what is causing the IKE Main Mode failure?

Referring to the debug output shown below, what is causing the IKE Main Mode failure?

1d00h: ISAKMP (0:1): atts are not acceptable. Next payload is 0

1d00h: ISAKMP (0:1): no offers accepted!

1d00h: ISAKMP (0:1): SA not acceptable!

1d00h: %CRYPTO-6-IKMP_MODE_FAILURE: Processing of Main Mode failed with peer at 150.150.150.1

Referring to the debug output shown below, what is causing the IKE Main Mode failure?

1d00h: ISAKMP (0:1): atts are not acceptable. Next payload is 0

1d00h: ISAKMP (0:1): no offers accepted!

1d00h: ISAKMP (0:1): SA not acceptable!

1d00h: %CRYPTO-6-IKMP_MODE_FAILURE: Processing of Main Mode failed with peer at 150.150.150.1

A.
The Crypto ACL is not a mirror image of the peer.

B.
The IKE Phase I policy does not match on both sides.

C.
The IPSec transform set on the peers do not match.

D.
The received IPsec packet specifies a Security Parameters Index (SPI) that does not exist in the security associations database (SADB).

E.
The pre-shared keys on the peers do not match.



Leave a Reply 0

Your email address will not be published. Required fields are marked *