Skip to main content
pan_da
New Member
March 29, 2022
Question

Site-Site VPN issue

  • March 29, 2022
  • 2 replies
  • 3204 views

HI,
I have created a SS VPN with Cisco ASA. 
Unless the remote site (ASA) initiates the ping, the VPN tunnel remains down. As soon as the ping is initiated from asa, everything works.
Can anyone help me with this? 

2 replies

akristof
Staff
Staff
March 29, 2022

Hello,

 

Thank you for your question. So if you manually bring phase2 up or traffic is initiated from client behind the FortiGate, tunnel is down? Can you verify if phase1 is up but phase2 not? Are you using address group in selectors in phase2? Can you share:

diag vpn ike gateway list name <tunnel_name>

diag vpn tunnel list name <tunnel_name>

pan_da
pan_daAuthor
New Member
March 30, 2022

pan_da_2-1648629990585.pngpan_da_3-1648630002745.pngpan_da_4-1648630016540.png

 

pan_da
pan_daAuthor
New Member
March 30, 2022

pan_da_0-1648632224798.png

when the tunnel is down

vponmuniraj
Staff
Staff
March 30, 2022

Hi,

 

You can perform a debug to understand where the VPN fails during negotiation. 

 

diag deb reset

diag vpn ike log-filter clear

diag vpn ike log-filter dst-addr4 <peer IP>

diag deb appl ike -1

diag deb en

 

Regards,

pan_da
pan_daAuthor
New Member
March 31, 2022

pan_da_0-1648701273366.png

 

22.png33.png44.png