Crypto System Error Messages for ISAKMP

%CRYPTO -6-IKMP_SA_NOT_AUTH: Cannot accept Quick Mode exchange from %15i if SA is not authenticated!

ISAKMP SA with the remote peer was not authenticated.

%CRYPTO -6-IKMP_SA_NOT_OFFERED: Remote peer %15i responded with attribute [chars] not offered or changed

ISAKMP peers failed protection suite negotiation for ISAKMP.

© 2004 Cisco Systems, Ir

Cisco IOS software can generate many useful system error messages for ISAKMP. Two of the error messages are as follows:

■ %CRYPTO-6-IKMP_SA_NOT_AUTH: Cannot accept Quick Mode exchange from %15i if SA is not authenticated!—The ISAKMP security association with the remote peer was not authenticated yet the peer attempted to begin a quick mode exchange. This exchange must only be done with an authenticated SA. The recommended action is to contact the remote peer administrator to resolve the improper configuration.

■ %CRYPTO-6-IKMP_SA_NOT_OFFERED: Remote peer %15i responded with attribute [chars] not offered or changed—ISAKMP peers negotiated policy by the initiator offering a list of possible alternate protection suites. The responder responded with an ISAKMP policy that the initiator did not offer. The recommended action is to contact the remote peer administrator to resolve the improper configuration.

0 0

Post a comment