Failing Phase2 Auth - IPSec - All IPSec SA proposals found unacceptable

I'm getting the Below Debug info when I try to Connect my Client to
the PIX 515e.

The Client is an iPhone. Seems like I have all of the Transforms in
there.

How can I trouble shoot this?

Thanks!
  Scott<-



4:15:32 PM   %PIX-3-713119: Group = <group>, Username = <user>, IP =
<ip>(unresolved), PHASE 1 COMPLETED
4:15:32 PM   %PIX-5-713904: Group = <group>, Username = <user>, IP =
<ip>(unresolved), All IPSec SA proposals found unacceptable!
4:15:32 PM   %PIX-3-713902: Group = <group>, Username = <user>, IP =
<ip>(unresolved), QM FSM error (P2 struct &0x2452b08, mess id
0x9193376c)!
4:15:32 PM   %PIX-3-713902: Group = <group>, Username = <user>, IP =
<ip>(unresolved), Removing peer from correlator table failed, no
match!
4:15:32 PM   %PIX-4-113019: Group = <group>, Username = <user>, IP =
<ip>(unresolved), Session disconnected. Session Type: IPSec, Duration:
0h:00m:00s, Bytes xmt: 0, Bytes rcv: 0, Reason: Phase 2 Mismatch
4:15:31 PM   %PIX-6-713172: Group = <group>, IP = <ip>(unresolved),
Automatic NAT Detection Status: Remote end IS behind a NAT device This
end IS behind a NAT device
4:15:31 PM   %PIX-6-113012: AAA user authentication Successful : local
database : user = <user>
4:15:31 PM   %PIX-6-113009: AAA retrieved default group policy
(<group>) for user = <user>
4:15:31 PM   %PIX-6-113008: AAA transaction status ACCEPT : user =
<user>
4:15:31 PM   %PIX-5-713130: Group = <group>, Username = <user>, IP =
<ip>(unresolved), Received unsupported transaction mode attribute: 5
4:15:31 PM   %PIX-6-713184: Group = <group>, Username = <user>, IP =
<ip>(unresolved), Client Type: iPhone OS Client Application Version:
2.2
4:15:31 PM   %PIX-5-713131: Group = <group>, Username = <user>, IP =
<ip>(unresolved), Received unknown transaction mode attribute: 28683
4:15:31 PM   %PIX-6-713228: Group = <group>, Username = <user>, IP =
<ip>(unresolved), Assigned private IP address <IpSecIP>(unresolved) to
remote user
0
11/27/2008 12:37:32 AM
comp.dcom.sys.cisco 25294 articles. 25 followers. Post Follow

1 Replies
490 Views

Similar Articles

[PageSpeed] 19
scooter133@gmail.com wrote:
> I'm getting the Below Debug info when I try to Connect my Client to
> the PIX 515e.
> 
> The Client is an iPhone. Seems like I have all of the Transforms in
> there.
> 
> How can I trouble shoot this?
> 
> Thanks!
>   Scott<-
> 
> 
> 
> 4:15:32 PM   %PIX-3-713119: Group = <group>, Username = <user>, IP =
> <ip>(unresolved), PHASE 1 COMPLETED
> 4:15:32 PM   %PIX-5-713904: Group = <group>, Username = <user>, IP =
> <ip>(unresolved), All IPSec SA proposals found unacceptable!
> 4:15:32 PM   %PIX-3-713902: Group = <group>, Username = <user>, IP =
> <ip>(unresolved), QM FSM error (P2 struct &0x2452b08, mess id
> 0x9193376c)!
> 4:15:32 PM   %PIX-3-713902: Group = <group>, Username = <user>, IP =
> <ip>(unresolved), Removing peer from correlator table failed, no
> match!
> 4:15:32 PM   %PIX-4-113019: Group = <group>, Username = <user>, IP =
> <ip>(unresolved), Session disconnected. Session Type: IPSec, Duration:
> 0h:00m:00s, Bytes xmt: 0, Bytes rcv: 0, Reason: Phase 2 Mismatch
> 4:15:31 PM   %PIX-6-713172: Group = <group>, IP = <ip>(unresolved),
> Automatic NAT Detection Status: Remote end IS behind a NAT device This
> end IS behind a NAT device
> 4:15:31 PM   %PIX-6-113012: AAA user authentication Successful : local
> database : user = <user>
> 4:15:31 PM   %PIX-6-113009: AAA retrieved default group policy
> (<group>) for user = <user>
> 4:15:31 PM   %PIX-6-113008: AAA transaction status ACCEPT : user =
> <user>
> 4:15:31 PM   %PIX-5-713130: Group = <group>, Username = <user>, IP =
> <ip>(unresolved), Received unsupported transaction mode attribute: 5
> 4:15:31 PM   %PIX-6-713184: Group = <group>, Username = <user>, IP =
> <ip>(unresolved), Client Type: iPhone OS Client Application Version:
> 2.2
> 4:15:31 PM   %PIX-5-713131: Group = <group>, Username = <user>, IP =
> <ip>(unresolved), Received unknown transaction mode attribute: 28683
> 4:15:31 PM   %PIX-6-713228: Group = <group>, Username = <user>, IP =
> <ip>(unresolved), Assigned private IP address <IpSecIP>(unresolved) to
> remote user

