 |
The message "No keystate" was received. It means either the pre-shared key is wrong or the Local ID of the IPSec VPN Client doesn't match the Remote ID of the VPN Gateway or peer.
Note: this message may also be received on various values mismatches, thus it is useful you check the whole VPN configuration.
Console message example:
20090429 115317 Default (SA Cnx-P1) SEND phase 1 Main Mode [KEY][NONCE]
20090429 115319 Default (SA Cnx-P1) RECV phase 1 Main Mode [KEY][NONCE]
20090429 115319 Default (SA Cnx-P1) SEND phase 1 Main Mode [ID][HASH][NOTIFY]
20090429 115319 Default ipsec_get_keystate: no keystate in ISAKMP SA 00B57C50 |