I know this is a bit general, but I could really use some ideas on what else to check.
We have had a site-to-site VPN up and running for several months. As of last Monday, the tunnel will no longer come up when traffic is initiated from my side of the tunnel. The tunnel will come up when initiated from the other side. But, my hosts are the initiators of the traffic so we need to be able to bring up the tunnel.
Nothing changed in my PIX 515 (v6.3.5). The other side is an ASA 5540 (v7.1) and there are changes made on that end frequently. I do not control or have access to that device.
It appears that when I initiate traffic, Phase 1 completes. Then, when I propose Phase 2 - there is no response from the other side.
My basic question is - what can cause that?
We both have TAC cases open and aren't getting anywhere. We have both rebooted a number of times. We have both completely ripped out all ACLs and Crypto Maps and Tunnel-Groups (on the ASA) and then reconfigured using different names/numbers. Nothing seems to help.
I know this is difficult without any configuration or debug info, but if anyone can provide a few things for us to look for I would appreciate it. There are no apparent errors or failures in the debugs on my side and he says the same about the other side. But, I can see Logging messages indicating that my device is tearing down the tunnel because there is not response from the other device.
I appreciate any advice or comments anyone may have!