12-09-2019 10:02 AM - edited 02-21-2020 09:45 AM
Hi,
I have set up a new VPN tunnel to a remote site, but the tunnel will not come up.
Running packet-tracer shows that the tunnel is failing with:
Phase: 8
Type: VPN
Subtype: encrypt
Result: DROP
Config:
Additional Information:
Result:
input-interface: inside
input-status: up
input-line-status: up
output-interface: outside
output-status: up
output-line-status: up
Action: drop
I have checked that the access-lists(encryption domain) matches.
I have checked that the return traffic matches the same nat rule as for outgoing traffic.
Any ideas what could be the cause for this?
I suspect this could be that the firewall does not have the source network directly connected, and that is why packet tracer cannot source the traffic correctly.
12-09-2019 02:36 PM
When the source subnet,subject to encryption is not directly connected, is it necessary to include the directly connected subnet in the access-list as well?
12-09-2019 02:42 PM
show your configuration otherwise its really hard to say what causing the issue.
12-10-2019 08:05 AM
Digging further into the logs i found this:
Local:0.0.0.0:0 Remote:0.0.0.0:0 Username:Unknown IKEv2 SA request rejected by CAC. Reason: IN-NEGOTIATION SA LIMIT REACHED
12-10-2019 09:25 AM
You may have found this already, but it seems like you're hitting this bug:
12-11-2019 02:09 AM
yes, lovely
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide