What does this output suggest?

You are troubleshooting a site-to-site VPN issue where the tunnel is not establishing. After
issuing the debug crypto isakmp command on the headend router, you see the following
output. What does this output suggest?
1d00h: ISAKMP (0:1): atts are not acceptable. Next payload is 0
1d00h: ISAKMP (0:1); no offers accepted!
1d00h: ISAKMP (0:1): SA not acceptable!
1d00h: %CRYPTO-6-IKMP_MODE_FAILURE. Processing of Main Mode failed with peer at
10.10.10.10

You are troubleshooting a site-to-site VPN issue where the tunnel is not establishing. After
issuing the debug crypto isakmp command on the headend router, you see the following
output. What does this output suggest?
1d00h: ISAKMP (0:1): atts are not acceptable. Next payload is 0
1d00h: ISAKMP (0:1); no offers accepted!
1d00h: ISAKMP (0:1): SA not acceptable!
1d00h: %CRYPTO-6-IKMP_MODE_FAILURE. Processing of Main Mode failed with peer at
10.10.10.10

A.
Phase 1 policy does not match on both sides.

B.
The transform set does not match on both sides.

C.
ISAKMP is not enabled on the remote peer.

D.
There is a mismatch in the ACL that identifies interesting traffic.



Leave a Reply 1

Your email address will not be published. Required fields are marked *