<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Cisco PIX disconnect issue.]]></title><description><![CDATA[<p dir="auto">First I would like to say wonderful software guys, great job.</p>
<p dir="auto">In my deployment, I have around 15 remote sites all connected with IPSEC vpn tunnels "in a star fashion" the hub being a PfSense box. Two of the clients also use pfsense and are working beautifully. The rest are all Cisco PIX 501's. All but 4 of those work fine.</p>
<p dir="auto">I followed the monowall guide in setting up these pix's and pfsense.</p>
<p dir="auto">Those 4 pix's connect but will never stay connected. I must disable and renenable the trunk. I have a pingable address in "Automatically ping host", "86400" in lifetime and have tried switching between "2" and "off" on "PFS key group", all with no luck.</p>
<p dir="auto">Here is a sample output of my ipsec log.</p>
<p dir="auto">May 8 12:17:11 racoon: [BoothEnergy]: ERROR: X.X.X.X give up to get IPsec-SA due to time up to wait.<br />
May 8 12:17:11 racoon: ERROR: not acceptable Identity Protection mode<br />
May 8 12:17:10 racoon: [VPN to Inez]: INFO: initiate new phase 2 negotiation: X.X.X.X[0]&lt;=&gt;X.X.X.X[0]<br />
May 8 12:17:10 last message repeated 2 times<br />
May 8 12:17:06 racoon: ERROR: not acceptable Identity Protection mode<br />
May 8 12:17:04 racoon: [Argus]: INFO: initiate new phase 2 negotiation: X.X.X.X[0]&lt;=&gt;X.X.X.X[0]<br />
May 8 12:17:03 last message repeated 4 times<br />
May 8 12:16:56 racoon: ERROR: not acceptable Identity Protection mode<br />
May 8 12:16:54 racoon: [Marco]: ERROR: 65.82.252.245 give up to get IPsec-SA due to time up to wait.<br />
May 8 12:16:53 racoon: ERROR: not acceptable Identity Protection mode<br />
May 8 12:16:51 racoon: ERROR: not acceptable Identity Protection mode<br />
May 8 12:16:50 racoon: [Argus]: ERROR: X.X.X.X give up to get IPsec-SA due to time up to wait.<br />
May 8 12:16:48 racoon: ERROR: not acceptable Identity Protection mode<br />
May 8 12:16:46 racoon: ERROR: not acceptable Identity Protection mode<br />
May 8 12:16:43 racoon: [VPN to Inez]: ERROR: X.X.X.X give up to get IPsec-SA due to time up to wait.<br />
May 8 12:16:43 last message repeated 2 times<br />
May 8 12:16:41 racoon: ERROR: not acceptable Identity Protection mode<br />
May 8 12:16:41 racoon: [BoothEnergy]: INFO: initiate new phase 2 negotiation: X.X.X.X[0]&lt;=&gt;X.X.X.X[0]<br />
May 8 12:16:36 racoon: ERROR: not acceptable Identity Protection mode<br />
May 8 12:16:31 racoon: ERROR: not acceptable Identity Protection mode<br />
May 8 12:16:29 racoon: [Wright Management]: ERROR: X.X.X.X give up to get IPsec-SA due to time up to wait.<br />
May 8 12:16:27 racoon: ERROR: not acceptable Identity Protection mode<br />
May 8 12:16:26 racoon: ERROR: not acceptable Identity Protection mode<br />
May 8 12:16:26 racoon: [Catletsburg]: INFO: IPsec-SA established: ESP/Tunnel X.X.X.X[0]-&gt;X.X.X.X[0] spi=1062033960(0x3f4d5a28)<br />
May 8 12:16:26 racoon: [Catletsburg]: INFO: IPsec-SA established: ESP/Tunnel X.X.X.X[0]-&gt;X.X.X.X[0] spi=123063969(0x755cea1)<br />
May 8 12:16:26 racoon: WARNING: attribute has been modified.<br />
May 8 12:16:26 racoon: WARNING: ignore RESPONDER-LIFETIME notification.<br />
May 8 12:16:26 racoon: [Catletsburg]: INFO: initiate new phase 2 negotiation: X.X.X.X[500]&lt;=&gt;X.X.X.X[500]<br />
May 8 12:16:26 racoon: ERROR: not acceptable Identity Protection mode<br />
May 8 12:16:25 racoon: INFO: purging spi=120073764.<br />
May 8 12:16:25 racoon: [Catletsburg]: INFO: ISAKMP-SA established X.X.X.X[500]-X.X.X.X[500] spi:ff6cf9f0cd73451e:525ad03944c99436<br />
May 8 12:16:25 racoon: NOTIFY: couldn't find the proper pskey, try to get one by the peer's address.<br />
May 8 12:16:25 racoon: WARNING: port 62465 expected, but 0<br />
May 8 12:16:25 racoon: INFO: received Vendor ID: CISCO-UNITY<br />
May 8 12:16:25 racoon: INFO: received Vendor ID: DPD<br />
May 8 12:16:25 racoon: INFO: received Vendor ID: draft-ietf-ipsra-isakmp-xauth-06.txt<br />
May 8 12:16:24 racoon: [Marco]: INFO: initiate new phase 2 negotiation: X.X.X.X[0]&lt;=&gt;65.82.252.245[0]<br />
May 8 12:16:24 racoon: INFO: begin Aggressive mode.<br />
May 8 12:16:24 racoon: [Catletsburg]: INFO: initiate new phase 1 negotiation: X.X.X.X[500]&lt;=&gt;X.X.X.X[500]<br />
May 8 12:16:24 racoon: [Catletsburg]: INFO: IPsec-SA request for X.X.X.X queued due to no phase1 found.<br />
May 8 12:16:21 racoon: ERROR: not acceptable Identity Protection mode<br />
May 8 12:16:21 racoon: ERROR: not acceptable Identity Protection mode<br />
May 8 12:16:20 racoon: [Argus]: INFO: initiate new phase 2 negotiation: X.X.X.X[0]&lt;=&gt;X.X.X.X[0]<br />
May 8 12:16:16 racoon: ERROR: not acceptable Identity Protection mode<br />
May 8 12:16:16 racoon: ERROR: not acceptable Identity Protection mode<br />
May 8 12:16:13 racoon: [Catletsburg]: INFO: ISAKMP-SA deleted X.X.X.X[500]-X.X.X.X[500] spi:7015b2e593734fd4:525ad03955769ff8<br />
May 8 12:16:13 racoon: [VPN to Inez]: INFO: initiate new phase 2 negotiation: X.X.X.X[0]&lt;=&gt;X.X.X.X[0]<br />
May 8 12:16:12 racoon: ERROR: phase2 negotiation failed due to phase1 expired. 7015b2e593734fd4:525ad03955769ff8:0000be31<br />
May 8 12:16:11 last message repeated 2 times<br />
May 8 12:16:06 racoon: ERROR: not acceptable Identity Protection mode</p>
]]></description><link>https://forum.netgate.com/topic/8808/cisco-pix-disconnect-issue</link><generator>RSS for Node</generator><lastBuildDate>Wed, 12 Aug 2026 03:13:05 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/8808.rss" rel="self" type="application/rss+xml"/><pubDate>Thu, 08 May 2008 12:22:51 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Cisco PIX disconnect issue. on Tue, 15 Jul 2008 12:41:09 GMT]]></title><description><![CDATA[<p dir="auto">I've found a confirmation of what heiko said about the identification mode with a preshared key, in the source code<br />
ipsec_doi.c<br />
/* In main mode with pre-shared key, only address type can be used. */</p>
]]></description><link>https://forum.netgate.com/post/177369</link><guid isPermaLink="true">https://forum.netgate.com/post/177369</guid><dc:creator><![CDATA[Dzus]]></dc:creator><pubDate>Tue, 15 Jul 2008 12:41:09 GMT</pubDate></item><item><title><![CDATA[Reply to Cisco PIX disconnect issue. on Wed, 14 May 2008 22:42:36 GMT]]></title><description><![CDATA[<p dir="auto">FWIW, I've had success connecting to PIX's without using no-xauth and no-config-mode<br />
eg-<br />
isakmp key ******** address x.x.x.x netmask 255.255.255.255</p>
<p dir="auto">I also didn't have<br />
isakmp identity address<br />
isakmp nat-traversal 20<br />
in my config. Otherwise similar- 6.3(5) on a 506</p>
]]></description><link>https://forum.netgate.com/post/173713</link><guid isPermaLink="true">https://forum.netgate.com/post/173713</guid><dc:creator><![CDATA[dotdash]]></dc:creator><pubDate>Wed, 14 May 2008 22:42:36 GMT</pubDate></item><item><title><![CDATA[Reply to Cisco PIX disconnect issue. on Wed, 14 May 2008 19:25:21 GMT]]></title><description><![CDATA[<p dir="auto">If you have on both sides static ip´s please test this as the  last slight hope, sorry but I haven´t a pix at the moment to duplicate your test</p>
]]></description><link>https://forum.netgate.com/post/173693</link><guid isPermaLink="true">https://forum.netgate.com/post/173693</guid><dc:creator><![CDATA[heiko]]></dc:creator><pubDate>Wed, 14 May 2008 19:25:21 GMT</pubDate></item><item><title><![CDATA[Reply to Cisco PIX disconnect issue. on Wed, 14 May 2008 15:15:10 GMT]]></title><description><![CDATA[<p dir="auto">I choose all of the following because that is what was required by the monowall instructions.</p>
]]></description><link>https://forum.netgate.com/post/173673</link><guid isPermaLink="true">https://forum.netgate.com/post/173673</guid><dc:creator><![CDATA[snowspeeder]]></dc:creator><pubDate>Wed, 14 May 2008 15:15:10 GMT</pubDate></item><item><title><![CDATA[Reply to Cisco PIX disconnect issue. on Wed, 14 May 2008 12:12:43 GMT]]></title><description><![CDATA[<p dir="auto">it looks OK, why do you choose "aggressive" mode and not main mode, did you try for phase 1 a lifetime "28800" and phase 2 "86400"?<br />
Do you have tested it with SHA not MD5 and what errors shows the pix log?</p>
]]></description><link>https://forum.netgate.com/post/173659</link><guid isPermaLink="true">https://forum.netgate.com/post/173659</guid><dc:creator><![CDATA[heiko]]></dc:creator><pubDate>Wed, 14 May 2008 12:12:43 GMT</pubDate></item><item><title><![CDATA[Reply to Cisco PIX disconnect issue. on Wed, 14 May 2008 11:48:35 GMT]]></title><description><![CDATA[<p dir="auto">Heres the config of my tunnel.</p>
<p dir="auto"><img src="/public/_imported_attachments_/1/config.JPG" alt="config.JPG" class=" img-fluid img-markdown" /><br />
<img src="/public/_imported_attachments_/1/config.JPG_thumb" alt="config.JPG_thumb" class=" img-fluid img-markdown" /></p>
]]></description><link>https://forum.netgate.com/post/173657</link><guid isPermaLink="true">https://forum.netgate.com/post/173657</guid><dc:creator><![CDATA[snowspeeder]]></dc:creator><pubDate>Wed, 14 May 2008 11:48:35 GMT</pubDate></item><item><title><![CDATA[Reply to Cisco PIX disconnect issue. on Wed, 14 May 2008 08:20:07 GMT]]></title><description><![CDATA[<p dir="auto">can you post your ipsec tunnel config from pfsense-side, are both sides static?</p>
<p dir="auto">racoon: ERROR: not acceptable Identity Protection mode –&gt; maybe an MD5 or SHA problem in your config?</p>
]]></description><link>https://forum.netgate.com/post/173634</link><guid isPermaLink="true">https://forum.netgate.com/post/173634</guid><dc:creator><![CDATA[heiko]]></dc:creator><pubDate>Wed, 14 May 2008 08:20:07 GMT</pubDate></item><item><title><![CDATA[Reply to Cisco PIX disconnect issue. on Wed, 14 May 2008 01:44:54 GMT]]></title><description><![CDATA[<p dir="auto">I already do. Here is the config of one of my PIX's.</p>
<p dir="auto">Building configuration…<br />
: Saved<br />
:<br />
PIX Version 6.3(4)<br />
interface ethernet0 auto<br />
interface ethernet1 100full<br />
nameif ethernet0 outside security0<br />
nameif ethernet1 inside security100<br />
enable password lAUX2PI8tpE7r9bA encrypted<br />
passwd lAUX2PI8tpE7r9bA encrypted<br />
hostname pixcat<br />
domain-name ANY.COM<br />
fixup protocol dns maximum-length 512<br />
fixup protocol ftp 21<br />
fixup protocol h323 h225 1720<br />
fixup protocol h323 ras 1718-1719<br />
fixup protocol http 80<br />
fixup protocol rsh 514<br />
fixup protocol rtsp 554<br />
fixup protocol sip 5060<br />
fixup protocol sip udp 5060<br />
fixup protocol skinny 2000<br />
fixup protocol smtp 25<br />
fixup protocol sqlnet 1521<br />
fixup protocol tftp 69<br />
names<br />
name 192.168.145.0 VPN_Client<br />
name 192.0.1.0 Lexington<br />
object-group service port-RTP-tcp tcp<br />
  port-object range 10000 20000<br />
object-group service port-RTP-udp udp<br />
  port-object range 10000 20000<br />
object-group service port-SIP-tcp tcp<br />
  port-object range 5004 5082<br />
object-group service port-SIP-udp udp<br />
  port-object range 5004 5082<br />
access-list outside_access_in permit icmp any any echo-reply<br />
access-list outside_access_in permit ip host Clark any<br />
access-list outside_access_in permit tcp any any eq 10000<br />
access-list outside_access_in permit udp any any eq 10000<br />
access-list inside_outbound_nat0_acl permit ip 192.168.6.0 255.255.255.0 Lexington 255.255.255.0<br />
access-list inside_outbound_nat0_acl permit ip 192.168.6.0 255.255.255.0 VPN_Client 255.255.255.0<br />
access-list inside_outbound_nat0_acl permit ip 192.168.6.0 255.255.255.0 192.168.1.0 255.255.255.0<br />
access-list outside_cryptomap_21 permit ip 192.168.6.0 255.255.255.0 Lexington 255.255.255.0<br />
access-list outside_cryptomap_21 permit ip 192.168.6.0 255.255.255.0 192.168.1.0 255.255.255.0<br />
access-list MyVoip permit tcp host 192.168.6.164 host X.X.X.X1 object-group port-RTP-tcp<br />
access-list MyVoip permit tcp host 192.168.6.164 host X.X.X.X1 object-group port-SIP-tcp<br />
access-list MyVoip permit udp host 192.168.6.164 host X.X.X.X1 object-group port-RTP-udp<br />
access-list MyVoip permit udp host 192.168.6.164 host X.X.X.X1 object-group port-SIP-udp<br />
access-list MyVoip permit tcp host 192.168.6.164 host X.X.X.X1 eq 2727<br />
pager lines 24<br />
mtu outside 1500<br />
mtu inside 1500<br />
ip address outside pppoe setroute<br />
ip address inside 192.168.6.1 255.255.255.0<br />
ip audit info action alarm<br />
ip audit attack action alarm<br />
ip local pool vpnpool 192.168.145.1-192.168.145.5 mask 255.255.255.0<br />
pdm location Lexington 255.255.255.0 outside<br />
pdm location VPN_Client 255.255.255.0 outside<br />
pdm location Clark 255.255.255.255 outside<br />
pdm location 192.168.4.154 255.255.255.255 inside<br />
pdm location 192.168.6.156 255.255.255.255 inside<br />
pdm location 192.168.1.0 255.255.255.0 outside<br />
pdm location 192.168.6.164 255.255.255.255 outside<br />
pdm location 192.168.1.0 255.255.255.0 inside<br />
pdm logging informational 100<br />
pdm history enable<br />
arp timeout 14400<br />
global (outside) 1 interface<br />
nat (inside) 0 access-list inside_outbound_nat0_acl<br />
nat (inside) 1 0.0.0.0 0.0.0.0 0 0<br />
static (inside,outside) tcp interface 10000 192.168.6.156 10000 netmask 255.255.255.255 0 0<br />
static (inside,outside) udp interface 10000 192.168.6.156 10000 netmask 255.255.255.255 0 0<br />
access-group MyVoip in interface outside<br />
timeout xlate 0:05:00<br />
timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 rpc 0:10:00 h225 1:00:00<br />
timeout h323 0:05:00 mgcp 0:05:00 sip 0:30:00 sip_media 0:02:00<br />
timeout uauth 0:05:00 absolute<br />
aaa-server TACACS+ protocol tacacs+<br />
aaa-server TACACS+ max-failed-attempts 3<br />
aaa-server TACACS+ deadtime 10<br />
aaa-server RADIUS protocol radius<br />
aaa-server RADIUS max-failed-attempts 3<br />
aaa-server RADIUS deadtime 10<br />
aaa-server LOCAL protocol local<br />
http server enable<br />
http 192.168.6.0 255.255.255.0 inside<br />
no snmp-server location<br />
no snmp-server contact<br />
snmp-server community public<br />
no snmp-server enable traps<br />
floodguard enable<br />
sysopt connection permit-ipsec<br />
crypto ipsec transform-set myset esp-3des esp-md5-hmac<br />
crypto dynamic-map outside_dyn_map 10 set transform-set myset<br />
crypto map outside_map 21 ipsec-isakmp<br />
crypto map outside_map 21 match address outside_cryptomap_21<br />
crypto map outside_map 21 set peer x.x.x.x<br />
crypto map outside_map 21 set transform-set myset<br />
crypto map outside_map 65535 ipsec-isakmp dynamic outside_dyn_map<br />
crypto map outside_map interface outside<br />
isakmp enable outside<br />
isakmp key ******** address x.x.x.x netmask 255.255.255.255 no-xauth no-config-mode<br />
isakmp identity address<br />
isakmp nat-traversal 20<br />
isakmp policy 10 authentication pre-share<br />
isakmp policy 10 encryption 3des<br />
isakmp policy 10 hash md5<br />
isakmp policy 10 group 2<br />
isakmp policy 10 lifetime 86400<br />
vpngroup eavpn1 address-pool vpnpool<br />
vpngroup eavpn1 dns-server 192.0.1.31<br />
vpngroup eavpn1 wins-server 192.0.1.31<br />
vpngroup eavpn1 default-domain any.com<br />
vpngroup eavpn1 idle-time 1800<br />
vpngroup eavpn1 password ********<br />
telnet 0.0.0.0 0.0.0.0 outside<br />
telnet 192.168.6.0 255.255.255.0 inside<br />
telnet timeout 5<br />
ssh Clark 255.255.255.255 outside<br />
ssh 0.0.0.0 0.0.0.0 outside<br />
ssh 0.0.0.0 0.0.0.0 inside<br />
ssh timeout 5<br />
management-access inside<br />
console timeout 0<br />
vpdn group PPPOEX request dialout pppoe<br />
vpdn group PPPOEX localname eliteky<br />
vpdn group PPPOEX ppp authentication pap<br />
vpdn username eliteky password *********<br />
dhcpd address 192.168.6.30-192.168.6.50 inside<br />
dhcpd dns 192.168.1.3<br />
dhcpd wins 192.0.1.31<br />
dhcpd lease 3600<br />
dhcpd ping_timeout 750<br />
dhcpd auto_config outside<br />
dhcpd enable inside<br />
terminal width 80<br />
Cryptochecksum:485a43c0741d54b44b74016ab728e644<br />
: end<br />
[OK]</p>
]]></description><link>https://forum.netgate.com/post/173622</link><guid isPermaLink="true">https://forum.netgate.com/post/173622</guid><dc:creator><![CDATA[snowspeeder]]></dc:creator><pubDate>Wed, 14 May 2008 01:44:54 GMT</pubDate></item><item><title><![CDATA[Reply to Cisco PIX disconnect issue. on Tue, 13 May 2008 14:21:01 GMT]]></title><description><![CDATA[<p dir="auto">Hello,</p>
<p dir="auto">Racoon really doesn’t want to recieve a FQDN when it’s trying to create a connection with a shared key.<br />
Make sure the Cisco has the line</p>
<ul>
<li>isakmp identity address in it’s config.</li>
</ul>
<p dir="auto">Don’t forget to set your DH and PFS number at the same number as the Cisco.<br />
In the past i have had problems between pfsense and "cisco´s" with DPD.</p>
<p dir="auto">Regards<br />
Heiko</p>
]]></description><link>https://forum.netgate.com/post/173591</link><guid isPermaLink="true">https://forum.netgate.com/post/173591</guid><dc:creator><![CDATA[heiko]]></dc:creator><pubDate>Tue, 13 May 2008 14:21:01 GMT</pubDate></item><item><title><![CDATA[Reply to Cisco PIX disconnect issue. on Tue, 13 May 2008 13:53:23 GMT]]></title><description><![CDATA[<p dir="auto">Still no replies from anyone but I am still attempting to help myself so here is what I'm doing and here are my results.</p>
<p dir="auto">One of the trunks that keeps going down is a cisco PIX. So I remove the 86400 lifetime from SA 2. and kept group on 2 "I also tried off".</p>
<p dir="auto">I get the exact same results.</p>
<p dir="auto">I will try tonight adding the lifetime back and removing the first lifetime.</p>
]]></description><link>https://forum.netgate.com/post/173586</link><guid isPermaLink="true">https://forum.netgate.com/post/173586</guid><dc:creator><![CDATA[snowspeeder]]></dc:creator><pubDate>Tue, 13 May 2008 13:53:23 GMT</pubDate></item><item><title><![CDATA[Reply to Cisco PIX disconnect issue. on Fri, 09 May 2008 15:33:46 GMT]]></title><description><![CDATA[<p dir="auto">No help at all?</p>
]]></description><link>https://forum.netgate.com/post/173353</link><guid isPermaLink="true">https://forum.netgate.com/post/173353</guid><dc:creator><![CDATA[snowspeeder]]></dc:creator><pubDate>Fri, 09 May 2008 15:33:46 GMT</pubDate></item></channel></rss>