05-21-2020 09:36 AM
So on the responder I see it gets to IKE_R_MM2 and keeps retransmiiting on the phase 1 MM_SA_SETUP.
Now given it makes it to this stage, suspect there may be a unidirectional routing issue through the WAN/tranpsort perhaps? There obviously is certain reachability if the responder receives packets. What else can I try and look for or do to confirm this? I know traceroute makes it up to provider FW next to our equiipment but never completes, nor are pings successful. Any help?
05-21-2020 12:31 PM
Hello,
what firewall is that ? Do you have the configuration ? Check if UDP port 500 is allowed through the firewall...
05-21-2020 04:03 PM - edited 05-21-2020 04:04 PM
Its not a FW its a ISR. Yes UDP500 and ESP are allowed.
Wouldn't it fail first at MM1 if UDP500 or ESP50 were not allowed or there was no reachability what so ever or no?
I confirm and see some UDP both ways on both the ingress/egress interface of my FW that basically sits in between the two tunnel router endpoints. There does not seem to be much as much traffic from both the routers however compared to working tunnels.
No I can't put the configs on here but it is basically pretty standard and the same on both devices.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide