与Cisco VPN客户端连接故障原因412

我正在使用Windows 8.1尝试使用Cisco VPN连接到Office。

我尝试连接,几秒钟后,我得到这个:

由客户端本地终止的安全VPN连接原因412:远程对端不再响应。

我的IT部门说阻止端口10000的stream量。 我已经尝试closures所有的软件防火墙,并validation我的路由器启用了VPN直通function。

我联系了我的ISP,他们声称它应该工作,他们提供的configuration文件已经为其他人工作。

这里是我的日志:

Cisco Systems VPN Client Version 5.0.07.0440 Copyright (C) 1998-2010 Cisco Systems, Inc. All Rights Reserved. Client Type(s): Windows, WinNT Running on: 6.2.9200 205 14:09:57.154 05/28/15 Sev=Info/4 CM/0x63100002 Begin connection process 206 14:09:57.156 05/28/15 Sev=Info/4 CM/0x63100004 Establish secure connection 207 14:09:57.156 05/28/15 Sev=Info/4 CM/0x63100024 Attempt connection with server "66.162.2.6" 208 14:09:57.159 05/28/15 Sev=Info/6 CM/0x6310002F Allocated local TCP port 57238 for TCP connection. 209 14:09:57.705 05/28/15 Sev=Info/4 IPSEC/0x63700008 IPSec driver successfully started 210 14:09:57.705 05/28/15 Sev=Info/4 IPSEC/0x63700014 Deleted all keys 211 14:09:57.705 05/28/15 Sev=Info/6 IPSEC/0x6370002C Sent 4 packets, 0 were fragmented. 212 14:09:57.705 05/28/15 Sev=Info/6 IPSEC/0x63700020 TCP SYN sent to 66.162.2.6, src port 57238, dst port 10000 213 14:09:57.705 05/28/15 Sev=Info/6 IPSEC/0x6370001C TCP SYN-ACK received from 66.162.2.6, src port 10000, dst port 57238 214 14:09:57.705 05/28/15 Sev=Info/6 IPSEC/0x63700021 TCP ACK sent to 66.162.2.6, src port 57238, dst port 10000 215 14:09:57.705 05/28/15 Sev=Info/4 CM/0x63100029 TCP connection established on port 10000 with server "66.162.2.6" 216 14:09:58.207 05/28/15 Sev=Info/4 CM/0x63100024 Attempt connection with server "66.162.2.6" 217 14:09:58.213 05/28/15 Sev=Info/6 IKE/0x6300003B Attempting to establish a connection with 66.162.2.6. 218 14:09:58.216 05/28/15 Sev=Info/4 IKE/0x63000001 Starting IKE Phase 1 Negotiation 219 14:09:58.226 05/28/15 Sev=Info/4 IKE/0x63000013 SENDING >>> ISAKMP OAK AG (SA, KE, NON, ID, VID(Xauth), VID(dpd), VID(Frag), VID(Unity)) to 66.162.2.6 220 14:10:03.707 05/28/15 Sev=Info/4 IKE/0x63000021 Retransmitting last packet! 221 14:10:03.707 05/28/15 Sev=Info/4 IKE/0x63000013 SENDING >>> ISAKMP OAK AG (Retransmission) to 66.162.2.6 222 14:10:08.707 05/28/15 Sev=Info/4 IKE/0x63000021 Retransmitting last packet! 223 14:10:08.707 05/28/15 Sev=Info/4 IKE/0x63000013 SENDING >>> ISAKMP OAK AG (Retransmission) to 66.162.2.6 224 14:10:14.205 05/28/15 Sev=Info/4 IKE/0x63000021 Retransmitting last packet! 225 14:10:14.205 05/28/15 Sev=Info/4 IKE/0x63000013 SENDING >>> ISAKMP OAK AG (Retransmission) to 66.162.2.6 226 14:10:19.207 05/28/15 Sev=Info/4 IKE/0x63000017 Marking IKE SA for deletion (I_Cookie=4CE6E0F6AFDD6219 R_Cookie=0000000000000000) reason = DEL_REASON_PEER_NOT_RESPONDING 227 14:10:20.206 05/28/15 Sev=Info/4 IKE/0x6300004B Discarding IKE SA negotiation (I_Cookie=4CE6E0F6AFDD6219 R_Cookie=0000000000000000) reason = DEL_REASON_PEER_NOT_RESPONDING 228 14:10:20.206 05/28/15 Sev=Info/4 CM/0x63100014 Unable to establish Phase 1 SA with server "66.162.2.6" because of "DEL_REASON_PEER_NOT_RESPONDING" 229 14:10:20.206 05/28/15 Sev=Info/5 CM/0x63100025 Initializing CVPNDrv 230 14:10:20.217 05/28/15 Sev=Info/4 CM/0x6310002D Resetting TCP connection on port 10000 231 14:10:20.218 05/28/15 Sev=Info/6 CM/0x63100030 Removed local TCP port 57238 for TCP connection. 232 14:10:20.225 05/28/15 Sev=Info/6 CM/0x63100046 Set tunnel established flag in registry to 0. 233 14:10:20.226 05/28/15 Sev=Info/4 IKE/0x63000001 IKE received signal to terminate VPN connection 234 14:10:20.241 05/28/15 Sev=Info/6 IPSEC/0x63700023 TCP RST sent to 66.162.2.6, src port 57238, dst port 10000 235 14:10:20.241 05/28/15 Sev=Info/4 IPSEC/0x63700014 Deleted all keys 236 14:10:20.241 05/28/15 Sev=Info/4 IPSEC/0x63700014 Deleted all keys 237 14:10:20.241 05/28/15 Sev=Info/4 IPSEC/0x63700014 Deleted all keys 238 14:10:20.241 05/28/15 Sev=Info/4 IPSEC/0x6370000A IPSec driver successfully stopped 

有谁知道为什么这可能会发生和任何其他步骤进行故障排除?

造成几个不同的原因:

  1. 客户端位于(或正在使用)阻止端口TCP 4500/10000或UDP 4500/10000或500和/或ESP的防火墙之后。

  2. 您的Internet连接不稳定并丢弃数据包。

  3. VPN客户端位于NAT设备后面,VPN服务器没有启用NAT-T。

可能的解决scheme:

  1. 如果您使用无线,请尝试连接有线,并确保您的851有稳定的networking。

  2. 在客户端上closures防火墙,然后testing连接以查看问题是否仍然存在。 如果没有,则可以重新开启防火墙,在防火墙中添加端口500,端口4500和ESP协议的例外规则

  3. 在您的configuration文件中打开NAT-T / TCP(请记住在您的防火墙中取消阻止端口10000)

  4. 用您的编辑器编辑您的configuration文件,并将ForceKeepAlive = 0更改为1

    • 有关更多信息,请访问: https : //supportforums.cisco.com/discussion/11390361/vpn-client-fails-reason-412#sthash.Z7M2vE1G.dpuf

– 不要忘记重新启动服务 –

通过在命令提示符下发出命令services.msc来访问服务

– 停止Cisco Systems,Inc.VPN服务

– 停止Internet连接共享(ICS)服务

– 右键单击​​ICS服务,然后select“属性”。 然后将启动types更改为禁用或手动。

– 启动Cisco Systems,Inc.VPN服务