What does this output suggest?

You are troubleshooting a site-to-site VPN issue where the tunnel is not establishing. After
issuing the debug crypto ipsec command on the headend router, you see the following
output. What does this output suggest?
1d00h: IPSec (validate_proposal): transform proposal
(port 3, trans 2, hmac_alg 2) not supported
1d00h: ISAKMP (0:2) : atts not acceptable. Next payload is 0
1d00h: ISAKMP (0:2) SA not acceptable

You are troubleshooting a site-to-site VPN issue where the tunnel is not establishing. After
issuing the debug crypto ipsec command on the headend router, you see the following
output. What does this output suggest?
1d00h: IPSec (validate_proposal): transform proposal
(port 3, trans 2, hmac_alg 2) not supported
1d00h: ISAKMP (0:2) : atts not acceptable. Next payload is 0
1d00h: ISAKMP (0:2) SA not acceptable

A.
Phase 1 policy does not match on both sides.

B.
The Phase 2 transform set does not match on both sides.

C.
ISAKMP is not enabled on the remote peer.

D.
The crypto map is not applied on the remote peer.

E.
The Phase 1 transform set does not match on both sides.



Leave a Reply 1

Your email address will not be published. Required fields are marked *