ā03-05-2024 05:19 AM
hi, we tried to config a site-to-site vpn to AWS on cisco asa (ver 9.1.x). After configuring on asa based on the configuration file downloaded from AWS, the vpn tunnel is not up, there is nothing (no sa) when running the command "sh crypto isakmp sa" or "sh crypto ikev1 sa", Then try to run debug "debug crypto ikev1 " , "debug crypto ikev1 32", there is no output. Can you anyone pls advise? thanks in advance!
ā03-05-2024 05:26 AM - edited ā03-05-2024 05:26 AM
@Herman2018 hi, few things to check.
1. are you using asdm or cli to configure?
2. is your config have crypto enable command for outside interface?
3. do you have configured routing towards internet? default route?
check if your config match with below configurations,
ā03-05-2024 05:42 AM
Asa use
Debug crypto isakmp 127
Debug crypto ipsec 127
For S2S vpn
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide