08-16-2022 09:19 PM
Hello all,
I have got an error like this : Site A - VPN Tunnel between FW/OUT/x.x.x.x/0.0.0.0 and Extranet Device/x.x.x.x/LAN-B is inactive due to Peer Address Changed.
but the connection VPN is up as normal!
Have you ever meet this issue please help to share your solution!!
Thanks in advanced
08-16-2022 10:20 PM
08-16-2022 11:37 PM
Jitendra,
Can you detail solution for me ?
08-17-2022 12:46 AM
If you are in the same affected release you have to upgrade.
08-17-2022 01:54 AM
I'm using Firepower 2120 not ASA.
08-17-2022 02:10 AM
can you share IPsec config details from both side?
08-18-2022 12:10 AM
Sorry i can't, but the configuration is the same as standard IPsec VPN.
08-17-2022 07:04 AM
you must config FTD side with dynamic Crypto map, this make the FTD listen to new IPsec Peer IP.
08-18-2022 12:11 AM
Hi MHM,
Is there other solution beside this solution ?
08-18-2022 06:16 AM
https://www.cisco.com/c/en/us/support/docs/security/asa-5500-x-series-next-generation-firewalls/119007-config-asa9x-ike-ipsec-00.html
config the FW with FQDN Peer instead of IP, example above give you some point how you config it.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide