<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[ERROR: can&#x27;t start the quick mode, there is no ISAKMP-SA]]></title><description><![CDATA[<p dir="auto">Greetings all,</p>
<p dir="auto">I updated our pfSense firewall last night from 2.0.2 to 2.1Beta (built on Tue Feb 5 20:22:25 EST 2013).  I am having a problem with some ipSec tunnels not coming up.  They were working fine with 2.0.2, but now I get some strange errors in the ipsec log.  Here are the log entries:</p>
<hr />
<p dir="auto">Feb 7 15:49:12 racoon: INFO: caught signal 15<br />
Feb 7 15:49:12 racoon: INFO: racoon process 40801 shutdown<br />
Feb 7 15:49:17 racoon: INFO: @(#)ipsec-tools 0.8.1 (http://ipsec-tools.sourceforge.net)<br />
Feb 7 15:49:17 racoon: INFO: @(#)This product linked OpenSSL 1.0.1c 10 May 2012 (http://www.openssl.org/)<br />
Feb 7 15:49:17 racoon: INFO: Reading configuration from "/var/etc/ipsec/racoon.conf"<br />
Feb 7 15:49:17 racoon: [Self]: INFO: &lt;local_wan_ip&gt;[4500] used for NAT-T<br />
Feb 7 15:49:17 racoon: [Self]: INFO: &lt;local_wan_ip&gt;[4500] used as isakmp port (fd=14)<br />
Feb 7 15:49:17 racoon: [Self]: INFO: &lt;local_wan_ip&gt;[500] used for NAT-T<br />
Feb 7 15:49:17 racoon: [Self]: INFO: &lt;local_wan_ip&gt;[500] used as isakmp port (fd=15)<br />
Feb 7 15:49:17 racoon: INFO: unsupported PF_KEY message REGISTER<br />
Feb 7 15:49:17 racoon: ERROR: such policy already exists. anyway replace it: 192.168.2.1/32[0] 192.168.2.0/24[0] proto=any dir=out<br />
Feb 7 15:49:17 racoon: ERROR: such policy already exists. anyway replace it: 192.168.2.0/24[0] 192.168.2.1/32[0] proto=any dir=in<br />
Feb 7 15:49:17 racoon: ERROR: such policy already exists. anyway replace it: 192.168.1.10/32[0] 10.0.0.74/32[0] proto=any dir=out<br />
Feb 7 15:49:17 racoon: ERROR: such policy already exists. anyway replace it: 10.0.0.74/32[0] 192.168.1.10/32[0] proto=any dir=in<br />
Feb 7 15:49:40 racoon: [Tunnel01]: [&lt;remote_ip&gt;] ERROR: can't start the quick mode, there is no ISAKMP-SA, 6f4743bcc2f2d185:6b8ab86e7bf06504:0000f732<br />
Feb 7 15:49:44 racoon: [Tunnel01]: [&lt;remote_ip&gt;] ERROR: can't start the quick mode, there is no ISAKMP-SA, 6f4743bcc2f2d185:6b8ab86e7bf06504:0000f732<br />
Feb 7 15:49:53 racoon: [Tunnel01]: [&lt;remote_ip&gt;] ERROR: can't start the quick mode, there is no ISAKMP-SA, 6f4743bcc2f2d185:6b8ab86e7bf06504:0000f732<br />
Feb 7 15:50:10 racoon: [Tunnel01]: [&lt;remote_ip&gt;] ERROR: can't start the quick mode, there is no ISAKMP-SA, 6f4743bcc2f2d185:6b8ab86e7bf06504:0000f732<br />
Feb 7 15:51:48 racoon: [Tunnel01]: [&lt;remote_ip&gt;] ERROR: can't start the quick mode, there is no ISAKMP-SA, 6f4743bcc2f2d185:eae07550665ecd12:00006d8b<br />
Feb 7 15:51:52 racoon: [Tunnel01]: [&lt;remote_ip&gt;] ERROR: can't start the quick mode, there is no ISAKMP-SA, 6f4743bcc2f2d185:eae07550665ecd12:00006d8b<br />
Feb 7 15:52:01 racoon: [Tunnel01]: [&lt;remote_ip&gt;] ERROR: can't start the quick mode, there is no ISAKMP-SA, 6f4743bcc2f2d185:eae07550665ecd12:00006d8b<br />
Feb 7 15:52:18 racoon: [Tunnel01]: [&lt;remote_ip&gt;] ERROR: can't start the quick mode, there is no ISAKMP-SA, 6f4743bcc2f2d185:eae07550665ecd12:00006d8b</p>
<hr />
<p dir="auto">I have removed and recreated the IPSec tunnel a few times, deleted the SPD entries, cleared the logs, etc.  Still no joy.</p>
<p dir="auto">Any ideas?  What else can I do to troubleshoot?</p>
<p dir="auto">Thanks.&lt;/remote_ip&gt;&lt;/remote_ip&gt;&lt;/remote_ip&gt;&lt;/remote_ip&gt;&lt;/remote_ip&gt;&lt;/remote_ip&gt;&lt;/remote_ip&gt;&lt;/remote_ip&gt;&lt;/local_wan_ip&gt;&lt;/local_wan_ip&gt;&lt;/local_wan_ip&gt;&lt;/local_wan_ip&gt;</p>
]]></description><link>https://forum.netgate.com/topic/52820/error-can-t-start-the-quick-mode-there-is-no-isakmp-sa</link><generator>RSS for Node</generator><lastBuildDate>Mon, 15 Jun 2026 08:16:54 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/52820.rss" rel="self" type="application/rss+xml"/><pubDate>Thu, 07 Feb 2013 15:55:26 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to ERROR: can&#x27;t start the quick mode, there is no ISAKMP-SA on Fri, 08 Feb 2013 14:25:55 GMT]]></title><description><![CDATA[<p dir="auto">Thanks.  I will try to upgrade today…</p>
]]></description><link>https://forum.netgate.com/post/377839</link><guid isPermaLink="true">https://forum.netgate.com/post/377839</guid><dc:creator><![CDATA[rkelleyrtp]]></dc:creator><pubDate>Fri, 08 Feb 2013 14:25:55 GMT</pubDate></item><item><title><![CDATA[Reply to ERROR: can&#x27;t start the quick mode, there is no ISAKMP-SA on Thu, 07 Feb 2013 19:09:10 GMT]]></title><description><![CDATA[<p dir="auto">You checked this thread http://forum.pfsense.org/index.php/topic,58579.0.html?</p>
<p dir="auto">Update to latest snapshot to have that fixed.</p>
]]></description><link>https://forum.netgate.com/post/377688</link><guid isPermaLink="true">https://forum.netgate.com/post/377688</guid><dc:creator><![CDATA[eri--]]></dc:creator><pubDate>Thu, 07 Feb 2013 19:09:10 GMT</pubDate></item></channel></rss>