01-17-2023 09:38 AM
Hi Guys I have strange issue - with ASA VPN tunnels.
I have Datacentre with 3 branch offices. All traffic is routed though the Datacentre.
At one of the branch office the IPCsec tunnel stops forwarding traffic even though the tunnel stays up.
As anyboy seen this before ?
01-17-2023 09:51 AM
share the
show crypto isakmp sa
show crypto ipsec sa
in datacenter and branchs
01-19-2023 06:20 AM
what do you think ?
01-17-2023 10:42 AM - edited 01-17-2023 10:58 AM
Banch ```
There are no IKEv1 SAs
IKEv2 SAs:
Session-id:14835, Status:UP-ACTIVE, IKE count:1, CHILD count:1
Tunnel-id Local Remote Status Role
1588121151 192.168.0.2/500 x.x.x81/500 READY RESPONDER
Encr: AES-CBC, keysize: 256, Hash: SHA96, DH Grp:5, Auth sign: PSK, Auth verify: PSK
Life/Active Time: 86400/1606 sec
Child sa: local selector 10.132.42.0/0 - 10.132.42.255/65535
remote selector 0.0.0.0/0 - 255.255.255.255/65535
ESP spi in/out: 0x8d70b1a7/0x1bc517ec
t
tvrs-ac-fw1# show crypto ipsec sa
interface: outside
Crypto map tag: outside_map, seq num: 1, local addr: 192.168.0.2
access-list outside_cryptomap extended permit ip 10.132.42.0 255.255.255.0 any
local ident (addr/mask/prot/port): (10.132.42.0/255.255.255.0/0/0)
remote ident (addr/mask/prot/port): (0.0.0.0/0.0.0.0/0/0)
current_peer: x.x.x.81
#pkts encaps: 1359227, #pkts encrypt: 1359226, #pkts digest: 1359226
#pkts decaps: 728111, #pkts decrypt: 728111, #pkts verify: 728111
#pkts compressed: 0, #pkts decompressed: 0
#pkts not compressed: 1359230, #pkts comp failed: 0, #pkts decomp failed: 0
#pre-frag successes: 0, #pre-frag failures: 0, #fragments created: 0
#PMTUs sent: 0, #PMTUs rcvd: 0, #decapsulated frgs needing reassembly: 0
#TFC rcvd: 0, #TFC sent: 0
#Valid ICMP Errors rcvd: 0, #Invalid ICMP Errors rcvd: 0
#send errors: 0, #recv errors: 0
local crypto endpt.: 192.168.0.2/500, remote crypto endpt.: x.x.x.81/500
path mtu 1500, ipsec overhead 58(36), media mtu 1500
PMTU time remaining (sec): 0, DF policy: copy-df
ICMP error validation: disabled, TFC packets: disabled
current outbound spi: 1BC517EC
current inbound spi : 8D70B1A7
inbound esp sas:
spi: 0x8D70B1A7 (2372972967)
SA State: active
transform: esp-des esp-sha-hmac no compression
in use settings ={L2L, Tunnel, IKEv2, }
slot: 0, conn_id: 60764160, crypto-map: outside_map
sa timing: remaining key lifetime (kB/sec): (4163705/27098)
IV size: 8 bytes
replay detection support: Y
Anti replay bitmap:
0xFFFFFFFF 0xFFFFFFFF
outbound esp sas:
spi: 0x1BC517EC (465901548)
SA State: active
transform: esp-des esp-sha-hmac no compression
in use settings ={L2L, Tunnel, IKEv2, }
slot: 0, conn_id: 60764160, crypto-map: outside_map
sa timing: remaining key lifetime (kB/sec): (2248524/27098)
IV size: 8 bytes
replay detection support: Y
Anti replay bitmap:
0x00000000 0x00000001```
01-17-2023 11:15 AM
No dynamic L2L VPN
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide