12-01-2023 03:15 PM
Hello everyone,
Long time reader, first time requester. As the title states I am having issues getting a S2S IKEv1 tunnel to establish between my ASA 5516-x and our AWS VPC. I followed a guide to do this, and downloaded the config straight from AWS that said to copy and paste into the firewall and the tunnel should come up. If only my life was ever that easy. Anyone have experience doing this? If I run
clear crypto ikev1 *peer ip*
I can see the IKEv1 tunnel in a Wait_MM_MSG2 status for about 15 seconds before I start seeing that there are no IKEv1 tunnels. Please advise. Thank you!
12-01-2023 03:26 PM
Can I see config of asa?
12-01-2023 04:45 PM
12-01-2023 04:47 PM
12-01-2023 04:59 PM
Your config have many s2s vpn
Can you try packet-tracer for ipsec and share result here
Note:- do packet-tracer twice to get results it can first one show drop
Note:- add detail keyword to end of packet tracer command
MHM
12-01-2023 05:02 PM
What is the command for packet-tracer ipsec?
I usually do packet-tracer input *outside interface name* 8 0 34.215.53.147(aws interface ip)
12-01-2023 05:23 PM
That it and add detail keyword to end
Share result here
MHM
12-01-2023 05:50 PM
12-02-2023 01:39 AM
There is something wrong in packet tracer command it show packet loop
Can I see command you use
MHM
12-03-2023 08:04 PM
I used
packet-tracer input *outside interface name* icmp *internal IP that should go through vpn* 8 0 *amazon IP* detailed
12-03-2023 08:10 PM
packet-tracer input *inside interface name* icmp *internal IP that should go through vpn* 8 0 *amazon IP* detailed
The source interface is INSIDE not OUTSIDE
MHM
12-04-2023 11:38 AM
12-04-2023 11:42 AM
Did you run it twice'
Make sure do packet tracer again and check if it drop in same phase or not.
MHM
12-04-2023 11:44 AM
Yes I ran twice and both failed in the same spot.
12-04-2023 12:02 PM
Show crypto isakmp sa
Only show me the tunnel end not work.
MHM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide