cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
804
Views
0
Helpful
5
Replies

Phase-2 Disconnecting

Imran Ahmad
Level 2
Level 2

Hello,

I have established VPN site-site between 2 ASAs Branch-to-HQ.  the issue is every morning time while both sites Turn-On their ASA devices, the Tunnel does not come up unless I run the following commands on HQ-ASA.

 

 

no crypto map tobranch interface outside

crypto map tobranch interface outside

 

Please instruct what is the issue ?

 

1 Accepted Solution

Accepted Solutions

the DPD's are getting lost on some device in the middle and that is what you need to check for

View solution in original post

5 Replies 5

pjain2
Cisco Employee
Cisco Employee

does any of the sides try and initiate traffic to the remote end?

when the issue occurs next, initiate traffic from behind one ASA and collect the below outputs from both the ends simultaneously:

debug crypto condition peer <peer ip>

debug crypto isakmp 127

debug crypto ipsec 127

 

Hello pjain,

Please find attached the debugging output

in the debugs, i see phase 1 getting completed but then getting deleted with the reason:

IKE lost contact with remote peer, deleting connection (keepalive type: DPD)

it means that the ASA did not receive DPD packets back from the remote peer.

can you check if your internet connection is stable while the ASA's try to bring up the tunnel by doing the ping between public ip's of both the ASA's during the time of the issue

there is no issue with internet connectivity, I can see 99.5% uptime.   there is onething else I want to mention.  my central office ASA has a private IP-Address (for its outside-interface),  so the ip (180.94.83.10) is the nated public ip-address of my Router connecting to internet. I have statically nated that ip (180.94.83.10) to my ASA Outside ip.     That is no causing the issue,, but I just wanted to let you know that I have this type of configuration.

 

Where the problem is, I am also stuck on it.     I contacted the ISP regarding the issue, they say there is no issue at our end.   but wat I m thinking is that the ISP at the remote sites are doing LINK-LOAD BALANCING , which I think that causes this vpn tunnel to get lost.   still not sure

 

 

 

the DPD's are getting lost on some device in the middle and that is what you need to check for