Skip to main content
sunny821
New Member
October 20, 2014
Question

5.2 IPsec VPN tunnel with cisco asa 5525

  • October 20, 2014
  • 4 replies
  • 15295 views
i' ve to setup IPsec vpn tunnel with fortiwifi 60d with cisco asa 5525 (asa version 8.6) via the " site to site wizard cisco" I receive " IPsec DPD failure" message in event log, I tried to ping in either direction & no reply. lastly, I couldn' t find any valid IPsec vpn documentation between fortigate & cisco asa in fortinet page

    4 replies

    mjcrevier
    New Member
    November 16, 2014

    You must create a separate phase-2 selector on the fortigate for every subnet you have defined in the Cisco's VPN configuration.

    For example:

    Lets say you have 1 subnet behind the Fortigate.

    You need to reach 5 subnets behind the ASA though the VPN.

    You probably created an network object-group in the Cisco ASDM and listed the 5 subnets under 1 object-group.

    This configuration requires 5 separate phase-2 selectors on the fortigate.

     

    If you have 2 subnets behind the fortigate and 5 behind the Cisco, you need to create 10 phase-2 selectors. This is assuming you aren't able to summarize the local and remote networks.

    emnoc
    New Member
    November 16, 2014

    Without the asa cfg review you are limited in your diagnostics. You have a host of issues that could cause problems.

    Please search here in this forum for  ASA-2-FGT vpn cfgs.

    Or at http://socpuppet.blogspot.com/2014/05/site-2-site-vpn-fortinet-fortigate-to.html

     

    For trouble-shooting you will need to execute a few items. Here's some basic from the fortigate side of things;

     

    http://socpuppet.blogspot.com/2013/10/site-2-site-routed-vpn-trouble-shooting.html

     

     

    Rewanta_FTNT
    Staff
    Staff
    November 20, 2014

    Hi,

     

    " IPsec DPD failure" would cause the ipsec tunnel flap. dpd messages are exchanged to check the liveliness of the ipsec peer/tunnel. if these dpd packets are missed for 3 times each sending every 5 seconds, tunnel will be torn down. first it would be worth to check if the asa receives the dpd packets when FGT sends it or these packets are dropped in the transit path. 

    You can check the dpd packets using the ike debug in FGT. 

     

    diag debug reset

    diag vpn ike log-filter dst-addr4 <peer_ip>

    diag debug app ike -1

    diag debug enable

     

    to turn off the debug

    diag debug reset

    diag debug disable

     

    if the tunnel are flapped due to dpd loss of packets, you may try disabling the dpd. You can disable dpd from FGT from Phase1 settings in GUI. and disable from asa side also. 

     

    Rewanta

     

     

     

     

    sijo_km
    New Member
    August 7, 2015

    Hi

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!