IKEv2 Site to Site VPN having ERROR: Maximum transmissions reached
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
09-21-2021 07:16 AM
Configured a new VPN from ASAV to Sonicwall.
VPN Phase 1 is not coming up with an Error as the Maximum number of transmissions reached.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
09-21-2021 07:18 AM
Phase 1 in ASA:
encryption aes-256
integrity sha256
group 14 5
prf sha256
lifetime seconds 86400
set pfs group14
set peer 89.242.3.146
set ikev2 ipsec-proposal AES-256-SHA-256
set security-association lifetime seconds 3600
set reverse-route
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
09-21-2021 07:19 AM
SonicWall config attached.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
09-21-2021 07:22 AM
Debug logs attached
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
09-21-2021 07:50 AM - edited 09-21-2021 07:51 AM
@Prashobcv93 try changing the Peer IKE ID on the Sonicwall (located in the General tab) to the private IP address of the ASA - 10.45.56.110
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
09-21-2021 07:54 AM
Tried both but no luck.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
09-21-2021 07:58 AM
@Prashobcv93 please provide the full ASA config
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
09-21-2021 08:02 AM
ASAV config attached.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
09-21-2021 08:16 AM
@Prashobcv93 The ASA is behind NAT but is the Sonicwall also?
Please turn on IKEv2 debugs on the ASA, attempt to establish the VPN tunnel and provide the debugs for review.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
09-21-2021 08:45 AM
Customer end device setting needs to be applied after a reboot and their firmware is outdated.
Awaiting device reboot and firmware upgrade.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
09-21-2021 10:48 AM
I am awaiting some time after the UK business hours to enable the debug.
I have the logs from the Sonicwall firewall (attached).
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
09-23-2021 03:32 AM
Customer Sonicwall was out of date and was asking for a reboot for any new changes to apply.
The VPN profile in Sonicwall was flushed and recreated, and the VPN came up instantly.
Thanks for your help, @Rob Ingram
