09-10-2019 10:16 PM - edited 09-10-2019 10:18 PM
Hello,
I have configured IKEv2 between 3945 and ASA. On 3945 end I have only 1 network, but on ASA end I have 3 networks. When the VPN connection is formed, I only see 1 subnet on each end, I cannot reach other two subnets from 3945 end. Yesterday after sometime, I was able to reach one of the other subnet, but again after sometime I can't? Any idea or suggestions?
When I do 'show crypto ipsec sa' on 3945, I see all three subnets, but on ASA only 1 subnet.
Thanks
09-11-2019 07:45 AM
One typical config-problem that can cause situations like these, is when the crypto ACLs on both ends do not mirror. Please check this first. And if you migrate to route based VPNs (virtual tunnel interfaces, VTIs), this config-problem can not happen.
09-11-2019 08:53 PM
Hi
Thank you for your response. ACL are exactly same on both end.
One thing I have obsevered that when I initiate the traffic from ASA end, the network tunnel comes up. But when I try to initiate the traffic from 3945, ASA doesn't bring the second IPSEC tunnel for the network. How can I make 3945 as traffic initiator?
Thanks
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide