cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
3677
Views
2
Helpful
6
Replies

Cisco ASA VPN site to site: Failed to authenticate the IKE SA

FrejusMA
Level 1
Level 1

Hello Community,

Just set up the site to site VPN between my ASA fw and a remote site using SOPHOS fw via public IP Internet. The VPN is not coming up with error message below:

Local:X.X.X.X:4500 Remote:name:39929 Username:X.X.X.X IKEv2 Negotiation aborted due to ERROR: Failed to authenticate the IKE SA

I suspect this is at phase 1. Can anyone has this before? Please assist.

 

Thank you

1 Accepted Solution

Accepted Solutions

BlakeBratu
Cisco Employee
Cisco Employee

If you're using the right keyring on both ends, can you double-check that your PSK's are matching within your keyring? Additionally, I have seen this error before when one of the peer ID's are mismatched.

View solution in original post

6 Replies 6

Are you use right keyring ?

Thanks for your response.

The remote side confirm to me that he is using the right keyring. So yes.

can you share the config ?

BlakeBratu
Cisco Employee
Cisco Employee

If you're using the right keyring on both ends, can you double-check that your PSK's are matching within your keyring? Additionally, I have seen this error before when one of the peer ID's are mismatched.

Hello Team 

Ramadan Moubarack

@MHM Cisco World  thanks for being available, My problem is solved now. We check the keys on both side and they were no mismatch. The problem as @BlakeBratu mentionned was on the peer ID's. The remote side were using a Sophos Firewall and they need to declare precisely the peer ID. When he puts the right peer ID the VPN comes up immediately. I went deeper to understand and I found out this peer ID was actually the real IP of my IPSEC peer which is weird. I thought the peer ID should be the same as my public IP. My question now is what is the meaning of this peer ID.

Thanks you @BlakeBratu in advance for your response 

Cheers guys.

You are so so welcome 
please select @BlakeBratu comment as solution. 
thanks 
have a nice day