05-10-2018 07:17 PM - edited 03-12-2019 03:52 AM
Hi Experts,
Having issue with one tunnel only in ASA5516 Version 9.5(2).
At moment, I recived a call from helpdesk that its again stop working please do something then I do timely clear the ipsec peer and then it start working.
What I inspect,
1. when I type show vpn-sess l2l, that peer Bytes RX : stucked while Bytes TX : Keep Changing.
2. When I clear both TX/RX become zero.
Please help.
05-12-2018 04:54 AM
Hello Animesh,
If the receive side stops and the transmit continues, I would suspect that there are two routes coming in to that IP where you have the specific IPSEC tunnel configured. So traffic establishes through the correct route and then for some reason it goes through another, at which point you stop receiving traffic on the specific IPSEC tunnel, when the latter occurs you are in a situation of asymmetric route.
Note that this is an issue that can have other causes as well, but from the information you provided I would check the routing tables, on both sides of the tunnel, to begin with and try to establish that there is only one route for the specific traffic.
Hope that helps.
05-14-2018 01:28 AM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide