Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Nick_Shah
Collaborator

IPSEC PHASE2 not coming up

I have built a IPSEC tunnel between PA and CP. When i initiate traffic from PC sitting behind CP, phase 1 comes up on both FW. But phase 2 fails, i tried every possible modification in phase 2 settings(same on both end), changed intresting traffic (subnet) coming to CP as well. But i couldn't succeed. 

CA has10.168.1.0/24

PA has 200.1.1.0/24

 

Below logs i captured.

PHASE1:

PHASE1PHASE1

 

PHASE2:

PHASE2 FAILED LOGPHASE2 FAILED LOG

 

 

PA PHASE 1 shows UPPA PHASE 1 shows UP

 

TCPDUMPtcpdumptcpdump

 

 

I reset the tunnel and initiated traffic from PA and i am able to ping. If there was config mismatch i shouldn't be able to reach from PA as well.

Router#ping 10.168.1.1 rep 100
Type escape sequence to abort.
Sending 100, 100-byte ICMP Echos to 10.168.1.1, timeout is 2 seconds:
!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
Success rate is 100 percent (100/100), round-trip min/avg/max = 24/31/44 ms

Thanks

0 Kudos
3 Replies
This widget could not be displayed.

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events