cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
Announcements
298
Views
0
Helpful
7
Replies
Highlighted
Beginner

VPN Site to Site tunnels drop connection every few days

Hi,

I manage a firewall. It is:

FPR-2110
Cisco Adaptive Security Appliance Software Version 9.8(4)15

 

From this FW, we have 10 sites to sites vpn tunnels with our partners. All of them work well.

Recently we just set up two more tunnels with a new partner. His firewall is:

Hardware: ASA5525
ASA Version 9.2(2)4

 

Below is basically my setting on my fw for the two tunnels. 

crypto map outside_map1 280 match address ACL_Kapsch_ORBEPP
crypto map outside_map1 280 set pfs group5
crypto map outside_map1 280 set peer 24.x.x.18
crypto map outside_map1 280 set ikev2 ipsec-proposal Kapsch-AES256-SHA256
crypto map outside_map1 280 set security-association lifetime seconds 28800

 

crypto map outside_map1 290 match address ACL_Kapsch_ORBEPP
crypto map outside_map1 290 set pfs group5
crypto map outside_map1 290 set peer 147.x.x.138
crypto map outside_map1 290 set ikev2 ipsec-proposal Kapsch-AES256-SHA256
crypto map outside_map1 290 set security-association lifetime seconds 28800

 

The issue is: These two new tunnels often go down every 2 or days. The only way to make it up is to reset the tunnels.

Could you advice how to troubleshoot and fix it?

If you need more information, please let me know.

I appreciate it if you can help.

Thanks

Loc

7 REPLIES 7
Highlighted
VIP Expert

What is other side config ?  when the Tunnel tier down what kind of Logs you see both the sides.

Since you mentioned other Tunnel working as expected. i supect some configuration issue other side - but that can only confirmed once we able to view their side config and Logs.

 

here is some tips to start with Troubleshooting.

 

https://www.cisco.com/c/en/us/support/docs/security/asa-5500-x-series-next-generation-firewalls/81824-common-ipsec-trouble.html

 

https://techmusa.com/ipsec-vpn-troubleshooting/



BB


*** Rate All Helpful Responses ***

Highlighted

Thanks.

 

The other site has the similar configuration.  That site also has several tunnels with other partners. it just has the issue with us only.

Highlighted
VIP Expert

we need more Logs when the Tunnel break, collect the Logs on both the side and post here.

 

other side using the same ISP for all the Links working vs not working, you also have the same ISP for working vs not working?

 



BB


*** Rate All Helpful Responses ***

Highlighted

Hi BB,

Both sides using the same ISP with the ones working.

There are a lot of logs. which one do you think it relates to the issue?

Thanks

Loc

Highlighted
VIP Expert

still not sure - You need to provide some Logs so we can look and gudie in better



BB


*** Rate All Helpful Responses ***

Highlighted
VIP Rising star

Loc, are both tunnels using same encryption domains?

Highlighted

Aref,

yes, we both use the same encryption domains

Content for Community-Ad