Once the pre-deploy package win-X.X.XXXXX-umbrella-predeploy-k9.msi is put on a machine, you need to navigate to the folder having that MSI file and then run the below commands while doing the installation
msiexec /package any...
this looks like a udp 500 block. please apply similar capture on the remote end to check if the udp 500 is being received there and being sent out.
you need to contact your ISP to check if they are blocking udp 500
The tunnel should come up with xxx.xxx.xxx.168 ip as well. Please collect the below captures when you try to configure xxx.xxx.xxx.168 on the primary ASA and the secondary ASA:
capture cap interface <outside interface name> match ip host <p...