cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1451
Views
5
Helpful
2
Replies

Site to Site VPN from ASA 5505 to Ubiquiti USG

rcraig1142
Level 1
Level 1

I've been trying for days to get a site to site vpn between a Cisco ASA and a Ubiquiti USG. I can get as far as phase 1, but thats it. Whatever settings I try to get phase 2 to work, it breaks phase 1 and I start all over. Has anyone ever successfully gotten a tunnel between these two devices to work? 

 

Robert

2 Replies 2

Udupi Krishna.
Cisco Employee
Cisco Employee

I have had my fair share of building site to site vpn between ASA and Pfsense. But never really had much trouble.

If the settings are correct for phase 2, its worth trying debug on ASA for phase 1 and 2.

the PhaseII start with ID and Pre-shared Key
ID can be change due of NAT between both Peer
Pre-Shared Key if you don't specify the right Peer then IPSec select first longest match and hence the IPSec PhaseII stop there.

this two factor I think which make issue here.