Rick Mitchell Solutions - RMSBlog

With Rick Mitchell Solutions, you get the experience of over 10 years dealing with these very same problems you face every day. Large businesses that are in the Fortune 500 down to the small business with aspirations to become global can rely on us to understand and design solutions that fit your needs and your budget.

Sunday, March 28, 2010

Cisco ASA site to site tunnel error message

One of the things that I think Cisco does a very poor job with is explaining error messages on the ASA platform when you are trying to connect a site-to-site tunnel. I am not sure why it has to be so difficult to explain simple misconfigurations. For example, here is an error message from a recent site-to-site tunnel I was building between a Cisco ASA 5520 and a Juniper firewall on the other end:

Received non-routine Notify message: No proposal chosen (14)

Obviously there is something wrong with the IPSEC proposal, but what? Would it be too difficult to say exactly what did not match?

It turned out that this message indicated a problem with perfect-forward secrecy being enabled on one side of the tunnel but not the other. This took some googling and scratching my head in order to figure something out that should have been quite simple. I did not have access to the other device to double check settings so I had to guess as to the problem. Not exactly what I would call the "self-healing" network.

0 Comments:

Post a Comment

Subscribe to Post Comments [Atom]

Links to this post:

Create a Link

<< Home