Did a quick search on Google for the term "iphone ipsec transforms" and 
received plenty of results.

The first link looked interesting in terms of identifying transform 
limitations of the iPhone:

http://www.networkworld.com/community/node/23023

Perhaps you'll find what you are looking for in that document, or one of 
the others within the search results.

Best Regards,
News Reader
0
News
11/27/2008 2:50:46 AM
Reply:
Similar Artilces:

dlsym failed #2
Hi I want to get a address of a function at runtime by using dlsym. This is the sample code i have written. (This is a sample code. In actual implementation _CreateVirtualProcess in a seperate shared library) //--Main.cpp #include <stdio.h> #include <unistd.h> #include <stdlib.h> #include <sys/stat.h> #include <sys/types.h> #include <fcntl.h> #include <dlfcn.h> #ifdef SUNOS #include <sys/filio.h> #else #include <sys/ioctl.h> #endif extern "C" pid_t _CreateVirtualProcess(void (*func)(int)) { /*Implementation*/ return get...

OT: Duke Nukem Forver FAIL Survey, erm, Fails
[quote] Game developer Gearbox has put together an online survey asking for feedback on its widely-panned game Duke Nukem Forever. When the shooter was released in June after 14 years of delay after delay and almost unflagging anticipation, it was hit by stonkingly bad reviews. Aside from the super cool launch party, we weren't too pleased with our own Duke Nukem Forever experience either. [/quote] http://www.reghardware.com/2011/09/20/gearbox_posts_duke_nukem_forever_survey/ Here's the survey: http://survey.gearboxsoftware.com/index.php?sid=56594 Here's what happens why I try...

Minix 3 fails in qemu
This is an OpenPGP/MIME signed message (RFC 2440 and 3156) --------------enigCFA0DF51B12CE06D11B998F9 Content-Type: text/plain; charset=ISO-8859-1 Content-Transfer-Encoding: quoted-printable I have always said that a picture is woth a thousand words, and a video, a million. I ran QEMU as a VNC server and caputred the session using vnc2swf. All of the partition tools fail miserably with coredumps and all. http://segin.no-ip.org/minix3.swf --------------enigCFA0DF51B12CE06D11B998F9 Content-Type: application/pgp-signature; name="signature.asc" Content-Description: OpenPGP digital s...

My splitter keeps failing
Hello, I am having trouble with a Digital splitter that keeps failing and has required replacement 4 times in 2 months. I have Cablevision which splits one time after entering my home. After splitting, one cable goes to my HDTV Digital box for my tv, the other cable goes to my cable modem. While trying to go online, I would get the message "cannot find server." After my original conversation with Cablevision over the phone he advised that I connect my modem directly to the incoming cable, thereby bypassing the splitter and that worked. I immediately replaced the split...

help: 'failed to save document' warning
Hi, SW2006 SP4 - I'm getting a 'failed to save document' warning when I try and save a part. It was previously referenced in an assembly, which I closed in order to save it as another part without messing with the references. Now I canr save the part at all. Any ideas? Thanks Lee "Lee Bazalgette - factorydesign" <lee@SPAMfactorydesign.co.uk> wrote in message news:1148295234.945.0@proxy02.news.clara.net... > Hi, > > SW2006 SP4 - I'm getting a 'failed to save document' warning when I try > and save a part. It was previously refer...

mv failes over NFS
Hi, I have move filesystems from one S11 fileserver to a new S11 fileserver using zrep, the destination fileserver is a S11 11/11 Sparc unpatched and the source is a fully updated 11/11 AMD64. From a S10 client where the filesystem is now NFS mounted from the new fileserver I failed to mv, cp is okey. What could have caused this? mila@giulietta $ mv /home/mila/Download/Basler\ Ace\ Camera\ Link\ Users\ Manual .pdf . mv: could not create attribute SUNWattr_ro on file ./Basler Ace Camera Link User s Manual.pdf: Permission denied mv: cannot change owner and group of attri...

if (f() != FAIL) or if (FAIL != f())?
Hello, I have a question concerning style related to conditional decision: #define FAIL -1 int f(); if (f() != FAIL) or better if ( FAIL != f())? Why? Thank you! Wenjie gokkog@yahoo.com (Wenjie) wrote: > #define FAIL -1 > int f(); > > if (f() != FAIL) or better if ( FAIL != f())? Why? The former, since it is the clearer by far. There are people who advocate using the second, because it can prevent an error caused by carelessness in completely different circumstances which cannot possibly occur here. Ignore them; writing unclear code usually produces more bugs than silly ...

bind-9.4.2 failed install
List, I am having trouble getting bind-9.4.2 to install. I run an FC2 server. (server packages only) This systems came with bind-9.2.3-13 rpm's installed originally, which I have removed. When I compile this new version of bind the initiation script is not created . Also name.conf is not created, nor is /etc/sysconfig/named, nor are any root zone files. I can only assume the rest of the software has been installed. I do find bind utilities in /usr/sbin. I am using this config line, which mimics what Red Hat builds. ../configure --prefix=/usr --exec-prefix=/usr -...

Failed to run /sys/lib/newuser
Hi all, After I created my account, I log in with my account and then run /sys/lib/newuser after the prompt. But it doesn't work and complains about permissions, "file does not exist" and "couldn't create *". What should I do? Any suggestions are appreciated. are you sure you _created_ the user? try echo $user to see if you did it. On 1/5/07, Camellia <breakfastea@gmail.com> wrote: > Hi all, > > After I created my account, I log in with my account and then run > /sys/lib/newuser after the prompt. But it doesn't work and complains > abo...

TffsDevformat fails
Hi, we are porting TFFS onto our AMD based 29LV flash part, 32 MB in size and supports word mode addressing (16 bits). I wrote a custom MTD for this, based on the CFI MTD windriver provided us. I had to modify the write and erase routines. Currently tffsDevFormat fails. I would appreciate if any experienced TFFS programmers can help me on this issue. 1) I have specified the interleaving as 2. We have a 32 bit bus and there is only one flash part sitting on it. The documentation is ambiguous in that it indicates interleaving is the number of chips sitting on the bus and also it is the syste...

DB_RECOVERY or DB_AUTO_COMMIT fails
Could someone explain me please how should I work with DB_RECOVERY and DB_AUTO_COMMIT? My problem is that after recovery procedure, my db is empty. My env: Windows XP SP2, VS 2005, console app., DB version 4.4.20 My test: 1) open db 2) add 1 million records into DB in a loop 3) abort program in the middle of the loop 4) try to restore all the data and find a record my code: pDBEnv = new DbEnv(0); pDBEnv->set_cachesize(0, 512*1024*1024, 1); pDBEnv->open(dir_path, DB_CREATE | DB_THREAD | DB_INIT_MPOOL | DB_INIT_TXN | DB_INIT_LOG | DB_INIT_LOCK | DB_RECOVER, 0); pDBEnv-&...

