01-25-2024 09:52 AM
Hello everyone, I have an ipsec/ikev2 Lan-to-Lan VPN working between an ASA and router A (Cisco), with this router behind a public router that is performing NAT, However, it keeps giving the following errors in the ASA side (i do not have information off router A, it is a client side):
30 in 30 seconds:
Local:203.0.113.45:4500 Remote:185.60.218.35:4500 Username:185.60.218.35 IKEv2 Negotiation aborted due to ERROR: There was no IPSEC policy found for received TS
Local:203.0.113.45:4500 Remote:185.60.218.35:4500 Username:185.60.218.35 IKEv2 Tunnel rejected: Crypto Map Policy not found for remote traffic selector 192.168.200.0/192.168.200.255/0/65535/0 local traffic selector 10.230.184.0/10.230.184.255/0/65535/0!
55 in 55 minutes:
IPSEC _ An inbound LAN-to-lAN SA (SPI - 0x12CPCSEO) between 185.60.218.35 and 203.0.113.45 (user- 185.60.218.35) has been deleted.
PSEC - An outbourd LAN-to-LAN SA (SPI- 0x69660748) between 203.0.113.45 and 185.60.218.35 (user- 185.60.218.35) has beer deleted
IPSEC - An inbound LAN-to-LAN SA (SPI- OKFBAE7961) between 203.0.113.45 and 185.60.218.35 (user_ 185.60.218.35) has been created
IPSEC - An outbound laN-to-LAN SA (SPI" 0¥72053486) between 203.0.113.45 and 185.60.218.35 (user- 185.60.218.35) has been created
PS: the router A have a SLA to keep the tunnel up ...
Despite no complaints from the client, the tunnel isn't functioning normally as can be seen in the logs. Any ideas?
Best regards
Fernando
Solved! Go to Solution.
01-25-2024 03:55 PM
IKEv2 Tunnel rejected: Crypto Map Policy not found for remote traffic selector 192.168.200.0/192.168.200.255/0/65535/0 local traffic selector 10.230.184.0/10.230.184.255/0/65535/0!
as per this logs - looks for me subnet miss match both ends, make sure both the side agree same subnet mask. depends what group you using.
can you post relevant configuration or run the debug on ASA. show crypto ikev2 sa also help as asked before.
01-26-2024 12:05 PM
Hi BB,
Relevant conf:
01-27-2024 11:47 AM
I dont think postponing the discussion until next week is a solution to this discussion. Please select a proper solution so that people searching for similar issues can find exactly what solved this for you.
01-27-2024 02:34 PM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide