Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
MaheshCheck
Explorer

Ikev2 Phase2 is not getting up

Can anyone help me to resolve the issue

 

IKEv2 Phase2 is not getting up and configuration seems to be fine from both the sides

 

Version :R81.20

 

0 Kudos
35 Replies
MaheshCheck
Explorer

 
0 Kudos
the_rock
Legend
Legend

Hey,

Im in the zoom meeting waiting, so if you are free, please join, Im good till 2.30 pm est.

Andy

0 Kudos
the_rock
Legend
Legend

Hey Mahesh,

Just send me your email in direct message, we can connect offline. Not sure what country you are in, but Im in Canada EST (GMT-5)

Andy

0 Kudos
MaheshCheck
Explorer

I am in india(IST) GMT+5:30

0 Kudos
the_rock
Legend
Legend

Just messaged you offline.

Andy

0 Kudos
the_rock
Legend
Legend

Hey everyoone,

Just to update on this, had zoom remote with @MaheshCheck and below are my notes. I feel good now if Cisco side resets the tunnel, it will work fine, but Mahesh will let us know for sure once they do it.

Andy

 

NOTES FROM THE CALL:

-zoom with Mahesh
-we enabled tunnel mgmt as per gateway since its combo of hosts/subnets
-installed policy
-first time config, never worked before
-Cisco mentioned phase 2 selectors are not matching
-peer ip x.x.x.x

below guidbedit settings should be set to FALSE to avoid any supernetting:


ike_enable_supernet

ike_p2_enable_supernet_from_R80.20

ike_use_largest_possible_subnets


peer -> xyz_gateway

we made sure guidbedit settings were set to false, changed last one -> ike_use_largest_possible_subnets

installed policy -> now tunnel shows UP

Mahesh will ask other side to check tomorrow and let us know

 

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events