Hi,
I manage a firewall. It is:
FPR-2110
Cisco Adaptive Security Appliance Software Version 9.8(4)15
From this FW, we have 10 sites to sites vpn tunnels with our partners. All of them work well.
Recently we just set up two more tunnels with a new partner. His firewall is:
Hardware: ASA5525
ASA Version 9.2(2)4
Below is basically my setting on my fw for the two tunnels.
crypto map outside_map1 280 match address ACL_Kapsch_ORBEPP
crypto map outside_map1 280 set pfs group5
crypto map outside_map1 280 set peer 24.x.x.18
crypto map outside_map1 280 set ikev2 ipsec-proposal Kapsch-AES256-SHA256
crypto map outside_map1 280 set security-association lifetime seconds 28800
crypto map outside_map1 290 match address ACL_Kapsch_ORBEPP
crypto map outside_map1 290 set pfs group5
crypto map outside_map1 290 set peer 147.x.x.138
crypto map outside_map1 290 set ikev2 ipsec-proposal Kapsch-AES256-SHA256
crypto map outside_map1 290 set security-association lifetime seconds 28800
The issue is: These two new tunnels often go down every 2 or days. The only way to make it up is to reset the tunnels.
Could you advice how to troubleshoot and fix it?
If you need more information, please let me know.
I appreciate it if you can help.
Thanks
Loc
What is other side config ? when the Tunnel tier down what kind of Logs you see both the sides.
Since you mentioned other Tunnel working as expected. i supect some configuration issue other side - but that can only confirmed once we able to view their side config and Logs.
here is some tips to start with Troubleshooting.
Thanks.
The other site has the similar configuration. That site also has several tunnels with other partners. it just has the issue with us only.
we need more Logs when the Tunnel break, collect the Logs on both the side and post here.
other side using the same ISP for all the Links working vs not working, you also have the same ISP for working vs not working?
Hi BB,
Both sides using the same ISP with the ones working.
There are a lot of logs. which one do you think it relates to the issue?
Thanks
Loc
still not sure - You need to provide some Logs so we can look and gudie in better
Loc, are both tunnels using same encryption domains?
Aref,
yes, we both use the same encryption domains