cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1048
Views
5
Helpful
9
Replies

FTD VPN : inactive due to Peer Address Changed.

engchheang
Level 1
Level 1

Hello all,

I have got an error like this : Site A - VPN Tunnel between FW/OUT/x.x.x.x/0.0.0.0 and Extranet Device/x.x.x.x/LAN-B is inactive due to Peer Address Changed.

but the connection VPN is up as normal!

Have you ever meet this issue please help to share your solution!!

Thanks in advanced 

9 Replies 9

Jitendra Kumar
Spotlight
Spotlight

engchheang
Level 1
Level 1

Jitendra,

Can you detail solution for me ?

If you are in the same affected release you have to upgrade.

Product (1 of 1)
Cisco Adaptive Security Appliance (ASA) Software
Known Affected Releases (1 of 1)
9.0
Known Fixed Releases (3 of 3)
9.7.1
9.6.3
9.4.4
Thanks,
Jitendra

I'm using Firepower 2120 not ASA.

can you share IPsec config details from both side?

 

Thanks,
Jitendra

Sorry i can't, but the configuration is the same as standard IPsec VPN.

you must config FTD side with dynamic Crypto map, this make the FTD listen to new IPsec Peer IP. 

Hi MHM,

Is there other solution beside this solution ?

https://www.cisco.com/c/en/us/support/docs/security/asa-5500-x-series-next-generation-firewalls/119007-config-asa9x-ike-ipsec-00.html
config the FW with FQDN Peer instead of IP, example above give you some point how you config it.

Review Cisco Networking for a $25 gift card