Hi,

following the appnote about configuring BM 3.8 VPN to link to a cisco IOS
12.2 we were of good hope for it sounds like a simple thing.

The BM was configured quickly an brought to work with another BM-Slave, the
cisco IOS was quickly configured as well.

Both systems communicated IKE Phase 1 but when it comes to Phase 2 this
arrogant cisco denies to work with such "low things" like a bordermanager.

He sais "IKE PHASE 2 not acceptable" and the BM gets a
"NO_PROPOSAL_CHOSEN". And an "Unacknowledge informational message type 14"

There is something wrong in the settings but i cannot figure out what.

does anybody have a working cisco-config (Ours is IOS 12.3 with crypto)
Here is the cisco´s debug:
Jun 29 18:11:24.007: ISAKMP (0:268435474): received packet from
213.69.52.215 dport 500 sport 500 Global (R) QM_IDLE
Jun 29 18:11:24.007: ISAKMP: set new node 606313191 to QM_IDLE
Jun 29 18:11:24.019: ISAKMP:(0:18:HW:2): processing HASH payload. message
ID = 606313191
Jun 29 18:11:24.019: ISAKMP:(0:18:HW:2): processing SA payload. message ID
= 606313191
Jun 29 18:11:24.019: ISAKMP:(0:18:HW:2):Checking IPSec proposal 1
Jun 29 18:11:24.019: ISAKMP: transform 1, ESP_3DES
Jun 29 18:11:24.019: ISAKMP: attributes in transform:
Jun 29 18:11:24.019: ISAKMP: SA life type in seconds
Jun 29 18:11:24.019: ISAKMP: SA life duration (VPI) of 0x0 0x0 0x1C 0x20
Jun 29 18:11:24.019: ISAKMP: encaps is 1
Jun 29 18:11:24.019: ISAKMP: authenticator is HMAC-MD5
Jun 29 18:11:24.019: ISAKMP:(0:18:HW:2):atts are acceptable.
Jun 29 18:11:24.023: ISAKMP:(0:18:HW:2): IPSec policy invalidated proposal
Jun 29 18:11:24.023: ISAKMP:(0:18:HW:2): phase 2 SA policy not acceptable!
(local 213.69.52.217 remote 213.69.52.215)
Jun 29 18:11:24.023: ISAKMP: set new node -2089981882 to QM_IDLE

kind regards and thanks
gerd