cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
650
Views
0
Helpful
3
Replies

ASA site to site VPN

miras
Level 5
Level 5

Site-to-site VPN won't come up.

I see the message below in the logs.

%ASA-6-110002: Failed to locate egress interface for "protocol" from inside:"IP" to "IP"
 

3 Replies 3

niemmanu
Cisco Employee
Cisco Employee

Hi,

 

please share outputs of debug cry isa 128 or debug cry ikev1 128.

 

Please use this command before using the debugs

debug cry condition peer <IP>

 

Also share the configuration of both ends.

Figured out the problem.

There was a router performing NATing that prevented the phase 1 to come up. I did trace it, i just checked the configuration of the router.

What is the process to trace these type of problems?

How are the packets encapsulated/decapsulated?

Hi,

Did you check the ASA routing table? it seems like the ASA does not know which exit interface it would use to reach that destination.

Regards,

Aref