07-24-2005 02:12 AM - edited 02-21-2020 01:52 PM
I have problems with ipsec tunnels on pix 525 7.0. For some time everything is ok and then tunnels a messed up. when I go to monitor and then VPN and then look list of lan to lan tunnels, I can see that rx bytes is incrementing as remote location is sending data but tx is zero. Only firewall restart helps. Any ideas? I'v tried everything, changeing from dynamic map to static, I've tried with upgrades, now I am on 7.0(2). Here is the part of config, I am using 3600 sec timeouts on peer side
07-24-2005 06:00 AM
mybe I have a clue. On int where I receive VPN connections, ther is an access-list. I've permitted all traffic from ipsec peers. In case of problems, there is a message that UDP 500 from peer ip to pix int ip UDP 500 is denied. After restart and tunnels reestablishment, there is no such message. Looks like PIX access-list stops working!!!!
07-25-2005 03:10 AM
it happened again, look at this
Built inbound UDP connection 14580 for intf2_vip:x.x.250.13/500 (x.x.250.13/500) to inside:x.x.254.5/500 (x.x.254.5/500)
UDP access denied by ACL from x.x.250.13/500 to inside:x.x.254.5/500
firs message seems ok, but then it starts. Is it possible that I hit some kind og limit of UDP connections?
07-26-2005 07:40 AM
another thing I've noticed in logs is
%PIX-3-313001: Denied ICMP type=11, code=0 from x.x.x.6 on interface
inside
x.x.x.6 is router through wich ipsec peers are connected to fw
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide