11-12-2023 03:01 PM
Hi
Running ASA 9.8.2, on ASA 5506.
Created S2S VPN to Cisco 1010.
Getting this error when trying to communicate.
Same 1010 is connected to another 2x ASA 5506, all works well.
Compared 1000 time the configs between the working one and the faulty one.
I have found online its a bug, but there is no solution. (Did reload also)
Any ideas?
Thanks
11-13-2023 12:52 AM
>..I have found online its a bug, but there is no solution.
Then you need to contact Cisco (TAC)
M.
11-13-2023 01:08 AM
share the config here I need to check both
Thanks A Lot
MHM
11-13-2023 01:17 AM
Hi @MHM Cisco World ,
What is the quickest and easiest way to pull the config and share it safely?
I every time stuck with that, and not sure if I am removing the right lines. About time ill ask that.
Thanks
11-13-2023 01:22 AM
share it as text after replace any public IP with random one like 1.1.1.1
Thanks A Lot
MHM
11-13-2023 01:41 AM - edited 11-13-2023 11:34 AM
@MHM Cisco World Hope its right
Thank you!
@Aref Alsouqi I have tried this one, but still got the same error
11-13-2023 02:08 AM
remove the pfs 19 from the FW.
it seem the gourp is mismatch
Thanks A Lot
MHM
11-13-2023 02:16 AM
@MHM Cisco World Its was on group 2, which i am not sure why was created.
I have deleted it, and also changed the pfs group 5 (which was a try from the link Aref shared)
still in the same error
11-13-2023 02:19 AM
dont use any pfs
and after do any change
clear crypto sa
clear isakamp sa
11-13-2023 10:28 AM
Still the same.
Any more ideas in your pocket?
11-13-2023 01:31 AM
Not sure if this applies to your case, but someone else suggests that the issue could potentially be the missing configs of PFS:
11-13-2023 11:34 AM
Got it!
My bad - I have set the local IP of my 1010 (Main FW) as part of the objects, which I guess cause the block.
removed it, and its working.
Thank you all!
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide