ASA IKEv1 VPN troubleshooting Steps and Tips
1. Phase I proposal mismatch Run show crypto isakmp sa Initiator: MM_WAIT_MSG2 Responder: No info Most likely this is phase1 proposal mismatch, verify IKEv1 policy, other symptoms: Initiator log: Information Exchange processing failed All configured IKE versions failed to establish the tunnel Initiator debug: Received an un-encrypted NO_PROPOSAL_CHOSEN notify message, dropping Responder log: Error processing payload: Payload ID Responder debug: All SA proposals found unacceptable 2. IKE version mismatch: Run show crypto isakmp sa no info at both initiator and responder Initiator log: Removing peer from correlator table failed, no match! Reason: User Requested All configured IKE versions failed to establish the tunnel Initiator debug: Oakley begin quick mode PHASE 1 COMPLETED IKE Initiator sending 1st QM pkt Removing peer from correlator table failed, no match! Session is being torn down. Reason: User Requested Responder log: Tunnel Rejected: Conflicting protocols specified