11-29-2023 03:00 PM
Hello guys,
I have a question about the vpn, why only works 1 of 2 tunnels configured in 1 vpn? I try to get up the tunnel A and works, but when I try to get up the tunnel B, it doesn't work, then I reset the vpn, but now I try to get up the tunnel B first and it works, however the tunnel A not working, I mean only 1 tunnel works at the same time, from 1 side is a Cisco ASA and the other is Juniper
No problem with the VPN, only for the second tunnel
I attach the config for both ends
Solved! Go to Solution.
12-01-2023 08:45 AM
I solved it, the issue was a mismatch on the DH group within the PFS.
Thank you all for your help.
12-01-2023 01:55 AM
Run debugs to verify why second IPsec SA fails to establish:
debug menu ikev2 3 1 //it will enable timestamps in the debugs
debug crypto condition peer X.X.X.X
debug crypto ike-common 127
debug crypto ikev2 platform 255
debug crypto ikev2 protocol 255
debug crypto ipsec 255
//initiate traffic and wait some time so the tunnel will try to reestablish
undebug all
12-01-2023 01:59 AM
I see only config of one vpn.
MHM
12-01-2023 08:45 AM
I solved it, the issue was a mismatch on the DH group within the PFS.
Thank you all for your help.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide