cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1498
Views
0
Helpful
3
Replies

VPN Tunnel Traffic intermittently disconnecting

Ravi@2670
Level 1
Level 1

HI all,

 

I have Site to site vpn established between meraki MX84 and ASA 5525.

sometimes one of subnet in crypto ACL is getting disconnected from tunnel from meraki end as well as asa end.

 

Thanks in advance.

3 Replies 3

balaji.bandi
Hall of Fame
Hall of Fame

Do you have stability internet  and confirmed there is no issue with internet ?

 

what do you see the logs, when you lost the tunnel ? both ASA and Meraki side ?

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

From meraki end

Actually from one vlan subnet I am able to reach the tunnel and from another VLAN subnet I am unable to reach sometimes

 

From ASA end

No Breakage is observed towards meraki tunnel at that time.

 

Logs at MX84 end

log: Failed to preprocess ph-2 packet(side:1 status:1)

log: Failed to get security association info.

 

No logs at ASA end.

 

All parameters are identical and ACL also identical on both ends

Both ISP connectivity is Stable. We have another site to site VPN from that ASA to Another ASA they are not observing any issues.

 

From Meraki Side

Log

msg: Ipsec-SA established 115.110.X.X[4500]-115.110.X.X[4500] 

 

This log i am getting from meraki end 

ASA end is tunnel status is up traffic is on going. 

 

 

 

Review Cisco Networking for a $25 gift card