cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1035
Views
0
Helpful
4
Replies

VPN site to site problem

FRasuli01
Level 1
Level 1

Hi everyone

The problem is the vpn suddenly stoped working,

 

IKE Peer: xx.xx.xx.xx
    Type    : L2L             Role    : initiator 
    Rekey   : no              State   : MM_ACTIVE
 
 
 
peer address: xx.xx.xx.xx
    Crypto map tag: outside_map, seq num: 1, local addr: yy.yy.yy.yy
      
      access-list outside_1_cryptomap permit ip host zz.zz.zz.zz host xx.xx.xx.xx 
      local ident (addr/mask/prot/port): (zz.zz.zz.zz/255.255.255.255/0/0)
      remote ident (addr/mask/prot/port): (xx.xx.xx.xx/255.255.255.255/0/0)
      current_peer: xx.xx.xx.xx
 
      #pkts encaps: 0, #pkts encrypt: 0, #pkts digest: 0       
      #pkts decaps: 20122, #pkts decrypt: 20122, #pkts verify: 20122
      #pkts compressed: 0, #pkts decompressed: 0
      #pkts not compressed: 0, #pkts comp failed: 0, #pkts decomp failed: 0
      #pre-frag successes: 0, #pre-frag failures: 0, #fragments created: 0
      #PMTUs sent: 0, #PMTUs rcvd: 0, #decapsulated frgs needing reassembly: 0
      #send errors: 0, #recv errors: 0
 
      local crypto endpt.: yy.yy.yy.yy/4500, remote crypto endpt.: xx.xx.xx.xx/4500
      path mtu 1500, ipsec overhead 66, media mtu 1500
      current outbound spi: DB3E5ABE
 
    inbound esp sas:
      spi: 0x0E11FF79 (236060537)
         transform: esp-3des esp-sha-hmac none 
         in use settings ={L2L, Tunnel,  NAT-T-Encaps, PFS Group 2, }
         slot: 0, conn_id: 59952, crypto-map: outside_map
         sa timing: remaining key lifetime (sec): 2968
         IV size: 8 bytes
         replay detection support: Y
    outbound esp sas:
      spi: 0xDB3E5ABE (3678296766)
         transform: esp-3des esp-sha-hmac none 
         in use settings ={L2L, Tunnel,  NAT-T-Encaps, PFS Group 2, }
         slot: 0, conn_id: 59952, crypto-map: outside_map
         sa timing: remaining key lifetime (sec): 2968
         IV size: 8 bytes
         replay detection support: Y
 
No outgoing packets.
#pkts encaps: 0, #pkts encrypt: 0, #pkts digest: 0       
      #pkts decaps: 20122, #pkts decrypt: 20122, #pkts verify: 20122
 
Where the problem might be?
 
4 Replies 4

vishal vyas
Level 1
Level 1

Please check interesting hosts access list both side 

Packets are touch the access-list, but do not go through thunnel. What maight be the problem?

#pkts encaps: 0, #pkts encrypt: 0, #pkts digest: 0  , packets are not encapsulating.

Packets are not hitting the tunnel, do you have multiple outside interfaces if so please check the routing.

by debug crypto ipsec 100 can see

IPSEC WARNING: outbound SA deletion retry, SPI: 0xF2DE0B5D, user: xx.xx.xx.xx, peer: xx.xx.xx.xx