cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1215
Views
5
Helpful
26
Replies

Cisco ASA VPN

iburlacu
Level 1
Level 1

I have a vpn connection between two cisco asa 5512 that failed. I restored an older backup with ASDM but the vpn is still down. What can I do to restore the vpn? Thank you.

26 Replies 26

can you more elaborate 

iburlacu
Level 1
Level 1

The VPN was L2L, had crypto map configured with "ip" traffic selection and was functional. I added icmp to the traffic selection and the vpn failed. On such a cisco I did a restore to a backup from 26.07.2023 when the vpn was functional, but even with this configuration I did not manage to make the vpn functional. What I did wrong?

friend are you use SLA monitor in ASA for ISP ?

iburlacu
Level 1
Level 1

no

Is s2s vpn is ikev2 ? If yes make peer clear crypto isakmp and clear crypto sa

iburlacu
Level 1
Level 1

No, its ikev1.

Did you try initiate traffic to make tunnel up?

iburlacu
Level 1
Level 1

I try initiate traffic with packet tracer.

Capture.PNG

Do packet tracer twice to work.

Also for rsa what is auth of vpn you use psk or rsa 

iburlacu
Level 1
Level 1

I talked to someone and he told me to access the show crypto key mypubkey rsa command and copy the key data, but I didn't understand where.

iburlacu
Level 1
Level 1

I used psk.

Ok' 

1- add psk again' sometime between backup and restore the config the pks is corrupt 

2- do packet-tracer twice to make tunnel up or connect pc and initiate real traffic 

iburlacu
Level 1
Level 1

I verify psk with: more system: running-config | in key and is correct. I use packet-tracer twice and the same result: MM_WAIT_MSG2. 

Can you access to both asa ?

If yes access and clear crypto sa and clear crypto isakmp