cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
960
Views
0
Helpful
1
Replies

VPN mismatch in ACL

Michal Valach
Level 1
Level 1

Hello I have VPN tunel between cisco router and ASA. I have 5 ACL entries host to host and are exaclty same on both sides. VPN is working fine. After that I have added subnet on cisco router and customer added host to host on other side and we have mismatch. I have tested ( sendig traffic-standard MQ requests) and this caused whole VPN outage even those 5 entries were affected.

Is is standard behavior?  Can ACL mismatch caused whole VPN down? Or it shoul only affect IPs which are not matching?

1 Reply 1

sganpat
Level 1
Level 1

Yes, this is normal behaviour. This is a Phase 2 mismatch. The ACLs must be a mirror match at both sides to allow the IPSec SAs to be created.