cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
5437
Views
0
Helpful
5
Replies

ASA VPN Tunnel Phase 8 Subtype encrypt : DROP

Chewbakka1
Level 1
Level 1

Hi,

I have set up a new VPN tunnel to a remote site, but the tunnel will not come up.

Running packet-tracer shows that the tunnel is failing with:

Phase: 8
Type: VPN
Subtype: encrypt
Result: DROP
Config:
Additional Information:

Result:
input-interface: inside
input-status: up
input-line-status: up
output-interface: outside
output-status: up
output-line-status: up
Action: drop

 

I have checked that the access-lists(encryption domain) matches.

I have checked that the return traffic matches the same nat rule as for outgoing traffic.

 

Any ideas what could be the cause for this?

I suspect this could be that the firewall does not have the source network directly connected, and that is why packet tracer cannot source the traffic correctly.

5 Replies 5

Chewbakka1
Level 1
Level 1

When the source subnet,subject to encryption is not directly connected, is it necessary to include the directly connected subnet in the access-list as well?

show your configuration otherwise its really hard to say what causing the issue.

please do not forget to rate.

Digging further into the logs i found this:

Local:0.0.0.0:0 Remote:0.0.0.0:0 Username:Unknown IKEv2 SA request rejected by CAC. Reason: IN-NEGOTIATION SA LIMIT REACHED

 

 

You may have found this already, but it seems like you're hitting this bug:

 

ASA IKEv2:L2L tunnel failing with IN-NEGOTIATION SA LIMIT REACHED
CSCug95008
 

yes, lovely

Review Cisco Networking for a $25 gift card