Page 1 of 1

Problem with MIkrotik and Cisco ASA IPSec Tunnel

Posted: Sat Apr 09, 2016 9:31 am
by munkitkat
I have a problem establishing an ipsec tunnel between a Cisco ASA 5505 and Mikrotik Routerboard with latest version .

Phase 1 is completed but phase 2 cannot complete. In ASA in debug logs i see the below errors ,

5 Apr 08 2016 18:33:28 713904 Group = 212.205.242.110, IP = 212.205.242.110, All IPSec SA proposals found unacceptable!

3 Apr 08 2016 18:33:28 713902 Group = 212.205.242.110, IP = 212.205.242.110, QM FSM error (P2 struct &0x78eca1e8, mess id 0xe330ac98)!

3 Apr 08 2016 18:33:28 713902 Group = 212.205.242.110, IP = 212.205.242.110, Removing peer from correlator table failed, no match!

5 Apr 08 2016 18:58:34 713259 Group = 212.205.242.110, IP = 212.205.242.110, Session is being torn down. Reason: Phase 2 Mismatch

I have a ping running from one side to another so for the phase2 to complete but nothing...


Any ideas maybe ?

Thanks

Re: Problem with MIkrotik and Cisco ASA IPSec Tunnel

Posted: Sat Apr 09, 2016 10:50 am
by pe1chl
Show the IPsec config of the ASA and of your MikroTik!

Re: Problem with MIkrotik and Cisco ASA IPSec Tunnel

Posted: Wed Apr 19, 2017 1:04 pm
by thavinci
Would have been nice to see response as i have the exact same setup and errors...

No mater what is done Phase 2 doesn't come up.
ipsec.PNG

Re: Problem with MIkrotik and Cisco ASA IPSec Tunnel

Posted: Wed Apr 19, 2017 2:03 pm
by pe1chl
The same thing applies: show your config!