Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Gacki
Participant

VPN SITE TO SITE

Hello,

I set up a vpn site to site with a partner, unfortunately after 30 minutes from setting up the vpn stops going through the second phase of IKE, what could be the problem?
We have the same vpn settings for phase 1 and phase 2

Thank you.

0 Kudos
11 Replies
G_W_Albrecht
MVP Silver
MVP Silver

What about the peers details ? What is the error shown in logs ? 

CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist
0 Kudos
Blason_R
MVP Gold
MVP Gold

VPN v1 or v2?

Start debug and see where is that failing. Hope you are aware of vpn debug commands?

vpn debug trunc

vpn debug ikeon

vpn debug on

 

once done

vpn debug ikeoff

vpn debug off

fw ctl debug 0

Thanks and Regards,
Blason R
CCSA,CCSE,CCCS
0 Kudos
G_W_Albrecht
MVP Silver
MVP Silver

> VPN v1 or v2?

You mean IKE ?

CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist
0 Kudos
Blason_R
MVP Gold
MVP Gold

That is correct - Wondering what was the IKE version and what is the tunnel type? Route based or policy based?

 

Thanks and Regards,
Blason R
CCSA,CCSE,CCCS
0 Kudos
G_W_Albrecht
MVP Silver
MVP Silver

Did not answer...

CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist
0 Kudos
Gacki
Participant

Policy base, IKEv2

0 Kudos
G_W_Albrecht
MVP Silver
MVP Silver

So give us information - we only know that you have two VPN peers and use IKEv2, but no more details: no error messages, no log entries, so nobody can tell you anything usefull by now... 

CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist
0 Kudos
the_rock
MVP Gold
MVP Gold

I agree with @G_W_Albrecht . You did not give us much info, except its ikev2 and policy based. Thats great, but as he said, we need errors, logs you see, where it fails, phase 1, phase 2? @Blason_R provided you excellent basic VPN debug that TAC would ask you to do anyway, but you may as well call them and get this fixed, way better over remote.

0 Kudos
G_W_Albrecht
MVP Silver
MVP Silver

I would suggest that you contact TAC - a quick RAS could find the issue easily and it will be resolved soon. As you do not want to explain anything here i see no other possible way...

CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist
0 Kudos
Blason_R
MVP Gold
MVP Gold

Or best way I would recommend is try disabling vpn acceleration. That has helped me lot many times.

vpn accel off -> This would reinitialize the IKE session.

Thanks and Regards,
Blason R
CCSA,CCSE,CCCS
0 Kudos
Lloyd_Braun
Advisor

I have had issues with Cisco ASA VPN peers that leave their default vpn-idle-timeout at 30 minutes. 

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events