<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA to Draytek IPSEC S2S tunnel stuck in MM_WAIT_MSG2 in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-to-draytek-ipsec-s2s-tunnel-stuck-in-mm-wait-msg2/m-p/4260021#M1076737</link>
    <description>&lt;P&gt;The error message you received on the ASA "MM_WAIT_MSG2" confirms the ASA is the initiator and is waiting to hear back from the peer (draytek). So if the draytek was set to "dial-out" when these logs were generated, that would explain why the ASA is waiting to hear back and not getting a response.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Set to "both" on the draytek, turn on the debug logs from the CLI,&amp;nbsp;generate some traffic to establish the tunnel. Provide the output of the debug for review, a screenshot from ASDM is not sufficient.&lt;/P&gt;</description>
    <pubDate>Thu, 17 Dec 2020 12:20:15 GMT</pubDate>
    <dc:creator>Rob Ingram</dc:creator>
    <dc:date>2020-12-17T12:20:15Z</dc:date>
    <item>
      <title>ASA to Draytek IPSEC S2S tunnel stuck in MM_WAIT_MSG2</title>
      <link>https://community.cisco.com/t5/network-security/asa-to-draytek-ipsec-s2s-tunnel-stuck-in-mm-wait-msg2/m-p/4260012#M1076731</link>
      <description>&lt;P&gt;I have configured a VPN site to site IPSEC tunnel from ASA to Draytek with IKEv1 and PFS disabled but Phase 1 stuck in MM_WAIT_MSG2.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Phase 1 and 2 configs are identical and cross-verified multiple times.&lt;BR /&gt;&lt;BR /&gt;What can be the issue?&lt;BR /&gt;&lt;BR /&gt;Phase 1 policy used:&lt;/P&gt;&lt;P&gt;crypto ikev1 policy 15&lt;BR /&gt;authentication pre-share&lt;BR /&gt;encryption aes-256&lt;BR /&gt;hash sha&lt;BR /&gt;group 5&lt;BR /&gt;lifetime 86400&lt;BR /&gt;&lt;BR /&gt;Phase 2 setup:&lt;BR /&gt;crypto map SME_ASAv_Ext_map1 &amp;lt;&amp;gt; match address &amp;lt;Cryptop Map&amp;gt;&lt;BR /&gt;crypto map SME_ASAv_Ext_map1 &amp;lt;&amp;gt; set peer &amp;lt;Peer IP&amp;gt;&lt;BR /&gt;crypto map SME_ASAv_Ext_map1 &amp;lt;&amp;gt; set ikev1 transform-set ESP-AES-256-SHA&lt;BR /&gt;crypto map SME_ASAv_Ext_map1 &amp;lt;&amp;gt; set security-association lifetime seconds 3600&lt;BR /&gt;crypto map SME_ASAv_Ext_map1 &amp;lt;&amp;gt; set reverse-route&lt;/P&gt;</description>
      <pubDate>Thu, 17 Dec 2020 12:04:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-to-draytek-ipsec-s2s-tunnel-stuck-in-mm-wait-msg2/m-p/4260012#M1076731</guid>
      <dc:creator>Prashobcv93</dc:creator>
      <dc:date>2020-12-17T12:04:31Z</dc:date>
    </item>
    <item>
      <title>Re: ASA to Draytek IPSEC S2S tunnel stuck in MM_WAIT_MSG2</title>
      <link>https://community.cisco.com/t5/network-security/asa-to-draytek-ipsec-s2s-tunnel-stuck-in-mm-wait-msg2/m-p/4260014#M1076733</link>
      <description>&lt;P&gt;Logs don't provide much info.&lt;BR /&gt;&lt;BR /&gt;IKE initiator New Phase 1.&lt;/P&gt;</description>
      <pubDate>Thu, 17 Dec 2020 12:02:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-to-draytek-ipsec-s2s-tunnel-stuck-in-mm-wait-msg2/m-p/4260014#M1076733</guid>
      <dc:creator>Prashobcv93</dc:creator>
      <dc:date>2020-12-17T12:02:32Z</dc:date>
    </item>
    <item>
      <title>Re: ASA to Draytek IPSEC S2S tunnel stuck in MM_WAIT_MSG2</title>
      <link>https://community.cisco.com/t5/network-security/asa-to-draytek-ipsec-s2s-tunnel-stuck-in-mm-wait-msg2/m-p/4260017#M1076735</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1145162"&gt;@Prashobcv93&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am not familar with Draytek firewalls/routers, but on image PJH 02.jpg you have the value "Call direction" both/dial-out/dial-in with dial-out selected. I assume that relates to which side can initate the tunnel? In which case only traffic initated from the draytek network can start the tunnel. Change it to "both" and test again.&lt;/P&gt;</description>
      <pubDate>Thu, 17 Dec 2020 12:09:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-to-draytek-ipsec-s2s-tunnel-stuck-in-mm-wait-msg2/m-p/4260017#M1076735</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2020-12-17T12:09:55Z</dc:date>
    </item>
    <item>
      <title>Re: ASA to Draytek IPSEC S2S tunnel stuck in MM_WAIT_MSG2</title>
      <link>https://community.cisco.com/t5/network-security/asa-to-draytek-ipsec-s2s-tunnel-stuck-in-mm-wait-msg2/m-p/4260018#M1076736</link>
      <description>&lt;P&gt;Hi Rob,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I tried with Call direction as Dial-Out and Both but no luck.&lt;/P&gt;</description>
      <pubDate>Thu, 17 Dec 2020 12:13:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-to-draytek-ipsec-s2s-tunnel-stuck-in-mm-wait-msg2/m-p/4260018#M1076736</guid>
      <dc:creator>Prashobcv93</dc:creator>
      <dc:date>2020-12-17T12:13:49Z</dc:date>
    </item>
    <item>
      <title>Re: ASA to Draytek IPSEC S2S tunnel stuck in MM_WAIT_MSG2</title>
      <link>https://community.cisco.com/t5/network-security/asa-to-draytek-ipsec-s2s-tunnel-stuck-in-mm-wait-msg2/m-p/4260021#M1076737</link>
      <description>&lt;P&gt;The error message you received on the ASA "MM_WAIT_MSG2" confirms the ASA is the initiator and is waiting to hear back from the peer (draytek). So if the draytek was set to "dial-out" when these logs were generated, that would explain why the ASA is waiting to hear back and not getting a response.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Set to "both" on the draytek, turn on the debug logs from the CLI,&amp;nbsp;generate some traffic to establish the tunnel. Provide the output of the debug for review, a screenshot from ASDM is not sufficient.&lt;/P&gt;</description>
      <pubDate>Thu, 17 Dec 2020 12:20:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-to-draytek-ipsec-s2s-tunnel-stuck-in-mm-wait-msg2/m-p/4260021#M1076737</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2020-12-17T12:20:15Z</dc:date>
    </item>
  </channel>
</rss>

