Cant get phase 2 to come up between a cisco and checkpoint firewall. The proxy ACL and transform set seem to match but yet no workie. Anyone have an idea why?
Oct 17 15:11:10: ISAKMP:(42743):Total payload length: 12
Oct 17 15:11:10: ISAKMP:(42743): sending packet to 1.1.1.1 my_port 500 peer_port 500 (R) MM_KEY_EXCH
Oct 17 15:11:10: ISAKMP:(42743):Sending an IKE IPv4 Packet.
Oct 17 15:11:10: ISAKMP:(42743):Input = IKE_MESG_INTERNAL, IKE_PROCESS_COMPLETE
Oct 17 15:11:10: ISAKMP:(42743):Old State = IKE_R_MM5 New State = IKE_P1_COMPLETE
Oct 17 15:11:10: ISAKMP:(42743):Input = IKE_MESG_INTERNAL, IKE_PHASE1_COMPLETE
Oct 17 15:11:10: ISAKMP:(42743):Old State = IKE_P1_COMPLETE New State = IKE_P1_COMPLETE
Oct 17 15:11:10: ISAKMP (42743): received packet from 1.1.1.1 dport 500 sport 500 Global (R) QM_IDLE
Oct 17 15:11:10: ISAKMP: set new node 2928898679 to QM_IDLE
Oct 17 15:11:10: ISAKMP:(42743): processing HASH payload. message ID = 2928898679
Oct 17 15:11:10: ISAKMP:(42743): processing SA payload. message ID = 2928898679
Oct 17 15:11:10: ISAKMP:(42743):Checking IPSec proposal 1
Oct 17 15:11:10: ISAKMP: transform 1, ESP_AES
Oct 17 15:11:10: ISAKMP: attributes in transform:
Oct 17 15:11:10: ISAKMP: SA life type in seconds
Oct 17 15:11:10: ISAKMP: SA life duration (VPI) of 0x0 0x0 0xE 0x10
Oct 17 15:11:10: ISAKMP: authenticator is HMAC-SHA
Oct 17 15:11:10: ISAKMP: encaps is 1 (Tunnel)
Oct 17 15:11:10: ISAKMP: key length is 256
Oct 17 15:11:10: ISAKMP:(42743):atts are acceptable.
Oct 17 15:11:10: IPSEC(ipsec_process_proposal): peer address 1.1.1.1 not found
Oct 17 15:11:10: ISAKMP:(42743): IPSec policy invalidated proposal with error 64
Oct 17 15:11:10: ISAKMP:(42743): phase 2 SA policy not acceptable! (local 2.2.2.2 remote 1.1.1.1)
Oct 17 15:11:10: ISAKMP: set new node 2706240197 to QM_IDLE
Oct 17 15:11:10: ISAKMP:(42743):Sending NOTIFY PROPOSAL_NOT_CHOSEN protocol 3
spi 139643081102792, message ID = 2706240197
Oct 17 15:11:10: ISAKMP:(42743): sending packet to 1.1.1.1 my_port 500 peer_port 500 (R) QM_IDLE
Oct 17 15:11:10: ISAKMP:(42743):Sending an IKE IPv4 Packet.
Oct 17 15:11:10: ISAKMP:(42743):purging node 2706240197
Oct 17 15:11:10: %CRYPTO-5-IPSEC_SETUP_FAILURE: IPSEC SETUP FAILED for local:1.1.1.1 local_id:1.1.1.1 remote:2.2.2.2 remote_id:2.2.2.2 IKE profile:None fvrf:None fail_reason:IPSec Proposal failure fail_class_cnt:1
Oct 17 15:11:10: ISAKMP:(42743):deleting node 2928898679 error TRUE reason "QM rejected"
Oct 17 15:11:10: ISAKMP:(42743):Node 2928898679, Input = IKE_MESG_FROM_PEER, IKE_QM_EXCH
Oct 17 15:11:10: ISAKMP:(42743):Old State = IKE_QM_READY New State = IKE_QM_READY
Oct 17 15:11:10: ISAKMP (42743): received packet from 1.1.1.1 dport 500 sport 500 Global (R) QM_IDLE
Oct 17 15:11:10: ISAKMP: set new node 3169756681 to QM_IDLE
Oct 17 15:11:10: ISAKMP:(42743): processing HASH payload. message ID = 3169756681
Oct 17 15:11:10: ISAKMP:(42743): processing SA payload. message ID = 3169756681
Oct 17 15:11:10: ISAKMP:(42743):Checking IPSec proposal 1
Oct 17 15:11:10: ISAKMP: transform 1, ESP_AES
Oct 17 15:11:10: ISAKMP: attributes in transform:
Oct 17 15:11:10: ISAKMP: SA life type in seconds
Oct 17 15:11:10: ISAKMP: SA life duration (VPI) of 0x0 0x0 0xE 0x10
Oct 17 15:11:10: ISAKMP: authenticator is HMAC-SHA
Oct 17 15:11:10: ISAKMP: encaps is 1 (Tunnel)
Oct 17 15:11:10: ISAKMP: key length is 256
Oct 17 15:11:10: ISAKMP:(42743):atts are acceptable.
Oct 17 15:11:10: IPSEC(ipsec_process_proposal): peer address 1.1.1.1 not found
Oct 17 15:11:10: ISAKMP:(42743): IPSec policy invalidated proposal with error 64
Oct 17 15:11:10: ISAKMP:(42743): phase 2 SA policy not acceptable! (local 2.2.2.2 remote 1.1.1.1)
Oct 17 15:11:10: ISAKMP: set new node 1941872296 to QM_IDLE
Oct 17 15:11:10: ISAKMP:(42743):Sending NOTIFY PROPOSAL_NOT_CHOSEN protocol 3
spi 139643081102792, message ID = 1941872296
Oct 17 15:11:10: ISAKMP:(42743): sending packet to 1.1.1.1 my_port 500 peer_port 500 (R) QM_IDLE
Oct 17 15:11:10: ISAKMP:(42743):Sending an IKE IPv4 Packet.
Oct 17 15:11:10: ISAKMP:(42743):purging node 1941872296
Oct 17 15:11:10: ISAKMP:(42743):deleting node 3169756681 error TRUE reason "QM rejected"
Oct 17 15:11:10: ISAKMP:(42743):Node 3169756681, Input = IKE_MESG_FROM_PEER, IKE_QM_EXCH
Oct 17 15:11:10: ISAKMP:(42743):Old State = IKE_QM_READY New State = IKE_QM_READY
Oct 17 15:11:17: IPSEC(delete_sa): SA found saving DEL kmi
Oct 17 15:11:29: ISAKMP:(42742):purging node 1673756212