08-18-2013 09:08 AM
I am using asa5505(8.2) SiteA iskamp site to site VPN to SiteB asa5515x(8.6) ikev1. The tunnel will up and running only if initial ping from SiteA
I don't know why tunnel cannot up and running if I try to initial ping from siteB. Is there any setup I miss that I can make both site initial ping to bring up tunnel?
Both site A 5505 and B 5515x are using static IP for peer.
Sent from Cisco Technical Support iPhone App
Solved! Go to Solution.
08-18-2013 11:29 PM
There are a couple of parameters in the IPSec-config that can cause this behaviour if they don't match on both sides. Start with checking that the entries in your Crypto-ACL are really mirrored. That's what I have seen most often with this problem. Check also if you have configured "initiate-only" or "respond-only" on your ASAs which could also cause this problem.
Sent from Cisco Technical Support iPad App
08-18-2013 11:29 PM
There are a couple of parameters in the IPSec-config that can cause this behaviour if they don't match on both sides. Start with checking that the entries in your Crypto-ACL are really mirrored. That's what I have seen most often with this problem. Check also if you have configured "initiate-only" or "respond-only" on your ASAs which could also cause this problem.
Sent from Cisco Technical Support iPad App
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: