05-03-2019 08:27 AM
HI all,
I have Site to site vpn established between meraki MX84 and ASA 5525.
sometimes one of subnet in crypto ACL is getting disconnected from tunnel from meraki end as well as asa end.
Thanks in advance.
05-03-2019 09:15 AM
Do you have stability internet and confirmed there is no issue with internet ?
what do you see the logs, when you lost the tunnel ? both ASA and Meraki side ?
05-06-2019 01:48 AM
From meraki end
Actually from one vlan subnet I am able to reach the tunnel and from another VLAN subnet I am unable to reach sometimes
From ASA end
No Breakage is observed towards meraki tunnel at that time.
Logs at MX84 end
log: Failed to preprocess ph-2 packet(side:1 status:1)
log: Failed to get security association info.
No logs at ASA end.
All parameters are identical and ACL also identical on both ends
05-09-2019 06:57 AM
Both ISP connectivity is Stable. We have another site to site VPN from that ASA to Another ASA they are not observing any issues.
From Meraki Side
Log
msg: Ipsec-SA established 115.110.X.X[4500]-115.110.X.X[4500]
This log i am getting from meraki end
ASA end is tunnel status is up traffic is on going.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide