IPSec ACL is what we usually call VPN traffic of interest. In real life, problems caused by this ACL configuration error are very common. The typical error is “QM FSM error”, which can be checked by running “Debug Crypto isakmp” on PIX/ASA.
May 15 09:17:11 [IKEv1]: Group = X.X.X.X, IP = X.X.X.X,
QM FSM error (P2 struct & 0x41f7f80, mess id 0x4d3d6016)!
May 15 09:17:11 [IKEv1]: Group = X.X.X.X, IP = X.X.X.X, construct_ipsec_delete(): No SPI to identify Phase 2 SA!
May 15 09:17:11 [IKEv1]: Group = X.X.X.X, IP = X.X.X.X, Removing peer from correlator table failed, no match!
Cisco’s website explains the error log:
QM FSM Error
The IPsec L2L VPN tunnel does not come up on The PIX Firewall or ASA, and The QM FSM error message proves ambiguous. One possible reason is The proxy identities, such as interesting traffic, Access Control List (ACL) or crypto ACL, do not match on both the ends. Check the configuration on both the devices, and make sure that the crypto ACLs match.
This article explains the whole process of IKE and IPsec in detail:
http://jackiechen.blog.51cto.com/196075/158222
This article from “facing the sea, spring flowers” blog, declined to reprint!
Read More:
- @In slf4j log.info Compile error: cannot find symbol log
- Consult IDE log for more details (Help | Show Log),read failed, socket might closed or timeout,
- NVIDIA NVML Driver/library version mismatch
- Nginx error log (error_ Log) configuration and information explanation
- error LNK2038: mismatch detected for ‘RuntimeLibrary’: value ‘MTd_StaticDebug’ doesn’t match value ‘
- Eclipse startup error: an error has occurred.See the log file E:\workspace\.metadata\.log.
- Development of rxtx version mismatch with springboot serial port
- Ubuntu18.04 x11vnc failed, report error opening logfile: /var/log/x11vnc.log
- (26)RuntimeError: Error(s) in loading state_dict for YoloBody:size mismatch for yolo_head3.1.weight
- Caused by: org.flywaydb.core.api.FlywayException: Validate failed: Migration checksum mismatch for m
- valueError: Length mismatch: Expected axis has 40 elements, new values have 38 elements
- Andorid: Installation failed due to invalid APK file due to version mismatch
- Failed to initialize nvml driver / library version mismatch due to automatic update of NVIDIA driver
- After Nacos started, the client worker log was printed all the time
- Error lnk2038 occurred during PCL code compilation: detected “error” during PCL code compilation_ ITERATOR_ DEBUG_ Mismatch of level: value ‘0’ does not match value ‘2’ solution
- Nginx reports 502 error, log connect() failed (111: Connection refused) while connecting to upstream. A personal effective solution
- log4j:ERROR
- SQL*Loader-522: lfiopn failed for file (xxx.log)
- Ranger Solr audit log installation