03-19-2015 01:29 AM - edited 03-11-2019 10:39 PM
Dear Experts,
I am facing an issue with IPsec Tunnel. the tunnel is unstable.
We have Cisco ASA at HO and Cisco Router at Remote Branch.
from HO we have 5 tunnels, all are stable, only one tunnel is unstable. it is establishing and then disconnecting. Please let me know what shall I check at remote end as every thing seems to be fine with ASA.
the MM_WAIT message keep on changing and the status becoming MM_ACTIVE, then after 1 minute the tunnel is going down. Then again the same cycle is repeated.
Please help to understand the issue.
03-19-2015 07:10 AM
Are you ever able to have the tunnel up for a long amount of time and are you able to pass any traffic at all across the tunnel? If not, to me that suggests that phase 1 is completing, but your phase 2 is mismatched. If you do show crypto ipsec sa peer x.x.x.x where x.x.x.x is the peer IP address, do you see any SAs listed when the tunnel is in MM_ACTIVE state?
03-19-2015 10:58 AM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide