11-05-2020 10:03 AM - edited 11-05-2020 10:05 AM
Hi,
I manage a firewall. It is:
FPR-2110
Cisco Adaptive Security Appliance Software Version 9.8(4)15
From this FW, we have 10 sites to sites vpn tunnels with our partners. All of them work well.
Recently we just set up two more tunnels with a new partner. His firewall is:
Hardware: ASA5525
ASA Version 9.2(2)4
Below is basically my setting on my fw for the two tunnels.
crypto map outside_map1 280 match address ACL_Kapsch_ORBEPP
crypto map outside_map1 280 set pfs group5
crypto map outside_map1 280 set peer 24.x.x.18
crypto map outside_map1 280 set ikev2 ipsec-proposal Kapsch-AES256-SHA256
crypto map outside_map1 280 set security-association lifetime seconds 28800
crypto map outside_map1 290 match address ACL_Kapsch_ORBEPP
crypto map outside_map1 290 set pfs group5
crypto map outside_map1 290 set peer 147.x.x.138
crypto map outside_map1 290 set ikev2 ipsec-proposal Kapsch-AES256-SHA256
crypto map outside_map1 290 set security-association lifetime seconds 28800
The issue is: These two new tunnels often go down every 2 or days. The only way to make it up is to reset the tunnels.
Could you advice how to troubleshoot and fix it?
If you need more information, please let me know.
I appreciate it if you can help.
Thanks
Loc
11-05-2020 10:09 AM - edited 11-05-2020 10:11 AM
What is other side config ? when the Tunnel tier down what kind of Logs you see both the sides.
Since you mentioned other Tunnel working as expected. i supect some configuration issue other side - but that can only confirmed once we able to view their side config and Logs.
here is some tips to start with Troubleshooting.
11-05-2020 01:03 PM
Thanks.
The other site has the similar configuration. That site also has several tunnels with other partners. it just has the issue with us only.
11-05-2020 04:10 PM
we need more Logs when the Tunnel break, collect the Logs on both the side and post here.
other side using the same ISP for all the Links working vs not working, you also have the same ISP for working vs not working?
11-09-2020 08:03 AM
Hi BB,
Both sides using the same ISP with the ones working.
There are a lot of logs. which one do you think it relates to the issue?
Thanks
Loc
11-09-2020 09:11 AM
still not sure - You need to provide some Logs so we can look and gudie in better
11-09-2020 02:56 PM
Loc, are both tunnels using same encryption domains?
11-11-2020 12:31 PM
Aref,
yes, we both use the same encryption domains
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide