Community discussions

MikroTik App
 
User avatar
munkitkat
just joined
Topic Author
Posts: 7
Joined: Wed Mar 09, 2016 3:14 pm

Problem with MIkrotik and Cisco ASA IPSec Tunnel

Sat Apr 09, 2016 9:31 am

I have a problem establishing an ipsec tunnel between a Cisco ASA 5505 and Mikrotik Routerboard with latest version .

Phase 1 is completed but phase 2 cannot complete. In ASA in debug logs i see the below errors ,

5 Apr 08 2016 18:33:28 713904 Group = 212.205.242.110, IP = 212.205.242.110, All IPSec SA proposals found unacceptable!

3 Apr 08 2016 18:33:28 713902 Group = 212.205.242.110, IP = 212.205.242.110, QM FSM error (P2 struct &0x78eca1e8, mess id 0xe330ac98)!

3 Apr 08 2016 18:33:28 713902 Group = 212.205.242.110, IP = 212.205.242.110, Removing peer from correlator table failed, no match!

5 Apr 08 2016 18:58:34 713259 Group = 212.205.242.110, IP = 212.205.242.110, Session is being torn down. Reason: Phase 2 Mismatch

I have a ping running from one side to another so for the phase2 to complete but nothing...


Any ideas maybe ?

Thanks
 
pe1chl
Forum Guru
Forum Guru
Posts: 10529
Joined: Mon Jun 08, 2015 12:09 pm

Re: Problem with MIkrotik and Cisco ASA IPSec Tunnel

Sat Apr 09, 2016 10:50 am

Show the IPsec config of the ASA and of your MikroTik!
 
User avatar
thavinci
Member
Member
Posts: 335
Joined: Sat Aug 04, 2007 4:40 pm
Location: Johannessburg
Contact:

Re: Problem with MIkrotik and Cisco ASA IPSec Tunnel

Wed Apr 19, 2017 1:04 pm

Would have been nice to see response as i have the exact same setup and errors...

No mater what is done Phase 2 doesn't come up.
ipsec.PNG
You do not have the required permissions to view the files attached to this post.
 
pe1chl
Forum Guru
Forum Guru
Posts: 10529
Joined: Mon Jun 08, 2015 12:09 pm

Re: Problem with MIkrotik and Cisco ASA IPSec Tunnel

Wed Apr 19, 2017 2:03 pm

The same thing applies: show your config!

Who is online

Users browsing this forum: FunTasTik and 67 guests