[cross-posting] perl-gtk installation failing on Solaris
--------cross posting from comp.lang.perl.modules because this is a high activity group--------- Hi All, I might be asking a very dumb quesion, but I am new to perl and perl- modules. I am using Solaris Nevada (Solaris 11). I am running Java Desktop System. So I assume I have GTK installed on my system. When I try to install perl-gtk on my system, I am getting following error ---------- [0] root@ak47:Gtk-Perl-0.7009# perl Makefile.PL [16:39:30] Can't exec "imlib-config": No such file or directory at Makefile.PL line 141. Can't exec "gdk-pixbuf-config": No such f...

Route; Command failed; File exists
"Route; Command failed; File exists" This message pauses my config.sys and waits for me to press enter. As routing seems not to be broken, I am reluctant to fix it, but I would like to get rid of the message. Any suggestions? johnsuth@nospam.com.au wrote: > "Route; Command failed; File exists" > > This message pauses my config.sys and waits for me to press enter. > > As routing seems not to be broken, I am reluctant to fix it, but I would > like to get rid of the message. > > Any suggestions? Check \MPTN\BIN\SETUP.CM...

Bitmap index creation failed
Have anyone encountered the following error when creating bitmap index? ORA-28604: table too fragmented to build bitmap index (22495432,16,16) The SQL command that caused the above error is: create bitmap index xxx on record(abc) tablespace idx_tbs; I am using Oracle 10.1.0.2.0 on Red Hat Enterprise 3.0 Thanks If you've read the details of the error message, you will have found that Oracle has an indication of the number of rows in the identified block, although it seems a little odd that a) the max slot count is only 16 b) the max slot found is apparently legal. If ...

TADOConnection Fails to connect
I have a service that I am writing. Looking at the TADOConnection component, I can connect when using the component properties in the BDE, however, it won't connect by code when I run the service. I've tracked it down to the specific lines, but am missing something (likely to be something simple). The only thing I am doing is passing the connection string (which I will build up later), but for now, it's identical. There aren't any obvious errors and it bombs out before I can get to a logging line later. Commenting out the connected := true part allows it to go past this...

cdlin failed
I failed in cdlin, why the tool cannot find the symbol. I have no idea. 1 subckt(s) found in the netlist file. ========================== Subckt: ACCSHCINX2 ========================== Created the CV ACCSHCINX2->netlist_tmp. ##################################### MOS Instance: M29 ##################################### Searching for the master cellview nfet->symbol in ref libs... ...in lib: Did not find nfet->symbol. ...in SS: Did not find nfet->symbol. Created master cellview: mos->symbol in target library SS. Usage error. AND PROCESSED Loading libI...

libapache2-mod-auth-kerb and cross-realm
Hi folks, As I make progress with my Kerberos configuration for Apache, cross-realm support leaves something to be desired. First, I started out with this configuration for libapache2-mod-auth-kerb (v5.4-2 on Debian wheezy): AuthType Kerberos KrbAuthRealms EXAMPLE.COM KrbServiceName Any Krb5Keytab /etc/apache2/krb5-apache.keytab KrbLocalUserMapping On AuthName "Example login" This works fine for local users, but excludes MYREALM.COM users, although the system is configured to support this additional realm. I fixed it by setting KrbLocalUserMappin...

FCC Chief's Proposal Seeks to Streamline Video-Franchising Process
USTelecom dailyLead December 1, 2006 http://r.smartbrief.com/resp/eVsIfDtusXgQeXCibuddjXKz TODAY'S HEADLINES NEWS OF THE DAY * FCC chief's proposal seeks to streamline video-franchising process BUSINESS & INDUSTRY WATCH * Verizon to acquire West Virginia Wireless * Sprint, Cingular push into consumer e-mail * Belgacom passes 100,000 IPTV subscribers * Comcast's deal with Disney marks end of a long road USTELECOM SPOTLIGHT * CALEA Webinars available on demand TECHNOLOGY TRENDS * Cavalier Telephone deploys MPEG-4 * Juniper updates SDX platform * Report: Wibree...

Fedora: fail Mint: fail OpenSuse: fail Ubuntu: fail Windows 7: success Windows Vista: success
"All current Linux versions I've tried with new kernels simply won't install at all, the install fails virtually before it even starts. Ubuntu 9.10 (2.6.31), 10.04, Fedora, Mint, OpenSuse, all fail. Just some CD activity and then they stop with a blank screen. Although Suse gets further, with a screen of coloured blocks. It must be a bug they have introduced in later kernels. My hardware is very standard, although I do see other people have problems with the ASUS P5Q series. Windows 7, Vista needless to say install and work flawlessly. It is enough to put you off Linux alt...

Konstruct Fails on kdelibs
I'm trying to build KDE 3.3 on a Mandrake 10 box. I'm using Konstruct. I thought I had all the dependencies covered, but I obviously missed some. Here's the output: make[4]: Entering directory `/home/david/downloads/konstruct/kde/kdelibs/work/kdelibs-3.3.0/dcop/client' make[5]: Entering directory `/home/david/downloads/konstruct/kde/kdelibs/work/kdelibs-3.3.0/dcop/client' test -z "/home/david/kde3.3/bin" || mkdir -p -- "/home/david/kde3.3/bin" ��/bin/sh�../../libtool�--silent�--mode=install�/usr/bin/install�-c�-p� 'dcop' '/home/david/kde3....

wxViewHTMLFile(const wxString& url) on launch.cpp failed onLinux
------_=_NextPart_001_01C69E4A.2B926E4F Content-Type: text/plain; charset="US-ASCII" Content-Transfer-Encoding: quoted-printable Hello. =20 I tried to use bool wxViewHTMLFile(const wxString& url) to open url by webrowser (netscape is the default browser on linux box). But get the meg from wxMessageBox(_("Could not determine the file type for extension html. Please edit your MIME types or set the BROWSER environment variable."), wxT("Browsing Problem"), wxOK|wxICON_EXCLAMATION); in the launch.cpp I copied from the wxWidget boo...

How should an NTP server fail?
Hi there. A quick question about what to expect when it comes to NTP failures. I configured a Meinberg NTP server (software-based server), had it working, serving time to the back-end hosts, Reachability at 377 for its two NTP upstream time sources (internet NTP servers). Once configured, I wanted to see how the server failed. My expectation was that once Reachability went to zero, the server would stop serving time since it no longer has a source itself. So I blocked port 123 UDP/TCP at the firewall, and sure enough, Reachability for the two upstream sources slowly wound down from 377 to...

Math::Pari test fail on Compaq OSF1 5.1b
Hi, I'm having problems to successfully execute the test scripts on a Compaq host ( OSF1 tr51bdev V5.1 2650 alpha ). Almost all tests end up with the following error message "PARI: *** Invalid arguments to divll. at test_eng/Testout.pm line 30. ...propagated at t/polyser.t line 9. t/polyser.....dubious Test returned status 255 (wstat 65280, 0xff00)" or similar. I've been wondering whether the fact that my perl was compiled with a native 'cc' thus forcing it to be used whenever compiling modules with perl, has some effect on the PARI c-library? I...

Update of X11 failed (fc-cache failed to write cache)
Consulted the FAQ, mailing list, and Google but no answers as to why updating X11 from 6.9.0-4 to 6.9.0-5 failed (see the end of the build below). [stuff deleted] " make[5]: Leaving directory `/usr/ports/opt/x11/work/src/xc/fonts/bdf/cyrillic' make[4]: Leaving directory `/usr/ports/opt/x11/work/src/xc/fonts/bdf' making all in fonts/scaled... make[4]: Entering directory `/usr/ports/opt/x11/work/src/xc/fonts/scaled' making all in fonts/scaled/Type1... make[5]: Entering directory `/usr/ports/opt/x11/work/src/xc/fonts/scaled/Type1' rm -f fonts.scale LD_LIBRAR...

Python framework installation: test_macostools failed failed
Hello. I hope this is the right place for my question. It's about python, but it is OS X specific, and in python forums noone could help me yet. I tried to do a Python 2.3.4 framework installation on my Mac OS X 10.3.5. I configured as described in the ReadMe: ../configure --enable-framework But on make test, one test failed: test test_macostools failed -- Traceback (most recent call last): File "/Users/sven/Downloads/Python-2.3.4/Lib/test/test_macostools.py", line 78, in test_mkalias_relative macostools.mkalias(test_support.TESTFN, TESTFN2, sys.prefix) Fi...