- Products
- Learn
- Local User Groups
- Partners
- More
Policy Insights and Policy Auditor in Action
19 November @ 5pm CET / 11am ET
Access Control and Threat Prevention Best Practices
Watch HereOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hello,
I set up a vpn site to site with a partner, unfortunately after 30 minutes from setting up the vpn stops going through the second phase of IKE, what could be the problem?
We have the same vpn settings for phase 1 and phase 2
Thank you.
What about the peers details ? What is the error shown in logs ?
VPN v1 or v2?
Start debug and see where is that failing. Hope you are aware of vpn debug commands?
vpn debug trunc
vpn debug ikeon
vpn debug on
once done
vpn debug ikeoff
vpn debug off
fw ctl debug 0
> VPN v1 or v2?
You mean IKE ?
That is correct - Wondering what was the IKE version and what is the tunnel type? Route based or policy based?
Did not answer...
Policy base, IKEv2
So give us information - we only know that you have two VPN peers and use IKEv2, but no more details: no error messages, no log entries, so nobody can tell you anything usefull by now...
I agree with @G_W_Albrecht . You did not give us much info, except its ikev2 and policy based. Thats great, but as he said, we need errors, logs you see, where it fails, phase 1, phase 2? @Blason_R provided you excellent basic VPN debug that TAC would ask you to do anyway, but you may as well call them and get this fixed, way better over remote.
I would suggest that you contact TAC - a quick RAS could find the issue easily and it will be resolved soon. As you do not want to explain anything here i see no other possible way...
Or best way I would recommend is try disabling vpn acceleration. That has helped me lot many times.
vpn accel off -> This would reinitialize the IKE session.
I have had issues with Cisco ASA VPN peers that leave their default vpn-idle-timeout at 30 minutes.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 41 | |
| 21 | |
| 9 | |
| 7 | |
| 7 | |
| 5 | |
| 5 | |
| 5 | |
| 4 | |
| 4 |
Wed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchWed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasWed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasWed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY