Community discussions

MikroTik App
 
staplebattery
just joined
Topic Author
Posts: 20
Joined: Tue Aug 28, 2018 3:57 pm

Cannot establish IPsec point to point VPN between Cisco RV180 and Mikrotik HAP ac2

Wed Sep 19, 2018 2:54 pm

I tried to follow this tutorial: https://ipnet.xyz/2015/01/ipsec-vpn-mikrotik-to-cisco/

I can't figure out why it doesn't work. Here's a snippet from the Cisco's error log (this repeats over and over):
Wed Sep 19 18:18:43 2018 (GMT +0800): [cisco] [IKE] INFO:  Using IPsec SA configuration: 192.168.10.1-192.168.10.254<->192.168.1.1-192.168.1.254
Wed Sep 19 18:18:43 2018 (GMT +0800): [cisco] [IKE] INFO:  Configuration found for [IP Mikrotik Site 1].
Wed Sep 19 18:18:43 2018 (GMT +0800): [cisco] [IKE] INFO:  Configuration found for [IP Mikrotik Site 1].
Wed Sep 19 18:18:43 2018 (GMT +0800): [cisco] [IKE] INFO:  Initiating new phase 1 negotiation: [IP Cisco Site 2][500]<=>[IP Mikrotik Site 1][500]
Wed Sep 19 18:18:43 2018 (GMT +0800): [cisco] [IKE] INFO:  Beginning Identity Protection mode.
Wed Sep 19 18:18:43 2018 (GMT +0800): [cisco] [IKE] INFO:   [isakmp_ident.c:186]: XXX: NUMNATTVENDORIDS: 3
Wed Sep 19 18:18:43 2018 (GMT +0800): [cisco] [IKE] INFO:   [isakmp_ident.c:190]: XXX: setting vendorid: 4
Wed Sep 19 18:18:43 2018 (GMT +0800): [cisco] [IKE] INFO:   [isakmp_ident.c:190]: XXX: setting vendorid: 8
Wed Sep 19 18:18:43 2018 (GMT +0800): [cisco] [IKE] INFO:   [isakmp_ident.c:190]: XXX: setting vendorid: 9
Wed Sep 19 18:19:15 2018 (GMT +0800): [cisco] [IKE] ERROR:  Phase 2 negotiation failed due to time up waiting for phase1. ESP [IP Mikrotik Site 1]->[IP Cisco Site 2] 
Wed Sep 19 18:19:54 2018 (GMT +0800): [cisco] [IKE] INFO:  FOUND
Wed Sep 19 18:19:54 2018 (GMT +0800): [cisco] [IKE] INFO:  FOUND
Wed Sep 19 18:19:54 2018 (GMT +0800): [cisco] [IKE] INFO:  Using IPsec SA configuration: 192.168.10.1-192.168.10.254<->192.168.1.1-192.168.1.254
Wed Sep 19 18:19:54 2018 (GMT +0800): [cisco] [IKE] INFO:  Configuration found for [IP Mikrotik Site 1].
Wed Sep 19 18:19:54 2018 (GMT +0800): [cisco] [IKE] INFO:  Configuration found for [IP Mikrotik Site 1].
Wed Sep 19 18:20:26 2018 (GMT +0800): [cisco] [IKE] ERROR:  Phase 2 negotiation failed due to time up waiting for phase1. ESP [IP Mikrotik Site 1]->[IP Cisco Site 2] 
Wed Sep 19 18:20:33 2018 (GMT +0800): [cisco] [IKE] ERROR:  Phase 1 negotiation failed due to time up for [IP Mikrotik Site 1][500]. d4469258c094be67:0000000000000000
Wed Sep 19 18:20:44 2018 (GMT +0800): [cisco] [IKE] INFO:  FOUND
Wed Sep 19 18:20:44 2018 (GMT +0800): [cisco] [IKE] INFO:  FOUND
Wed Sep 19 18:20:44 2018 (GMT +0800): [cisco] [IKE] INFO:  Using IPsec SA configuration: 192.168.10.1-192.168.10.254<->192.168.1.1-192.168.1.254
Wed Sep 19 18:20:44 2018 (GMT +0800): [cisco] [IKE] INFO:  Configuration found for [IP Mikrotik Site 1].
Wed Sep 19 18:20:44 2018 (GMT +0800): [cisco] [IKE] INFO:  Configuration found for [IP Mikrotik Site 1].
Wed Sep 19 18:20:44 2018 (GMT +0800): [cisco] [IKE] INFO:  Initiating new phase 1 negotiation: [IP Cisco Site 2][500]<=>[IP Mikrotik Site 1][500]
Wed Sep 19 18:20:44 2018 (GMT +0800): [cisco] [IKE] INFO:  Beginning Identity Protection mode.
Wed Sep 19 18:20:44 2018 (GMT +0800): [cisco] [IKE] INFO:   [isakmp_ident.c:186]: XXX: NUMNATTVENDORIDS: 3
Wed Sep 19 18:20:44 2018 (GMT +0800): [cisco] [IKE] INFO:   [isakmp_ident.c:190]: XXX: setting vendorid: 4
Wed Sep 19 18:20:44 2018 (GMT +0800): [cisco] [IKE] INFO:   [isakmp_ident.c:190]: XXX: setting vendorid: 8
Wed Sep 19 18:20:44 2018 (GMT +0800): [cisco] [IKE] INFO:   [isakmp_ident.c:190]: XXX: setting vendorid: 9
Wed Sep 19 18:21:15 2018 (GMT +0800): [cisco] [IKE] ERROR:  Phase 2 negotiation failed due to time up waiting for phase1. ESP [IP Mikrotik Site 1]->[IP Cisco Site 2] 
Wed Sep 19 18:21:55 2018 (GMT +0800): [cisco] [IKE] INFO:  FOUND
Wed Sep 19 18:21:55 2018 (GMT +0800): [cisco] [IKE] INFO:  FOUND
Wed Sep 19 18:21:55 2018 (GMT +0800): [cisco] [IKE] INFO:  Using IPsec SA configuration: 192.168.10.1-192.168.10.254<->192.168.1.1-192.168.1.254
Wed Sep 19 18:21:55 2018 (GMT +0800): [cisco] [IKE] INFO:  Configuration found for [IP Mikrotik Site 1].
Wed Sep 19 18:21:55 2018 (GMT +0800): [cisco] [IKE] INFO:  Configuration found for [IP Mikrotik Site 1].
Wed Sep 19 18:22:26 2018 (GMT +0800): [cisco] [IKE] ERROR:  Phase 2 negotiation failed due to time up waiting for phase1. ESP [IP Mikrotik Site 1]->[IP Cisco Site 2] 
Wed Sep 19 18:22:34 2018 (GMT +0800): [cisco] [IKE] ERROR:  Phase 1 negotiation failed due to time up for [IP Mikrotik Site 1][500]. fb36a60252dae512:0000000000000000
Wed Sep 19 18:22:44 2018 (GMT +0800): [cisco] [IKE] INFO:  FOUND
Wed Sep 19 18:22:44 2018 (GMT +0800): [cisco] [IKE] INFO:  FOUND
Wed Sep 19 18:22:44 2018 (GMT +0800): [cisco] [IKE] INFO:  Using IPsec SA configuration: 192.168.10.1-192.168.10.254<->192.168.1.1-192.168.1.254
Wed Sep 19 18:22:44 2018 (GMT +0800): [cisco] [IKE] INFO:  Configuration found for [IP Mikrotik Site 1].
Wed Sep 19 18:22:44 2018 (GMT +0800): [cisco] [IKE] INFO:  Configuration found for [IP Mikrotik Site 1].
Wed Sep 19 18:22:44 2018 (GMT +0800): [cisco] [IKE] INFO:  Initiating new phase 1 negotiation: [IP Cisco Site 2][500]<=>[IP Mikrotik Site 1][500]
Wed Sep 19 18:22:44 2018 (GMT +0800): [cisco] [IKE] INFO:  Beginning Identity Protection mode.
Wed Sep 19 18:22:44 2018 (GMT +0800): [cisco] [IKE] INFO:   [isakmp_ident.c:186]: XXX: NUMNATTVENDORIDS: 3
Wed Sep 19 18:22:44 2018 (GMT +0800): [cisco] [IKE] INFO:   [isakmp_ident.c:190]: XXX: setting vendorid: 4
Wed Sep 19 18:22:44 2018 (GMT +0800): [cisco] [IKE] INFO:   [isakmp_ident.c:190]: XXX: setting vendorid: 8
Wed Sep 19 18:22:44 2018 (GMT +0800): [cisco] [IKE] INFO:   [isakmp_ident.c:190]: XXX: setting vendorid: 9
Wed Sep 19 18:23:15 2018 (GMT +0800): [cisco] [IKE] ERROR:  Phase 2 negotiation failed due to time up waiting for phase1. ESP [IP Mikrotik Site 1]->[IP Cisco Site 2] 
Wed Sep 19 18:24:34 2018 (GMT +0800): [cisco] [IKE] ERROR:  Phase 1 negotiation failed due to time up for [IP Mikrotik Site 1][500]. 614295a23efccdac:0000000000000000
Wed Sep 19 19:32:47 2018 (GMT +0800): [cisco] [IKE] INFO:  Configuration found for [IP Mikrotik Site 1][500].
Wed Sep 19 19:32:47 2018 (GMT +0800): [cisco] [IKE] INFO:  Received request for new phase 1 negotiation: [IP Cisco Site 2][500]<=>[IP Mikrotik Site 1][500]
Wed Sep 19 19:32:47 2018 (GMT +0800): [cisco] [IKE] INFO:  Beginning Identity Protection mode.
Wed Sep 19 19:32:47 2018 (GMT +0800): [cisco] [IKE] INFO:  Received Vendor ID: RFC XXXX
Wed Sep 19 19:32:47 2018 (GMT +0800): [cisco] [IKE] INFO:  Received Vendor ID: draft-ietf-ipsec-nat-t-ike-02
The Mikrotik's log gives far less information:
ipsec error
phase1 negotiation failed due to time up [site 1 Mikrotik IP][500]<=>[site 2 Cisco IP][500] 128080728e3f8eac:0000000000000000
Site 2 has the Cisco and the LAN is 192.168.10.x
Site 1 has the Mikrotik and the LAN is 192.168.1.x

Any ideas how to fix this?
 
User avatar
mrz
MikroTik Support
MikroTik Support
Posts: 7054
Joined: Wed Feb 07, 2007 12:45 pm
Location: Latvia
Contact:

Re: Cannot establish IPsec point to point VPN between Cisco RV180 and Mikrotik HAP ac2

Wed Sep 19, 2018 2:57 pm

It means that phase1 fails because routers cannot communicate with each other. I would suggest to recheck firewall if UDP/500 is allowed.
 
staplebattery
just joined
Topic Author
Posts: 20
Joined: Tue Aug 28, 2018 3:57 pm

Re: Cannot establish IPsec point to point VPN between Cisco RV180 and Mikrotik HAP ac2

Wed Sep 19, 2018 3:54 pm

Finally fixed that, thanks... now a new problem.
Wed Sep 19 20:40:30 2018 (GMT +0800): [cisco] [IKE] ERROR:  Failed to get IPsec SA configuration for: 192.168.10.0/24<->192.168.1.0/24 from [Mikrotik Site IP]/32[62465]

Who is online

Users browsing this forum: GoogleOther [Bot], robertkjonesjr and 88 guests