03-02-2023 11:03 AM
I've been having an issue in FTD 7.0.5 on FMC. My site to site tunnels lose connectivity to certain VLANS in my main site.
it's not always the same VLAN or the same device. it's not ALL vlans, just 1 out of 5. it's random.
My question is, on the old ASDM, you could restart a tunnel by logging it out from one side or the other.
I can't find that functionality in FMC, so I'm forced to reboot the remote device.
is there a way to logout a Site to Site tunnel in FMC?
Solved! Go to Solution.
03-02-2023 11:11 AM
@Lee Dress from the CLI of the FTD you can run clear crypto ipsec sa peer <ip address> which will delete the IPSec SA for that peer. You'd then need to generating interesting traffic in order for the VPN tunnel to be re-established.
03-02-2023 11:11 AM
@Lee Dress from the CLI of the FTD you can run clear crypto ipsec sa peer <ip address> which will delete the IPSec SA for that peer. You'd then need to generating interesting traffic in order for the VPN tunnel to be re-established.
03-02-2023 11:17 AM
clear crypto ipsec - command refer below :
03-02-2023 11:22 AM
Thanks to both of you. I appreciate the quick response!
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide