cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
372
Views
0
Helpful
4
Replies

Cisco ASA Ipsec Tunnel stops forwarding traffic

Thombie
Level 1
Level 1

Hi Guys I have strange issue  -  with ASA  VPN tunnels.

I have Datacentre  with  3 branch offices. All traffic is routed though the Datacentre.

At one of the branch office the  IPCsec tunnel stops forwarding traffic even though the tunnel stays up.

As anyboy seen this before ?

 

4 Replies 4

share the 
show crypto isakmp sa
show crypto ipsec sa 
in datacenter and branchs

what do you think ?

Thombie
Level 1
Level 1

Banch ```

There are no IKEv1 SAs

IKEv2 SAs:

Session-id:14835, Status:UP-ACTIVE, IKE count:1, CHILD count:1

Tunnel-id Local Remote Status Role
1588121151 192.168.0.2/500 x.x.x81/500 READY RESPONDER
Encr: AES-CBC, keysize: 256, Hash: SHA96, DH Grp:5, Auth sign: PSK, Auth verify: PSK
Life/Active Time: 86400/1606 sec
Child sa: local selector 10.132.42.0/0 - 10.132.42.255/65535
remote selector 0.0.0.0/0 - 255.255.255.255/65535
ESP spi in/out: 0x8d70b1a7/0x1bc517ec
t


tvrs-ac-fw1# show crypto ipsec sa
interface: outside
Crypto map tag: outside_map, seq num: 1, local addr: 192.168.0.2

access-list outside_cryptomap extended permit ip 10.132.42.0 255.255.255.0 any
local ident (addr/mask/prot/port): (10.132.42.0/255.255.255.0/0/0)
remote ident (addr/mask/prot/port): (0.0.0.0/0.0.0.0/0/0)
current_peer: x.x.x.81


#pkts encaps: 1359227, #pkts encrypt: 1359226, #pkts digest: 1359226
#pkts decaps: 728111, #pkts decrypt: 728111, #pkts verify: 728111
#pkts compressed: 0, #pkts decompressed: 0
#pkts not compressed: 1359230, #pkts comp failed: 0, #pkts decomp failed: 0
#pre-frag successes: 0, #pre-frag failures: 0, #fragments created: 0
#PMTUs sent: 0, #PMTUs rcvd: 0, #decapsulated frgs needing reassembly: 0
#TFC rcvd: 0, #TFC sent: 0
#Valid ICMP Errors rcvd: 0, #Invalid ICMP Errors rcvd: 0
#send errors: 0, #recv errors: 0

local crypto endpt.: 192.168.0.2/500, remote crypto endpt.: x.x.x.81/500
path mtu 1500, ipsec overhead 58(36), media mtu 1500
PMTU time remaining (sec): 0, DF policy: copy-df
ICMP error validation: disabled, TFC packets: disabled
current outbound spi: 1BC517EC
current inbound spi : 8D70B1A7

inbound esp sas:
spi: 0x8D70B1A7 (2372972967)
SA State: active
transform: esp-des esp-sha-hmac no compression
in use settings ={L2L, Tunnel, IKEv2, }
slot: 0, conn_id: 60764160, crypto-map: outside_map
sa timing: remaining key lifetime (kB/sec): (4163705/27098)
IV size: 8 bytes
replay detection support: Y
Anti replay bitmap:
0xFFFFFFFF 0xFFFFFFFF
outbound esp sas:
spi: 0x1BC517EC (465901548)
SA State: active
transform: esp-des esp-sha-hmac no compression
in use settings ={L2L, Tunnel, IKEv2, }
slot: 0, conn_id: 60764160, crypto-map: outside_map
sa timing: remaining key lifetime (kB/sec): (2248524/27098)
IV size: 8 bytes
replay detection support: Y
Anti replay bitmap:
0x00000000 0x00000001```

 

Thombie
Level 1
Level 1

No dynamic L2L VPN