<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IKEv2 issue with Cisco ASA in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/IKEv2-issue-with-Cisco-ASA/m-p/280958#M46674</link>
    <description>&lt;P&gt;Which side is initiating the authentication with DH 14?&lt;/P&gt;</description>
    <pubDate>Tue, 11 Aug 2026 13:38:36 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2026-08-11T13:38:36Z</dc:date>
    <item>
      <title>IKEv2 issue with Cisco ASA</title>
      <link>https://community.checkpoint.com/t5/General-Topics/IKEv2-issue-with-Cisco-ASA/m-p/280944#M46673</link>
      <description>&lt;P&gt;I'm trying to troubleshoot a strange issue that has hit a common problem of a failure with no changes.&lt;/P&gt;
&lt;P&gt;The customer has around 20 site to site VPN's running, with about a third of them running IKEv2. The gateways were upgraded from 5400's to 3920's (R81.20 to R82.10 obviously too), after which, besides a stuck SA that was soon sorted, it's been running fine.&lt;/P&gt;
&lt;P&gt;Everything was fine for about a week, then one VPN failed to renew phase 1, receiving a cookie response to the IKE INIT packet. We know nothing was changed our end, and the Cisco guys say nothing was changed their end.&lt;/P&gt;
&lt;P&gt;Looking in detail at the key exchange, I would expect to see phase 1 renew every 24 hours (1440 minutes) and phase 2 every hour (3600 seconds), but instead, in the days leading up to the failure I see the Phase 1 at around 6.45am then repeating again every hour for anything from 2 to 5 hours, before it switches to just renewing phase 2, until 6.45 the next day when the process starts again. Each time we receive a delete request for the SA, which is obviously coming from the other end.&lt;/P&gt;
&lt;P&gt;Another strange thing is that up to that point of failure we see the Phase 1 presenting and authenticating fine using DH group 14, but the Cisco guys are saying it should be group 19 or 20.&lt;/P&gt;
&lt;P&gt;The cookie response, i believe (but i'm no expert!), happens to prevent from DDoS attacks. The ASA sees lots of incoming auth requests, sends a cookie to stem the flow and the other end should then respond including the cookie data to verify it's identity. A tcpdump from both ends simply shows an IKE INIT Initiator Request outbound from us followed by an IKE INIT Responder Response from them to us, and this pattern repeats. (Both ends show the same thing, so we're not flooding them).&lt;/P&gt;
&lt;P&gt;My thought is that the ASA is not responding as expected and possibly something changed. TAC are saying that something appears wrong at the other end.&lt;/P&gt;
&lt;P&gt;Can anyone throw any light on what may suddenly be happening, or the best way to troubleshoot it at all?&lt;/P&gt;</description>
      <pubDate>Tue, 11 Aug 2026 11:04:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/IKEv2-issue-with-Cisco-ASA/m-p/280944#M46673</guid>
      <dc:creator>StevePearson</dc:creator>
      <dc:date>2026-08-11T11:04:04Z</dc:date>
    </item>
    <item>
      <title>Re: IKEv2 issue with Cisco ASA</title>
      <link>https://community.checkpoint.com/t5/General-Topics/IKEv2-issue-with-Cisco-ASA/m-p/280958#M46674</link>
      <description>&lt;P&gt;Which side is initiating the authentication with DH 14?&lt;/P&gt;</description>
      <pubDate>Tue, 11 Aug 2026 13:38:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/IKEv2-issue-with-Cisco-ASA/m-p/280958#M46674</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2026-08-11T13:38:36Z</dc:date>
    </item>
    <item>
      <title>Re: IKEv2 issue with Cisco ASA</title>
      <link>https://community.checkpoint.com/t5/General-Topics/IKEv2-issue-with-Cisco-ASA/m-p/280979#M46675</link>
      <description>&lt;P&gt;We initiate from the Checkpoint end, traffic only flows outbound on this connection.&lt;/P&gt;
&lt;P&gt;One thing that maybe worth mentioning is that all outbound traffic from local source subnets to destination subnets is manually natted behind a specific external IP, not the gateway. But this has been working in the current configuration for years.&lt;/P&gt;</description>
      <pubDate>Tue, 11 Aug 2026 15:56:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/IKEv2-issue-with-Cisco-ASA/m-p/280979#M46675</guid>
      <dc:creator>StevePearson</dc:creator>
      <dc:date>2026-08-11T15:56:47Z</dc:date>
    </item>
  </channel>
</rss>

