09-30-2015 09:50 AM
I have a wierd situation. i have a site to site tunnel; site A and site B. site A does not ping site B but if i ping from site B, I will get a reply from A. Only then will site A start sending traffic. Is there such a thing like master and slave setup in VPN where one end has to be the initiator of traffic. how do i fix it so that both ends can ping each other
09-30-2015 09:50 PM
Hi Michael ,
This problem is seen if the ACL specified on the crypto map does not match exactly with the peer , make sure the interesting traffic is mirrored properly on both devices. Other possibility is that a stateful firewall is on the middle of the connection and is blocking the traffic from A to B , but allowing B to A traffic.
Hope it helps
-Randy-
09-30-2015 09:51 PM
1. are you initiating traffic from one of the host behind site A or from the ASA A itself?
2. when you initiate traffic first from Site A, do you see the traffic getting encrypted in the ipsec sa output?
2. do you see corresponding decaps on the Site B ASA?
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide