Cisco VPN Client to 3005 Concentrator

"Denver Fletcher" <[email protected]> Wed, 23 Mar 2005 13:44:10 +1200
Newsgroups gmane.comp.security.vpn
Message-ID <[email protected]>
Hey all,
 
I have a question about this.
 
We're getting a NAT-T negotiation and connection successfully: e.g. ...
 
 
21     15:01:51.937  02/28/05  Sev=Info/5 IKE/0x63000071
Automatic NAT Detection Status:
   Remote end is NOT behind a NAT device
   This end IS behind a NAT device
 
22     15:01:51.937  02/28/05  Sev=Info/4 CM/0x6310000E
Established Phase 1 SA.  1 Crypto Active IKE SA, 0 User Authenticated
IKE SA in the system
 
 
- but then receiving (at the client: a Cisco VPN Client 4.3(?) running
on Windows) the following message:
 
 
39     15:02:23.828  02/28/05  Sev=Info/4 IKE/0xE3000033
Invalid payload: length stated is smaller than length of header alone.
 
(!!!???)
 
40     15:02:23.828  02/28/05  Sev=Warning/3 IKE/0xA3000058
Received malformed message or negotiation no longer active (message id:
0x5A13E0D0)
 
 
After which everything stops, all associations are deleted, and .....
bzzzzzzt!
 
(The intervening entries appear to be all keepalives ...)
 
We're running via a Microsoft ISA Server 2000 and a Cisco PIX 515e
(v6.3.4)
 
The other end is a Cisco 3005 running v4.1.2.
 
If anyone has seen this before, I'd really appreciate your help with it.
Any pointers greatfully received.
 
thanks

Denver Fletcher
Systems Architect

_______________________________________________
VPN mailing list
[email protected]
http://lists.shmoo.com/mailman/listinfo/vpn