 
 
Walter Roberson
Guest
Posts: n/a
 
      07-12-2005
We've just gone through a PIX 6.3 VPN problem in which the characteristic
debug message was

ISAKMP: invalid udp len

This message has been mentioned a very small number of times online,
and one person asked about it, but no solution was given, so I am
documenting it here for future reference.


This is an IPSEC Phase 2 problem, not a Phase 1 problem. Therefore
this problem will not occur unless you -have- managed to find usable
"isakmp policy" and your isakmp key (or certificates) have passed muster.

Because it is Phase 2, it cannot be an "isakmp identity" problem
[the TAC's answer]: the identity is used in Phase 1. In particular
if you see these messages then you know the other end has figured out
who you are:

IPSEC(key_engine_delete_sas): rec'd delete notify from ISAKMP
IPSEC(key_engine_delete_sas): delete all SAs shared with <REMOTEIP>


In our case, the trigger for this debug message was that the other
side had valid isakmp key and isakmp policy (the Phase 1 infrastructure)
but had somehow lost all of its crypto map statements and so could
not negotiate Phase 2 with us.

[Yes, I would have expected a rather more obvious diagnostic in this
situation...]
--
Usenet is like a slice of lemon, wrapped around a large gold brick.
 
Reply With Quote
 
 
 
Reply

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
if len(str(a)) == len(str(r)) and isMult(a, r): faster if isMult isslow? maestro Python 1 08-11-2008 01:17 PM
len(var) is [CONSTANT] equal to len(var) == [CONSTANT]? Tor Erik Soenvisen Python 14 11-23-2006 09:57 PM
PIX VPN and DNS Problem with udp checksum errors Oliver Rahn Cisco 0 08-30-2004 11:28 AM
Cisco Pix 515 Port forwarding range: 10000-50000 (tcp/udp) Andras Kende Cisco 1 04-29-2004 01:15 AM
udp (0) -> udp (0) traffic ? Tom Cisco 2 03-04-2004 06:06 PM



Advertisments