cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
704
Views
0
Helpful
7
Replies

VPN Site to Site tunnels drop connection every few days

Loc Nguyen
Level 1
Level 1

Hi,

I manage a firewall. It is:

FPR-2110
Cisco Adaptive Security Appliance Software Version 9.8(4)15

 

From this FW, we have 10 sites to sites vpn tunnels with our partners. All of them work well.

Recently we just set up two more tunnels with a new partner. His firewall is:

Hardware: ASA5525
ASA Version 9.2(2)4

 

Below is basically my setting on my fw for the two tunnels. 

crypto map outside_map1 280 match address ACL_Kapsch_ORBEPP
crypto map outside_map1 280 set pfs group5
crypto map outside_map1 280 set peer 24.x.x.18
crypto map outside_map1 280 set ikev2 ipsec-proposal Kapsch-AES256-SHA256
crypto map outside_map1 280 set security-association lifetime seconds 28800

 

crypto map outside_map1 290 match address ACL_Kapsch_ORBEPP
crypto map outside_map1 290 set pfs group5
crypto map outside_map1 290 set peer 147.x.x.138
crypto map outside_map1 290 set ikev2 ipsec-proposal Kapsch-AES256-SHA256
crypto map outside_map1 290 set security-association lifetime seconds 28800

 

The issue is: These two new tunnels often go down every 2 or days. The only way to make it up is to reset the tunnels.

Could you advice how to troubleshoot and fix it?

If you need more information, please let me know.

I appreciate it if you can help.

Thanks

Loc

7 Replies 7

balaji.bandi
Hall of Fame
Hall of Fame

What is other side config ?  when the Tunnel tier down what kind of Logs you see both the sides.

Since you mentioned other Tunnel working as expected. i supect some configuration issue other side - but that can only confirmed once we able to view their side config and Logs.

 

here is some tips to start with Troubleshooting.

 

https://www.cisco.com/c/en/us/support/docs/security/asa-5500-x-series-next-generation-firewalls/81824-common-ipsec-trouble.html

 

https://techmusa.com/ipsec-vpn-troubleshooting/

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

Thanks.

 

The other site has the similar configuration.  That site also has several tunnels with other partners. it just has the issue with us only.

balaji.bandi
Hall of Fame
Hall of Fame

we need more Logs when the Tunnel break, collect the Logs on both the side and post here.

 

other side using the same ISP for all the Links working vs not working, you also have the same ISP for working vs not working?

 

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

Hi BB,

Both sides using the same ISP with the ones working.

There are a lot of logs. which one do you think it relates to the issue?

Thanks

Loc

balaji.bandi
Hall of Fame
Hall of Fame

still not sure - You need to provide some Logs so we can look and gudie in better

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

Loc, are both tunnels using same encryption domains?

Aref,

yes, we both use the same encryption domains

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: