10-21-2023 08:48 AM
we have around 100+ site to site VPN integrations. previously we were working smoothly with VPN configuration with out any issue.
but after upgrading our FMC from 7.0.5 to 7.2.5 we have faced on establishing site to site VPN.this is like this :
the VPN is active both phase1 and phase2 .
our partner can reach to our end point successfully and both decap and encap is has some number.
but we are not able to reach partners end point . out going traffic is not working . only incoming traffic is ok.
NAT exemption is done on FTD 2130 Model.
does the upgrade FMC version(7.2.5) has issue like this
10-21-2023 08:53 AM
Can you clear tunnel and check again.
I think the SA is duplicate.
10-21-2023 09:35 AM
yea ,I have cleared the tunnel. this issue is the same for 7 tunnels that are created after the upgrade
10-21-2023 10:20 AM
Do you use pbr with flexconfig?
Do you use NAT source/destiantion (no exemption NAT) for vpn ?
10-22-2023 11:25 AM
yea we did NAT exemption as we do have dynamic NAT.
Is there any bug with the current FMC(7.2.5).
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide