Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Gacki
Participant

VPN SITE TO SITE

Hello,

I set up a vpn site to site with a partner, unfortunately after 30 minutes from setting up the vpn stops going through the second phase of IKE, what could be the problem?
We have the same vpn settings for phase 1 and phase 2

Thank you.

0 Kudos
11 Replies
G_W_Albrecht
Legend
Legend

What about the peers details ? What is the error shown in logs ? 

CCSE CCTE CCSM SMB Specialist
0 Kudos
Blason_R
Leader
Leader

VPN v1 or v2?

Start debug and see where is that failing. Hope you are aware of vpn debug commands?

vpn debug trunc

vpn debug ikeon

vpn debug on

 

once done

vpn debug ikeoff

vpn debug off

fw ctl debug 0

Thanks and Regards,
Blason R
CCSA,CCSE,CCCS
0 Kudos
G_W_Albrecht
Legend
Legend

> VPN v1 or v2?

You mean IKE ?

CCSE CCTE CCSM SMB Specialist
0 Kudos
Blason_R
Leader
Leader

That is correct - Wondering what was the IKE version and what is the tunnel type? Route based or policy based?

 

Thanks and Regards,
Blason R
CCSA,CCSE,CCCS
0 Kudos
G_W_Albrecht
Legend
Legend

Did not answer...

CCSE CCTE CCSM SMB Specialist
0 Kudos
Gacki
Participant

Policy base, IKEv2

0 Kudos
G_W_Albrecht
Legend
Legend

So give us information - we only know that you have two VPN peers and use IKEv2, but no more details: no error messages, no log entries, so nobody can tell you anything usefull by now... 

CCSE CCTE CCSM SMB Specialist
0 Kudos
the_rock
Legend
Legend

I agree with @G_W_Albrecht . You did not give us much info, except its ikev2 and policy based. Thats great, but as he said, we need errors, logs you see, where it fails, phase 1, phase 2? @Blason_R provided you excellent basic VPN debug that TAC would ask you to do anyway, but you may as well call them and get this fixed, way better over remote.

0 Kudos
G_W_Albrecht
Legend
Legend

I would suggest that you contact TAC - a quick RAS could find the issue easily and it will be resolved soon. As you do not want to explain anything here i see no other possible way...

CCSE CCTE CCSM SMB Specialist
0 Kudos
Blason_R
Leader
Leader

Or best way I would recommend is try disabling vpn acceleration. That has helped me lot many times.

vpn accel off -> This would reinitialize the IKE session.

Thanks and Regards,
Blason R
CCSA,CCSE,CCCS
0 Kudos
Lloyd_Braun
Collaborator

I have had issues with Cisco ASA VPN peers that leave their default vpn-idle-timeout at 30 minutes. 

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    Tue 23 Apr 2024 @ 11:00 AM (EDT)

    East US: What's New in R82

    Thu 25 Apr 2024 @ 11:00 AM (SGT)

    APAC: CPX 2024 Recap

    Tue 30 Apr 2024 @ 03:00 PM (CDT)

    EMEA: CPX 2024 Recap

    Thu 02 May 2024 @ 11:00 AM (SGT)

    APAC: What's new in R82

    Tue 23 Apr 2024 @ 11:00 AM (EDT)

    East US: What's New in R82

    Thu 25 Apr 2024 @ 11:00 AM (SGT)

    APAC: CPX 2024 Recap

    Tue 30 Apr 2024 @ 03:00 PM (CDT)

    EMEA: CPX 2024 Recap

    Thu 02 May 2024 @ 11:00 AM (SGT)

    APAC: What's new in R82
    CheckMates Events