05-07-2018 06:52 AM - edited 03-12-2019 05:15 AM
Community,
I am noticing a partner (50.x.y.30) is sending multiple Phase 1 Requests to our VPN router (64.w.z.111) but cannot figure out why. Any idea what would cause this or how to fix it? All of our other VPN peers only show 1 Phase 1 setup.
I believe they are using a Sophos UTM on their side, we are using a Cisco 2911 on our side.
IPv4 Crypto ISAKMP SA
dst src state conn-id status
50.x.y.30 64.w.z.111 MM_NO_STATE 0 ACTIVE
50.x.y.30 64.w.z.111 MM_NO_STATE 0 ACTIVE (deleted)
64.w.z.111 50.x.y.30 MM_NO_STATE 0 ACTIVE (deleted)
Thanks.
05-07-2018 07:32 AM
Hello @Craddockc,
The log you provided means they are trying to setup the VPN tunnel but they are unable to do it, you see 2 attempts is because the "refresh" for the Router is a little bit slow and that´s why you see 2 but htere is no worries since the second one is deleted and it takes a while to dissapear:
dst src state conn-id status
50.x.y.30 64.w.z.111 MM_NO_STATE 0 ACTIVE
50.x.y.30 64.w.z.111 MM_NO_STATE 0 ACTIVE (deleted) --> No longer negotiating
64.w.z.111 50.x.y.30 MM_NO_STATE 0 ACTIVE (deleted) --> No longer negotiating
HTH
Gio
05-07-2018 09:59 AM
Gio,
Thank you very much for your replies. The VPN tunnel is back up, however my router is still showing multiple Phase 1 connections to the peer as well as one that is continually trying but failing. Is this something on the partner end that could be causing this? Multiple profiles or similar? I would like just one active Phase 1 connection.
Thanks.
IPv4 Crypto ISAKMP SA
dst src state conn-id status
50.x.y.30 64.w.z.111 QM_IDLE 8014 ACTIVE
64.w.z.111 50.x.y.30 MM_NO_STATE 0 ACTIVE (deleted)
64.w.z.111 50.x.y.30 QM_IDLE 8013 ACTIVE
dst src state conn-id status
50.x.y.30 64.w.z.111 QM_IDLE 8014 ACTIVE
64.w.z.111 50.x.y.30 MM_SA_SETUP 0 ACTIVE
64.w.z.111 50.x.y.30 QM_IDLE 8013 ACTIVE
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide