cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
Announcements

Ask the Expert- SD-WAN

225
Views
0
Helpful
0
Replies
Highlighted
Beginner

IPsec VPN re-keying sometimes fails between ASA5525 and Meraki MX68

Hello,

 

I am having this issue that Ipsec VPN re-keying between ASA5525 and MX68 sometimes fails.

 

This issue happens about once a week.

workaround for the issue is clearing ikev1 sa and ipsec sa but I would like to know the root cause of this issue.

 

I read this somewhere that lifetime of ike tunnel should always be greater than lifetime of ipsec tunnel (although I could not find the reason of this practice.)

 

My current config is not following this practice. means phase 1 and phase 2 have the same lifetime at this moment.

Could this config cause this re-key issue?

 

I see these logs on ASA side:

Removing peer from correlator table failed, no match!

All IPSec SA proposals found unacceptable!

 

I see these logs on Meraki:

Jun 5 12:48:21 Non-Meraki / Client VPN negotiation msg: no proposal chosen.
Jun 5 12:48:21 Non-Meraki / Client VPN negotiation msg: no suitable policy found.
Jun 5 12:48:21 Non-Meraki / Client VPN negotiation msg: not matched
Jun 5 12:48:21 Non-Meraki / Client VPN negotiation msg: encmode mismatched: my:Tunnel peer:UDP-Tunnel
Jun 5 12:48:20 Non-Meraki / Client VPN negotiation msg: notification NO-PROPOSAL-CHOSEN received in informational exchange.
Jun 5 12:48:20 Non-Meraki / Client VPN negotiation msg: initiate new phase 2 negotiation:xxx
Jun 5 12:48:20 Non-Meraki / Client VPN negotiation msg: purged IPsec-SA proto_id=ESP spi=2758757436.
Jun 5 12:48:20 Non-Meraki / Client VPN negotiation msg: IPsec-SA expired: ESP/Tunnel xxx
Jun 5 12:48:18 Non-Meraki / Client VPN negotiation msg: notification NO-PROPOSAL-CHOSEN received in informational exchange.
Jun 5 12:48:18 Non-Meraki / Client VPN negotiation msg: initiate new phase 2 negotiation: 61.xxx
Jun 5 12:48:16 xxx 802.11 disassociation unknown reason
Jun 5 12:48:16 Non-Meraki / Client VPN negotiation msg: failed to pre-process ph2 packet (side: 1, status: 1).
Jun 5 12:48:16 Non-Meraki / Client VPN negotiation msg: no proposal chosen.
Jun 5 12:48:16 Non-Meraki / Client VPN negotiation msg: no suitable policy found.
Jun 5 12:48:16 Non-Meraki / Client VPN negotiation msg: not matched

 

 

 

Everyone's tags (4)