<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA IPSec Ikev2 VPN tunnel down issue in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-ipsec-ikev2-vpn-tunnel-down-issue/m-p/4891950#M1102951</link>
    <description>&lt;P&gt;hi&lt;/P&gt;
&lt;P&gt;What exactly was the problem? - the use of ikev1 instead of ikev2?&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 25 Jul 2023 09:00:29 GMT</pubDate>
    <dc:creator>Yordan1</dc:creator>
    <dc:date>2023-07-25T09:00:29Z</dc:date>
    <item>
      <title>ASA IPSec Ikev2 VPN tunnel down issue</title>
      <link>https://community.cisco.com/t5/network-security/asa-ipsec-ikev2-vpn-tunnel-down-issue/m-p/4119803#M1072089</link>
      <description>&lt;P&gt;Need support, as we are facing issue with VPN tunnels which went down in ASA. Tunnel was up and was working fine, but suddenly it went down. Below are the error message i am getting on ASA firewall.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Need support to figure out this issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;IKEv2-PLAT-5: INVALID PSH HANDLE&lt;BR /&gt;IKEv2-PLAT-5: INVALID PSH HANDLE&lt;BR /&gt;IKEv2-PLAT-2: attempting to find tunnel group for IP: 62.193.73.40&lt;BR /&gt;IKEv2-PLAT-2: mapped to tunnel group 62.193.73.40 using peer IP&lt;BR /&gt;IKEv2-PLAT-5: INVALID PSH HANDLE&lt;BR /&gt;IKEv2-PLAT-5: INVALID PSH HANDLE&lt;BR /&gt;IKEv2-PLAT-5: INVALID PSH HANDLE&lt;BR /&gt;IKEv2-PLAT-2: my_auth_method = 2&lt;BR /&gt;IKEv2-PLAT-2: supported_peers_auth_method = 2&lt;BR /&gt;IKEv2-PLAT-2: P1 ID = 0&lt;BR /&gt;IKEv2-PLAT-2: Translating IKE_ID_AUTO to = 255&lt;BR /&gt;IKEv2-PLAT-5: INVALID PSH HANDLE&lt;BR /&gt;IKEv2-PLAT-2: Received PFKEY SPI callback for SPI 0x5F3E7150, error FALSE&lt;BR /&gt;IKEv2-PLAT-2:&lt;BR /&gt;IKEv2 received a requested SPI from CTM and waiting for 5 more SPIs&lt;BR /&gt;IKEv2-PLAT-2: Received PFKEY SPI callback for SPI 0xD8BE34AF, error FALSE&lt;BR /&gt;IKEv2-PLAT-2:&lt;BR /&gt;IKEv2 received a requested SPI from CTM and waiting for 4 more SPIs&lt;BR /&gt;IKEv2-PLAT-2: Received PFKEY SPI callback for SPI 0xC8E638DD, error FALSE&lt;BR /&gt;IKEv2-PLAT-2:&lt;BR /&gt;IKEv2 received a requested SPI from CTM and waiting for 3 more SPIs&lt;BR /&gt;IKEv2-PLAT-2: Received PFKEY SPI callback for SPI 0x586654AF, error FALSE&lt;BR /&gt;IKEv2-PLAT-2:&lt;BR /&gt;IKEv2 received a requested SPI from CTM and waiting for 2 more SPIs&lt;BR /&gt;IKEv2-PLAT-2: Received PFKEY SPI callback for SPI 0x81D31FB5, error FALSE&lt;BR /&gt;IKEv2-PLAT-2:&lt;BR /&gt;IKEv2 received a requested SPI from CTM and waiting for 1 more SPIs&lt;BR /&gt;IKEv2-PLAT-2: Received PFKEY SPI callback for SPI 0x63593133, error FALSE&lt;BR /&gt;IKEv2-PLAT-2:&lt;BR /&gt;IKEv2 received all requested SPIs from CTM to initiate tunnel.&lt;BR /&gt;IKEv2-PLAT-5: INVALID PSH HANDLE&lt;BR /&gt;IKEv2-PLAT-5: INVALID PSH HANDLE&lt;BR /&gt;IKEv2-PLAT-2: tp_name set to:&lt;BR /&gt;IKEv2-PLAT-2: tg_name set to: 62.193.73.40&lt;BR /&gt;IKEv2-PLAT-2: tunn grp type set to: L2L&lt;BR /&gt;IKEv2-PLAT-5: New ikev2 sa request admitted&lt;BR /&gt;IKEv2-PLAT-5: Incrementing outgoing negotiating sa count by one&lt;BR /&gt;IKEv2-PLAT-3: (974): SENT PKT [IKE_SA_INIT] [41.65.204.228]:500-&amp;gt;[62.193.73.40]:500 InitSPI=0x020d81dc2ec6afd0 RespSPI=0x0000000000000000 MID=00000000&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;IKEv2 Recv RAW packet dump&lt;BR /&gt;02 0d 81 dc 2e c6 af d0 2e c3 fa b7 73 42 0d c4 | ............sB..&lt;BR /&gt;29 20 22 20 00 00 00 00 00 00 00 24 00 00 00 08 | ) " .......$....&lt;BR /&gt;01 00 00 0e | ....&lt;BR /&gt;IKEv2-PLAT-3: RECV PKT [IKE_SA_INIT] [62.193.73.40]:500-&amp;gt;[41.65.204.228]:500 InitSPI=0x020d81dc2ec6afd0 RespSPI=0x2ec3fab773420dc4 MID=00000000&lt;BR /&gt;IKEv2-PLAT-5: Negotiating SA request deleted&lt;BR /&gt;IKEv2-PLAT-5: Decrement count for outgoing negotiating&lt;BR /&gt;IKEv2-PLAT-2: (974): PSH cleanup&lt;BR /&gt;IKEv2-PLAT-1: Failed to remove peer correlation entry from cikePeerCorrTable. Local Type = 0. Local Address = 0.0.0.0. Remote Type = 0. Remote Address = 0.0.0.0. Correlation Peer Index = 0. IPSEC Tunnel Index = 0.&lt;BR /&gt;IKEv2-PLAT-1: Failed to remove peer correlation entry from cikePeerCorrTable. Local Type = 0. Local Address = 0.0.0.0. Remote Type = 0. Remote Address = 0.0.0.0. Correlation Peer Index = 0. IPSEC Tunnel Index = 0.&lt;BR /&gt;IKEv2-PLAT-1: Failed to remove peer correlation entry from cikePeerCorrTable. Local Type = 0. Local Address = 0.0.0.0. Remote Type = 0. Remote Address = 0.0.0.0. Correlation Peer Index = 0. IPSEC Tunnel Index = 0.&lt;BR /&gt;IKEv2-PLAT-1: Failed to remove peer correlation entry from cikePeerCorrTable. Local Type = 0. Local Address = 0.0.0.0. Remote Type = 0. Remote Address = 0.0.0.0. Correlation Peer Index = 0. IPSEC Tunnel Index = 0.&lt;BR /&gt;IKEv2-PLAT-1: Failed to remove peer correlation entry from cikePeerCorrTable. Local Type = 0. Local Address = 0.0.0.0. Remote Type = 0. Remote Address = 0.0.0.0. Correlation Peer Index = 0. IPSEC Tunnel Index = 0.&lt;BR /&gt;IKEv2-PLAT-1: Failed to remove peer correlation entry from cikePeerCorrTable. Local Type = 0. Local Address = 0.0.0.0. Remote Type = 0. Remote Address = 0.0.0.0. Correlation Peer Index = 0. IPSEC Tunnel Index = 0.&lt;BR /&gt;IKEv2-PLAT-2: Received PFKEY delete SA for SPI 0x5F3E7150 error FALSE&lt;BR /&gt;IKEv2-PLAT-2: Received PFKEY delete SA for SPI 0xD8BE34AF error FALSE&lt;BR /&gt;IKEv2-PLAT-2: Received PFKEY delete SA for SPI 0xC8E638DD error FALSE&lt;BR /&gt;IKEv2-PLAT-2: Received PFKEY delete SA for SPI 0x586654AF error FALSE&lt;BR /&gt;IKEv2-PLAT-2: Received PFKEY delete SA for SPI 0x81D31FB5 error FALSE&lt;BR /&gt;IKEv2-PLAT-2: Received PFKEY delete SA for SPI 0x63593133 error FALSE&lt;BR /&gt;IKEv2-PLAT-2: Received PFKEY Acquire SA for SPI 0x0, error FALSE&lt;BR /&gt;IKEv2-PLAT-5: INVALID PSH HANDLE&lt;BR /&gt;IKEv2-PLAT-5: INVALID PSH HANDLE&lt;BR /&gt;IKEv2-PLAT-2: attempting to find tunnel group for IP: 62.193.73.40&lt;BR /&gt;IKEv2-PLAT-2: mapped to tunnel group 62.193.73.40 using peer IP&lt;BR /&gt;IKEv2-PLAT-5: INVALID PSH HANDLE&lt;BR /&gt;IKEv2-PLAT-5: INVALID PSH HANDLE&lt;BR /&gt;IKEv2-PLAT-5: INVALID PSH HANDLE&lt;BR /&gt;IKEv2-PLAT-2: my_auth_method = 2&lt;BR /&gt;IKEv2-PLAT-2: supported_peers_auth_method = 2&lt;BR /&gt;IKEv2-PLAT-2: P1 ID = 0&lt;BR /&gt;IKEv2-PLAT-2: Translating IKE_ID_AUTO to = 255&lt;BR /&gt;IKEv2-PLAT-5: INVALID PSH HANDLE&lt;BR /&gt;IKEv2-PLAT-2: Received PFKEY SPI callback for SPI 0xD224F1DF, error FALSE&lt;BR /&gt;IKEv2-PLAT-2:&lt;BR /&gt;IKEv2 received a requested SPI from CTM and waiting for 5 more SPIs&lt;BR /&gt;IKEv2-PLAT-2: Received PFKEY SPI callback for SPI 0x73A78E47, error FALSE&lt;BR /&gt;IKEv2-PLAT-2:&lt;BR /&gt;IKEv2 received a requested SPI from CTM and waiting for 4 more SPIs&lt;BR /&gt;IKEv2-PLAT-2: Received PFKEY SPI callback for SPI 0x10186562, error FALSE&lt;BR /&gt;IKEv2-PLAT-2:&lt;BR /&gt;IKEv2 received a requested SPI from CTM and waiting for 3 more SPIs&lt;BR /&gt;IKEv2-PLAT-2: Received PFKEY SPI callback for SPI 0x7F10A3FF, error FALSE&lt;BR /&gt;IKEv2-PLAT-2:&lt;BR /&gt;IKEv2 received a requested SPI from CTM and waiting for 2 more SPIs&lt;BR /&gt;IKEv2-PLAT-2: Received PFKEY SPI callback for SPI 0x869898E1, error FALSE&lt;BR /&gt;IKEv2-PLAT-2:&lt;BR /&gt;IKEv2 received a requested SPI from CTM and waiting for 1 more SPIs&lt;BR /&gt;IKEv2-PLAT-2: Received PFKEY SPI callback for SPI 0xB5857108, error FALSE&lt;BR /&gt;IKEv2-PLAT-2:&lt;BR /&gt;IKEv2 received all requested SPIs from CTM to initiate tunnel.&lt;BR /&gt;IKEv2-PLAT-5: INVALID PSH HANDLE&lt;BR /&gt;IKEv2-PLAT-5: INVALID PSH HANDLE&lt;BR /&gt;IKEv2-PLAT-2: tp_name set to:&lt;BR /&gt;IKEv2-PLAT-2: tg_name set to: 62.193.73.40&lt;BR /&gt;IKEv2-PLAT-2: tunn grp type set to: L2L&lt;BR /&gt;IKEv2-PLAT-5: New ikev2 sa request admitted&lt;BR /&gt;IKEv2-PLAT-5: Incrementing outgoing negotiating sa count by one&lt;BR /&gt;IKEv2-PLAT-3: (975): SENT PKT [IKE_SA_INIT] [41.65.204.228]:500-&amp;gt;[62.193.73.40]:500 InitSPI=0xc23347e2222776cc RespSPI=0x0000000000000000 MID=00000000&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;IKEv2 Recv RAW packet dump&lt;BR /&gt;c2 33 47 e2 22 27 76 cc d8 1b 84 86 93 1d 51 14 | .3G."'v.......Q.&lt;BR /&gt;29 20 22 20 00 00 00 00 00 00 00 24 00 00 00 08 | ) " .......$....&lt;BR /&gt;01 00 00 0e | ....&lt;BR /&gt;IKEv2-PLAT-3: RECV PKT [IKE_SA_INIT] [62.193.73.40]:500-&amp;gt;[41.65.204.228]:500 InitSPI=0xc23347e2222776cc RespSPI=0xd81b8486931d5114 MID=00000000&lt;BR /&gt;IKEv2-PLAT-5: Negotiating SA request deleted&lt;BR /&gt;IKEv2-PLAT-5: Decrement count for outgoing negotiating&lt;BR /&gt;IKEv2-PLAT-2: (975): PSH cleanup&lt;BR /&gt;IKEv2-PLAT-1: Failed to remove peer correlation entry from cikePeerCorrTable. Local Type = 0. Local Address = 0.0.0.0. Remote Type = 0. Remote Address = 0.0.0.0. Correlation Peer Index = 0. IPSEC Tunnel Index = 0.&lt;BR /&gt;IKEv2-PLAT-1: Failed to remove peer correlation entry from cikePeerCorrTable. Local Type = 0. Local Address = 0.0.0.0. Remote Type = 0. Remote Address = 0.0.0.0. Correlation Peer Index = 0. IPSEC Tunnel Index = 0.&lt;BR /&gt;IKEv2-PLAT-1: Failed to remove peer correlation entry from cikePeerCorrTable. Local Type = 0. Local Address = 0.0.0.0. Remote Type = 0. Remote Address = 0.0.0.0. Correlation Peer Index = 0. IPSEC Tunnel Index = 0.&lt;BR /&gt;IKEv2-PLAT-1: Failed to remove peer correlation entry from cikePeerCorrTable. Local Type = 0. Local Address = 0.0.0.0. Remote Type = 0. Remote Address = 0.0.0.0. Correlation Peer Index = 0. IPSEC Tunnel Index = 0.&lt;BR /&gt;IKEv2-PLAT-1: Failed to remove peer correlation entry from cikePeerCorrTable. Local Type = 0. Local Address = 0.0.0.0. Remote Type = 0. Remote Address = 0.0.0.0. Correlation Peer Index = 0. IPSEC Tunnel Index = 0.&lt;BR /&gt;IKEv2-PLAT-1: Failed to remove peer correlation entry from cikePeerCorrTable. Local Type = 0. Local Address = 0.0.0.0. Remote Type = 0. Remote Address = 0.0.0.0. Correlation Peer Index = 0. IPSEC Tunnel Index = 0.&lt;BR /&gt;IKEv2-PLAT-2: Received PFKEY delete SA for SPI 0xD224F1DF error FALSE&lt;BR /&gt;IKEv2-PLAT-2: Received PFKEY delete SA for SPI 0x73A78E47 error FALSE&lt;BR /&gt;IKEv2-PLAT-2: Received PFKEY delete SA for SPI 0x10186562 error FALSE&lt;BR /&gt;IKEv2-PLAT-2: Received PFKEY delete SA for SPI 0x7F10A3FF error FALSE&lt;BR /&gt;IKEv2-PLAT-2: Received PFKEY delete SA for SPI 0x869898E1 error FALSE&lt;BR /&gt;IKEv2-PLAT-2: Received PFKEY delete SA for SPI 0xB5857108 error FALSE&lt;BR /&gt;IKEv2-PLAT-2: Received PFKEY Acquire SA for SPI 0x0, error FALSE&lt;BR /&gt;IKEv2-PLAT-5: INVALID PSH HANDLE&lt;BR /&gt;IKEv2-PLAT-5: INVALID PSH HANDLE&lt;BR /&gt;IKEv2-PLAT-2: attempting to find tunnel group for IP: 62.193.73.40&lt;BR /&gt;IKEv2-PLAT-2: mapped to tunnel group 62.193.73.40 using peer IP&lt;BR /&gt;IKEv2-PLAT-5: INVALID PSH HANDLE&lt;BR /&gt;IKEv2-PLAT-5: INVALID PSH HANDLE&lt;BR /&gt;IKEv2-PLAT-5: INVALID PSH HANDLE&lt;BR /&gt;IKEv2-PLAT-2: my_auth_method = 2&lt;BR /&gt;IKEv2-PLAT-2: supported_peers_auth_method = 2&lt;BR /&gt;IKEv2-PLAT-2: P1 ID = 0&lt;BR /&gt;IKEv2-PLAT-2: Translating IKE_ID_AUTO to = 255&lt;BR /&gt;IKEv2-PLAT-5: INVALID PSH HANDLE&lt;BR /&gt;IKEv2-PLAT-2: Received PFKEY SPI callback for SPI 0x4701E818, error FALSE&lt;BR /&gt;IKEv2-PLAT-2:&lt;BR /&gt;IKEv2 received a requested SPI from CTM and waiting for 5 more SPIs&lt;BR /&gt;IKEv2-PLAT-2: Received PFKEY SPI callback for SPI 0x6CF14D00, error FALSE&lt;BR /&gt;IKEv2-PLAT-2:&lt;BR /&gt;IKEv2 received a requested SPI from CTM and waiting for 4 more SPIs&lt;BR /&gt;IKEv2-PLAT-2: Received PFKEY SPI callback for SPI 0x4A4E81C9, error FALSE&lt;BR /&gt;IKEv2-PLAT-2:&lt;BR /&gt;IKEv2 received a requested SPI from CTM and waiting for 3 more SPIs&lt;BR /&gt;IKEv2-PLAT-2: Received PFKEY SPI callback for SPI 0x8D7B56D0, error FALSE&lt;BR /&gt;IKEv2-PLAT-2:&lt;BR /&gt;IKEv2 received a requested SPI from CTM and waiting for 2 more SPIs&lt;BR /&gt;IKEv2-PLAT-2: Received PFKEY SPI callback for SPI 0x70FE0DEF, error FALSE&lt;BR /&gt;IKEv2-PLAT-2:&lt;BR /&gt;IKEv2 received a requested SPI from CTM and waiting for 1 more SPIs&lt;BR /&gt;IKEv2-PLAT-2: Received PFKEY SPI callback for SPI 0x8D374785, error FALSE&lt;BR /&gt;IKEv2-PLAT-2:&lt;BR /&gt;IKEv2 received all requested SPIs from CTM to initiate tunnel.&lt;BR /&gt;IKEv2-PLAT-5: INVALID PSH HANDLE&lt;BR /&gt;IKEv2-PLAT-5: INVALID PSH HANDLE&lt;BR /&gt;IKEv2-PLAT-2: tp_name set to:&lt;BR /&gt;IKEv2-PLAT-2: tg_name set to: 62.193.73.40&lt;BR /&gt;IKEv2-PLAT-2: tunn grp type set to: L2L&lt;BR /&gt;IKEv2-PLAT-5: New ikev2 sa request admitted&lt;BR /&gt;IKEv2-PLAT-5: Incrementing outgoing negotiating sa count by one&lt;BR /&gt;IKEv2-PLAT-3: (976): SENT PKT [IKE_SA_INIT] [41.65.204.228]:500-&amp;gt;[62.193.73.40]:500 InitSPI=0x0f013f25474cd723 RespSPI=0x0000000000000000 MID=00000000&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 16 Jul 2020 11:03:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-ipsec-ikev2-vpn-tunnel-down-issue/m-p/4119803#M1072089</guid>
      <dc:creator>preetpeethambaran</dc:creator>
      <dc:date>2020-07-16T11:03:30Z</dc:date>
    </item>
    <item>
      <title>Re: ASA IPSec Ikev2 VPN tunnel down issue</title>
      <link>https://community.cisco.com/t5/network-security/asa-ipsec-ikev2-vpn-tunnel-down-issue/m-p/4121331#M1072117</link>
      <description>&lt;P&gt;Is your issue fixed? need more data to find out what cause an issue.&lt;/P&gt;
&lt;P&gt;could you capture data and share with us.&lt;/P&gt;
&lt;PRE&gt;    Debugs:

Debug crypto condition peer 62.193.73.40
Debug crypto ikev2 platform 255
Debug crypto ikev2 protocol 255
Debug crypto ipsec 255
 

    Capture:

Capture isa type isakmp interface outside match ip host 62.193.73.40 host (outside ASA ip address)&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 19 Jul 2020 15:22:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-ipsec-ikev2-vpn-tunnel-down-issue/m-p/4121331#M1072117</guid>
      <dc:creator>Sheraz.Salim</dc:creator>
      <dc:date>2020-07-19T15:22:27Z</dc:date>
    </item>
    <item>
      <title>Re: ASA IPSec Ikev2 VPN tunnel down issue</title>
      <link>https://community.cisco.com/t5/network-security/asa-ipsec-ikev2-vpn-tunnel-down-issue/m-p/4138057#M1073118</link>
      <description>Thanks for the reply.&lt;BR /&gt;Issue is fixed - There was mismatch in Phase1 parameter on both sides.</description>
      <pubDate>Wed, 19 Aug 2020 12:32:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-ipsec-ikev2-vpn-tunnel-down-issue/m-p/4138057#M1073118</guid>
      <dc:creator>preetpeethambaran</dc:creator>
      <dc:date>2020-08-19T12:32:31Z</dc:date>
    </item>
    <item>
      <title>Re: ASA IPSec Ikev2 VPN tunnel down issue</title>
      <link>https://community.cisco.com/t5/network-security/asa-ipsec-ikev2-vpn-tunnel-down-issue/m-p/4891950#M1102951</link>
      <description>&lt;P&gt;hi&lt;/P&gt;
&lt;P&gt;What exactly was the problem? - the use of ikev1 instead of ikev2?&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Jul 2023 09:00:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-ipsec-ikev2-vpn-tunnel-down-issue/m-p/4891950#M1102951</guid>
      <dc:creator>Yordan1</dc:creator>
      <dc:date>2023-07-25T09:00:29Z</dc:date>
    </item>
  </channel>
</rss>

