<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: The tunnels between AZURE and Cisco ASA stopped working. in VPN</title>
    <link>https://community.cisco.com/t5/vpn/the-tunnels-between-azure-and-cisco-asa-stopped-working/m-p/5265566#M298680</link>
    <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;- Check the &lt;U&gt;&lt;STRONG&gt;logs&lt;/STRONG&gt; &lt;/U&gt;on the ASA ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp; M.&lt;/P&gt;</description>
    <pubDate>Thu, 27 Feb 2025 14:02:16 GMT</pubDate>
    <dc:creator>marce1000</dc:creator>
    <dc:date>2025-02-27T14:02:16Z</dc:date>
    <item>
      <title>The tunnels between AZURE and Cisco ASA stopped working.</title>
      <link>https://community.cisco.com/t5/vpn/the-tunnels-between-azure-and-cisco-asa-stopped-working/m-p/5265478#M298676</link>
      <description>&lt;P&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Hello, I ask for help in solving the following problem.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt; As of today, the tunnels between AZURE and CISCO ASA stopped working.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt; There were no problems until now.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt; I am attaching the CISCO ASA config&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;!&lt;BR /&gt;hostname I-FW1&lt;BR /&gt;domain-name magvatech.com&lt;BR /&gt;enable password ***** pbkdf2&lt;BR /&gt;service-module 1 keepalive-timeout 4&lt;BR /&gt;service-module 1 keepalive-counter 6&lt;BR /&gt;!&lt;BR /&gt;license smart&lt;BR /&gt;feature tier standard&lt;BR /&gt;names&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;!&lt;BR /&gt;interface Vlan1&lt;BR /&gt;no nameif&lt;BR /&gt;no security-level&lt;BR /&gt;no ip address&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet1/1&lt;BR /&gt;no switchport&lt;BR /&gt;no nameif&lt;BR /&gt;no security-level&lt;BR /&gt;no ip address&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet1/1.201&lt;BR /&gt;description ANYCONNECT&lt;BR /&gt;vlan 201&lt;BR /&gt;nameif OUTSIDE-ANYCONNECT&lt;BR /&gt;security-level 0&lt;BR /&gt;ip address 95.70.236.225 255.255.255.254&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet1/1.202&lt;BR /&gt;description MVTEUCLOUD&lt;BR /&gt;vlan 202&lt;BR /&gt;nameif MVTEUCLOUD&lt;BR /&gt;security-level 0&lt;BR /&gt;ip address 95.70.236.227 255.255.255.254&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet1/1.203&lt;BR /&gt;description MVTBRCLOUD&lt;BR /&gt;vlan 203&lt;BR /&gt;nameif MVTBRCLOUD&lt;BR /&gt;security-level 0&lt;BR /&gt;ip address 95.70.236.229 255.255.255.254&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet1/1.204&lt;BR /&gt;description FCMEUCLOUD&lt;BR /&gt;vlan 204&lt;BR /&gt;nameif FCMEUCLOUD&lt;BR /&gt;security-level 0&lt;BR /&gt;ip address 95.70.236.231 255.255.255.254&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet1/1.205&lt;BR /&gt;description TESCLOUD&lt;BR /&gt;vlan 205&lt;BR /&gt;nameif TESCLOUD&lt;BR /&gt;security-level 0&lt;BR /&gt;ip address 95.70.236.233 255.255.255.254&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet1/2&lt;BR /&gt;no switchport&lt;BR /&gt;no nameif&lt;BR /&gt;no security-level&lt;BR /&gt;no ip address&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet1/2.102&lt;BR /&gt;vlan 102&lt;BR /&gt;nameif V102_OSPF-I-FW1&lt;BR /&gt;security-level 100&lt;BR /&gt;ip address 10.254.1.14 255.255.255.252&lt;BR /&gt;ospf network point-to-point non-broadcast&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet1/3&lt;BR /&gt;no switchport&lt;BR /&gt;nameif INSIDE-LOC-LAN&lt;BR /&gt;security-level 100&lt;BR /&gt;ip address 10.17.1.253 255.255.252.0&lt;BR /&gt;&lt;BR /&gt;!&lt;BR /&gt;interface Tunnel2&lt;BR /&gt;nameif MVTEU-I-FW1&lt;BR /&gt;ip address 10.70.200.1 255.255.255.252&lt;BR /&gt;tunnel source interface MVTEUCLOUD&lt;BR /&gt;tunnel destination 20.217.184.175&lt;BR /&gt;tunnel mode ipsec ipv4&lt;BR /&gt;tunnel protection ipsec profile AZURE-PROPOSAL&lt;BR /&gt;!&lt;BR /&gt;interface Tunnel3&lt;BR /&gt;nameif MVTBR-I-FW1&lt;BR /&gt;ip address 10.70.201.1 255.255.255.252&lt;BR /&gt;tunnel source interface MVTBRCLOUD&lt;BR /&gt;tunnel destination 20.226.120.230&lt;BR /&gt;tunnel mode ipsec ipv4&lt;BR /&gt;tunnel protection ipsec profile AZURE-PROPOSAL&lt;BR /&gt;!&lt;BR /&gt;interface Tunnel4&lt;BR /&gt;nameif FCMEU-I-FW1&lt;BR /&gt;ip address 10.70.202.1 255.255.255.252&lt;BR /&gt;tunnel source interface FCMEUCLOUD&lt;BR /&gt;tunnel destination 52.174.183.101&lt;BR /&gt;tunnel mode ipsec ipv4&lt;BR /&gt;tunnel protection ipsec profile AZURE-PROPOSAL&lt;BR /&gt;!&lt;BR /&gt;interface Tunnel5&lt;BR /&gt;nameif TES-I-FW1&lt;BR /&gt;ip address 192.168.88.1 255.255.255.252&lt;BR /&gt;tunnel source interface TESCLOUD&lt;BR /&gt;tunnel destination 52.174.122.149&lt;BR /&gt;tunnel mode ipsec ipv4&lt;BR /&gt;tunnel protection ipsec profile AZURE-PROPOSAL&lt;BR /&gt;!&lt;BR /&gt;ftp mode passive&lt;BR /&gt;dns domain-lookup OUTSIDE-ANYCONNECT&lt;BR /&gt;dns domain-lookup MVTEUCLOUD&lt;BR /&gt;dns domain-lookup FCMEUCLOUD&lt;BR /&gt;dns domain-lookup TESCLOUD&lt;BR /&gt;dns server-group DefaultDNS&lt;BR /&gt;name-server 8.8.8.8&lt;BR /&gt;name-server 10.14.19.4&lt;BR /&gt;domain-name magvatech.com&lt;BR /&gt;same-security-traffic permit inter-interface&lt;BR /&gt;same-security-traffic permit intra-interface&lt;BR /&gt;no object-group-search access-control&lt;BR /&gt;object network RAVPN&lt;BR /&gt;subnet 10.17.16.0 255.255.255.0&lt;BR /&gt;object network LAN_V10&lt;BR /&gt;subnet 10.17.0.0 255.255.252.0&lt;BR /&gt;object network I-FW1&lt;BR /&gt;host 10.17.1.253&lt;BR /&gt;description I-FW1-LAN&lt;BR /&gt;object network MVTEUCLOUD&lt;BR /&gt;subnet 10.14.0.0 255.255.0.0&lt;BR /&gt;description MVTEUCLOUD-LAN&lt;BR /&gt;object network POOL-ISP-I&lt;BR /&gt;subnet 10.17.17.0 255.255.255.0&lt;BR /&gt;&lt;BR /&gt;pager lines 24&lt;BR /&gt;logging enable&lt;BR /&gt;logging trap warnings&lt;BR /&gt;logging asdm debugging&lt;BR /&gt;logging host INSIDE-LOC-LAN 10.17.50.208 6/1025&lt;BR /&gt;mtu OUTSIDE-ANYCONNECT 1500&lt;BR /&gt;mtu MVTEUCLOUD 1500&lt;BR /&gt;mtu MVTBRCLOUD 1500&lt;BR /&gt;mtu FCMEUCLOUD 1500&lt;BR /&gt;mtu TESCLOUD 1500&lt;BR /&gt;mtu V102_OSPF-I-FW1 1500&lt;BR /&gt;mtu INSIDE-LOC-LAN 1500&lt;BR /&gt;mtu management 1500&lt;BR /&gt;icmp unreachable rate-limit 1 burst-size 1&lt;BR /&gt;icmp permit any INSIDE-LOC-LAN&lt;BR /&gt;no asdm history enable&lt;BR /&gt;arp timeout 14400&lt;BR /&gt;no arp permit-nonconnected&lt;BR /&gt;arp rate-limit 16384&lt;BR /&gt;nat (INSIDE-LOC-LAN,OUTSIDE-ANYCONNECT) source static LAN_V10 LAN_V10 destination static RAVPN RAVPN&lt;BR /&gt;nat (OUTSIDE-ANYCONNECT,OUTSIDE-ANYCONNECT) source dynamic DM_INLINE_NETWORK_1 interface&lt;BR /&gt;nat (OUTSIDE-ANYCONNECT,OUTSIDE-ANYCONNECT) source dynamic POOL-ISP-I interface&lt;BR /&gt;router bgp 65000&lt;BR /&gt;bgp log-neighbor-changes&lt;BR /&gt;bgp graceful-restart&lt;BR /&gt;address-family ipv4 unicast&lt;BR /&gt;neighbor 10.13.16.158 remote-as 65525&lt;BR /&gt;neighbor 10.13.16.158 ebgp-multihop 255&lt;BR /&gt;neighbor 10.13.16.158 activate&lt;BR /&gt;neighbor 10.15.16.158 remote-as 65515&lt;BR /&gt;neighbor 10.15.16.158 ebgp-multihop 255&lt;BR /&gt;neighbor 10.15.16.158 activate&lt;BR /&gt;neighbor 10.14.18.158 remote-as 65570&lt;BR /&gt;neighbor 10.14.18.158 ebgp-multihop 255&lt;BR /&gt;neighbor 10.14.18.158 activate&lt;BR /&gt;neighbor 192.168.77.254 remote-as 65516&lt;BR /&gt;neighbor 192.168.77.254 ebgp-multihop 255&lt;BR /&gt;neighbor 192.168.77.254 activate&lt;BR /&gt;network 10.13.0.0&lt;BR /&gt;network 10.14.0.0&lt;BR /&gt;network 172.16.0.0&lt;BR /&gt;network 10.17.0.0 mask 255.255.252.0&lt;BR /&gt;network 172.17.0.0&lt;BR /&gt;network 172.18.0.0&lt;BR /&gt;network 10.17.16.0 mask 255.255.255.0&lt;BR /&gt;network 10.17.50.0 mask 255.255.255.0&lt;BR /&gt;network 192.168.88.0 mask 255.255.255.252&lt;BR /&gt;network 10.17.101.0 mask 255.255.255.252&lt;BR /&gt;network 10.70.200.0 mask 255.255.255.252&lt;BR /&gt;network 10.70.201.0 mask 255.255.255.252&lt;BR /&gt;network 10.70.202.0 mask 255.255.255.252&lt;BR /&gt;network 10.254.0.64 mask 255.255.255.252&lt;BR /&gt;network 10.254.0.160 mask 255.255.255.252&lt;BR /&gt;no auto-summary&lt;BR /&gt;no synchronization&lt;BR /&gt;exit-address-family&lt;BR /&gt;!&lt;BR /&gt;router ospf 1&lt;BR /&gt;network 10.13.0.0 255.255.0.0 area 1&lt;BR /&gt;network 10.14.0.0 255.255.0.0 area 1&lt;BR /&gt;network 10.15.0.0 255.255.0.0 area 1&lt;BR /&gt;network 10.17.0.0 255.255.252.0 area 1&lt;BR /&gt;network 10.254.1.12 255.255.255.252 area 1&lt;BR /&gt;neighbor 10.254.1.13 interface V102_OSPF-I-FW1&lt;BR /&gt;log-adj-changes&lt;BR /&gt;!&lt;BR /&gt;route OUTSIDE-ANYCONNECT 0.0.0.0 0.0.0.0 95.70.236.224 1&lt;BR /&gt;route MVTBRCLOUD 0.0.0.0 0.0.0.0 95.70.236.228 2&lt;BR /&gt;route MVTEUCLOUD 0.0.0.0 0.0.0.0 95.70.236.226 3&lt;BR /&gt;route TESCLOUD 0.0.0.0 0.0.0.0 95.70.236.232 4&lt;BR /&gt;route FCMEUCLOUD 0.0.0.0 0.0.0.0 95.70.236.230 5&lt;BR /&gt;route FCMEU-I-FW1 10.13.16.158 255.255.255.255 10.70.202.2 1&lt;BR /&gt;route INSIDE-LOC-LAN 10.14.0.0 255.255.0.0 10.17.1.254 1&lt;BR /&gt;route MVTEU-I-FW1 10.14.18.158 255.255.255.255 10.70.200.2 1&lt;BR /&gt;route MVTEU-I-FW1 10.14.19.4 255.255.255.255 10.70.200.2 1&lt;BR /&gt;route MVTBR-I-FW1 10.15.16.158 255.255.255.255 10.70.201.2 1&lt;BR /&gt;route INSIDE-LOC-LAN 10.17.15.0 255.255.255.0 10.17.1.254 1&lt;BR /&gt;route INSIDE-LOC-LAN 10.17.16.0 255.255.255.0 10.17.1.254 1&lt;BR /&gt;route INSIDE-LOC-LAN 10.17.18.0 255.255.255.0 10.17.1.254 1&lt;BR /&gt;route INSIDE-LOC-LAN 10.17.19.0 255.255.255.0 10.17.1.254 1&lt;BR /&gt;route INSIDE-LOC-LAN 10.17.20.0 255.255.255.0 10.17.1.254 1&lt;BR /&gt;route INSIDE-LOC-LAN 10.17.50.0 255.255.255.0 10.17.1.254 1&lt;BR /&gt;route INSIDE-LOC-LAN 10.254.0.64 255.255.255.252 10.17.1.254 1&lt;BR /&gt;route INSIDE-LOC-LAN 172.16.0.0 255.255.0.0 10.17.1.254 1&lt;BR /&gt;route INSIDE-LOC-LAN 172.17.0.0 255.255.0.0 10.17.1.254 1&lt;BR /&gt;route INSIDE-LOC-LAN 172.18.0.0 255.255.0.0 10.17.1.254 1&lt;BR /&gt;route TES-I-FW1 192.168.77.254 255.255.255.255 192.168.88.2 1&lt;BR /&gt;timeout xlate 3:00:00&lt;BR /&gt;timeout pat-xlate 0:00:30&lt;BR /&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 sctp 0:02:00 icmp 0:00:02&lt;BR /&gt;timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00&lt;BR /&gt;timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00&lt;BR /&gt;timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute&lt;BR /&gt;timeout tcp-proxy-reassembly 0:01:00&lt;BR /&gt;timeout floating-conn 0:00:00&lt;BR /&gt;timeout conn-holddown 0:00:15&lt;BR /&gt;timeout igp stale-route 0:01:10&lt;BR /&gt;ldap attribute-map VPN_USERS&lt;BR /&gt;map-name memberOf IETF-Radius-Class&lt;BR /&gt;map-value memberOf memberOf CN=VPN_USERS2,OU=MVT_GROUPS,DC=mvt,DC=com&lt;BR /&gt;aaa-server LDAP protocol ldap&lt;BR /&gt;aaa-server LDAP (INSIDE-LOC-LAN) host 10.14.1.4&lt;BR /&gt;ldap-base-dn DC=mvt,DC=com&lt;BR /&gt;ldap-scope subtree&lt;BR /&gt;ldap-naming-attribute SamAccountName&lt;BR /&gt;ldap-login-password *****&lt;BR /&gt;ldap-login-dn CN=Timur Dzhu,OU=MVT,OU=MVT_USERS,DC=mvt,DC=com&lt;BR /&gt;server-type microsoft&lt;BR /&gt;aaa-server Radius-T protocol radius&lt;BR /&gt;aaa-server Radius-T (INSIDE-LOC-LAN) host 172.16.7.148&lt;BR /&gt;key *****&lt;BR /&gt;authentication-port 1812&lt;BR /&gt;accounting-port 1813&lt;BR /&gt;radius-common-pw *****&lt;BR /&gt;user-identity default-domain LOCAL&lt;BR /&gt;aaa authentication ssh console LOCAL&lt;BR /&gt;aaa authentication http console LOCAL&lt;BR /&gt;aaa authentication enable console LOCAL&lt;BR /&gt;aaa authentication login-history&lt;BR /&gt;http server enable&lt;BR /&gt;http 10.17.0.0 255.255.252.0 management&lt;BR /&gt;http 10.17.50.0 255.255.255.0 management&lt;BR /&gt;http 172.17.0.0 255.255.0.0 INSIDE-LOC-LAN&lt;BR /&gt;http 172.16.0.0 255.255.0.0 INSIDE-LOC-LAN&lt;BR /&gt;http 10.17.0.0 255.255.0.0 INSIDE-LOC-LAN&lt;BR /&gt;http 10.17.0.0 255.255.0.0 V102_OSPF-I-FW1&lt;BR /&gt;snmp-server host INSIDE-LOC-LAN 10.17.50.207 community ***** version 2c&lt;BR /&gt;snmp-server host INSIDE-LOC-LAN 172.17.5.207 community ***** version 2c&lt;BR /&gt;snmp-server host INSIDE-LOC-LAN 172.16.5.207 community ***** version 2c&lt;BR /&gt;snmp-server host INSIDE-LOC-LAN 172.18.5.207 community ***** version 2c&lt;BR /&gt;no snmp-server location&lt;BR /&gt;no snmp-server contact&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-128-SHA esp-aes esp-sha-hmac&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-192-SHA esp-aes-192 esp-sha-hmac&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-256-SHA esp-aes-256 esp-sha-hmac&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-DES-SHA esp-aes esp-sha-hmac&lt;BR /&gt;crypto ipsec ikev2 ipsec-proposal AZURE-PROPOSAL&lt;BR /&gt;protocol esp encryption aes-256&lt;BR /&gt;protocol esp integrity sha-256&lt;BR /&gt;crypto ipsec ikev2 ipsec-proposal AES256&lt;BR /&gt;protocol esp encryption aes-256&lt;BR /&gt;protocol esp integrity sha-256 sha-1&lt;BR /&gt;crypto ipsec ikev2 ipsec-proposal AES192&lt;BR /&gt;protocol esp encryption aes-192&lt;BR /&gt;protocol esp integrity sha-256 sha-1&lt;BR /&gt;crypto ipsec ikev2 ipsec-proposal AES&lt;BR /&gt;protocol esp encryption aes&lt;BR /&gt;protocol esp integrity sha-256 sha-1&lt;BR /&gt;crypto ipsec ikev2 ipsec-proposal 3DES&lt;BR /&gt;protocol esp encryption aes&lt;BR /&gt;protocol esp integrity sha-256 sha-1&lt;BR /&gt;crypto ipsec ikev2 ipsec-proposal DES&lt;BR /&gt;protocol esp encryption aes&lt;BR /&gt;protocol esp integrity sha-256 sha-1&lt;BR /&gt;crypto ipsec profile AZURE-PROPOSAL&lt;BR /&gt;set ikev2 ipsec-proposal AZURE-PROPOSAL&lt;BR /&gt;crypto ipsec security-association pmtu-aging infinite&lt;BR /&gt;crypto dynamic-map SYSTEM_DEFAULT_CRYPTO_MAP 65535 set ikev1 transform-set ESP-AES-256-SHA&lt;BR /&gt;crypto dynamic-map SYSTEM_DEFAULT_CRYPTO_MAP 65535 set ikev2 ipsec-proposal AES256&lt;BR /&gt;crypto map ANYCONNECT_map 65535 ipsec-isakmp dynamic SYSTEM_DEFAULT_CRYPTO_MAP&lt;BR /&gt;crypto map ANYCONNECT_map interface OUTSIDE-ANYCONNECT&lt;BR /&gt;crypto map MVTEUCLOUD_map 65535 ipsec-isakmp dynamic SYSTEM_DEFAULT_CRYPTO_MAP&lt;BR /&gt;crypto map MVTEUCLOUD_map interface MVTEUCLOUD&lt;BR /&gt;crypto map MVTBRCLOUD_map 65535 ipsec-isakmp dynamic SYSTEM_DEFAULT_CRYPTO_MAP&lt;BR /&gt;crypto map LOC-LAN_map 65535 ipsec-isakmp dynamic SYSTEM_DEFAULT_CRYPTO_MAP&lt;BR /&gt;crypto map LOC-LAN_map interface INSIDE-LOC-LAN&lt;BR /&gt;crypto map PEER_I-R1_map 65535 ipsec-isakmp dynamic SYSTEM_DEFAULT_CRYPTO_MAP&lt;BR /&gt;crypto ca permit-weak-crypto&lt;BR /&gt;crypto ca trustpoint connect-i_2024v4&lt;BR /&gt;enrollment terminal&lt;BR /&gt;fqdn connect-i.magvatech.com&lt;BR /&gt;subject-name CN=connect-i.magvatech.com,O=Magvatech,C=TR,St=Izmir&lt;BR /&gt;keypair connect-i_2024v4&lt;BR /&gt;crl configure&lt;BR /&gt;crypto ca trustpoint Digisert&lt;BR /&gt;enrollment terminal&lt;BR /&gt;crl configure&lt;BR /&gt;crypto ca trustpoint Digisert2&lt;BR /&gt;enrollment terminal&lt;BR /&gt;crl configure&lt;BR /&gt;crypto ca trustpoint _SmartCallHome_ServerCA&lt;BR /&gt;no validation-usage&lt;BR /&gt;crl configure&lt;BR /&gt;crypto ca trustpoint _SmartCallHome_ServerCA2&lt;BR /&gt;no validation-usage&lt;BR /&gt;crl configure&lt;BR /&gt;crypto ca trustpoint ASDM_TrustPoint0&lt;BR /&gt;enrollment terminal&lt;BR /&gt;fqdn connect-i.magvatech.com&lt;BR /&gt;subject-name CN=connect-i.magvatech.com,O=Magvatech,C=TR,St=Gaziemir,L=Konak&lt;BR /&gt;keypair connect-i_2025&lt;BR /&gt;crl configure&lt;BR /&gt;crypto ca trustpoint ASDM_TrustPoint1&lt;BR /&gt;enrollment terminal&lt;BR /&gt;no validation-usage&lt;BR /&gt;crl configure&lt;BR /&gt;crypto ca trustpoint ASDM_TrustPoint2&lt;BR /&gt;enrollment terminal&lt;BR /&gt;no validation-usage&lt;BR /&gt;crl configure&lt;BR /&gt;crypto ca trustpool policy&lt;BR /&gt;auto-import&lt;BR /&gt;&lt;BR /&gt;crypto ikev2 policy 10&lt;BR /&gt;encryption aes-gcm-256 aes-gcm-192 aes-gcm&lt;BR /&gt;integrity null&lt;BR /&gt;group 14 5&lt;BR /&gt;prf sha512 sha384 sha256 sha&lt;BR /&gt;lifetime seconds 86400&lt;BR /&gt;crypto ikev2 policy 20&lt;BR /&gt;encryption aes-256 aes-192 aes&lt;BR /&gt;integrity sha512 sha384 sha256 sha&lt;BR /&gt;group 14 5&lt;BR /&gt;prf sha512 sha384 sha256 sha&lt;BR /&gt;lifetime seconds 86400&lt;BR /&gt;crypto ikev2 enable MVTEUCLOUD&lt;BR /&gt;crypto ikev2 enable MVTBRCLOUD&lt;BR /&gt;crypto ikev2 enable FCMEUCLOUD&lt;BR /&gt;crypto ikev2 enable TESCLOUD&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;webvpn&lt;BR /&gt;group-policy GroupPolicy_Connect-I_ISP internal&lt;BR /&gt;group-policy GroupPolicy_Connect-I_ISP attributes&lt;BR /&gt;dns-server value 10.14.1.4 8.8.8.8&lt;BR /&gt;vpn-tunnel-protocol ikev2 ssl-client&lt;BR /&gt;split-tunnel-policy tunnelall&lt;BR /&gt;group-policy AZURE internal&lt;BR /&gt;group-policy AZURE attributes&lt;BR /&gt;&lt;BR /&gt;tunnel-group DefaultWEBVPNGroup general-attributes&lt;BR /&gt;&lt;BR /&gt;default-group-policy AZURE&lt;BR /&gt;tunnel-group 52.174.183.101 ipsec-attributes&lt;BR /&gt;ikev2 remote-authentication pre-shared-key *****&lt;BR /&gt;ikev2 local-authentication pre-shared-key *****&lt;BR /&gt;tunnel-group 20.226.120.230 type ipsec-l2l&lt;BR /&gt;tunnel-group 20.226.120.230 general-attributes&lt;BR /&gt;default-group-policy AZURE&lt;BR /&gt;tunnel-group 20.226.120.230 ipsec-attributes&lt;BR /&gt;ikev2 remote-authentication pre-shared-key *****&lt;BR /&gt;ikev2 local-authentication pre-shared-key *****&lt;BR /&gt;tunnel-group 20.217.184.175 type ipsec-l2l&lt;BR /&gt;tunnel-group 20.217.184.175 general-attributes&lt;BR /&gt;default-group-policy AZURE&lt;BR /&gt;tunnel-group 20.217.184.175 ipsec-attributes&lt;BR /&gt;ikev2 remote-authentication pre-shared-key *****&lt;BR /&gt;ikev2 local-authentication pre-shared-key *****&lt;BR /&gt;tunnel-group 52.174.122.149 type ipsec-l2l&lt;BR /&gt;tunnel-group 52.174.122.149 general-attributes&lt;BR /&gt;default-group-policy AZURE&lt;BR /&gt;tunnel-group 52.174.122.149 ipsec-attributes&lt;BR /&gt;ikev2 remote-authentication pre-shared-key *****&lt;BR /&gt;ikev2 local-authentication pre-shared-key *****&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 27 Feb 2025 11:16:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/vpn/the-tunnels-between-azure-and-cisco-asa-stopped-working/m-p/5265478#M298676</guid>
      <dc:creator>Vasiliy P</dc:creator>
      <dc:date>2025-02-27T11:16:12Z</dc:date>
    </item>
    <item>
      <title>Re: The tunnels between AZURE and Cisco ASA stopped working.</title>
      <link>https://community.cisco.com/t5/vpn/the-tunnels-between-azure-and-cisco-asa-stopped-working/m-p/5265566#M298680</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;- Check the &lt;U&gt;&lt;STRONG&gt;logs&lt;/STRONG&gt; &lt;/U&gt;on the ASA ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp; M.&lt;/P&gt;</description>
      <pubDate>Thu, 27 Feb 2025 14:02:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/vpn/the-tunnels-between-azure-and-cisco-asa-stopped-working/m-p/5265566#M298680</guid>
      <dc:creator>marce1000</dc:creator>
      <dc:date>2025-02-27T14:02:16Z</dc:date>
    </item>
    <item>
      <title>Re: The tunnels between AZURE and Cisco ASA stopped working.</title>
      <link>https://community.cisco.com/t5/vpn/the-tunnels-between-azure-and-cisco-asa-stopped-working/m-p/5265846#M298682</link>
      <description>&lt;P&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;The problem was solved.&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;SPAN class=""&gt;&lt;SPAN class=""&gt;The interface in AZURE froze.&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;SPAN class=""&gt;&lt;SPAN class=""&gt;After updating it and switching, everything started working.&lt;BR /&gt;&lt;SPAN&gt;Thank you all very much!&lt;/SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 28 Feb 2025 05:23:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/vpn/the-tunnels-between-azure-and-cisco-asa-stopped-working/m-p/5265846#M298682</guid>
      <dc:creator>Vasiliy P</dc:creator>
      <dc:date>2025-02-28T05:23:17Z</dc:date>
    </item>
  </channel>
</rss>

