08-16-2007 03:32 AM - edited 02-21-2020 03:13 PM
Hi all,
I am getting some problems with a Site to Site VPN from the last two weeks. In some occasions it stops to send traffic through the VPN without any apparent reason. I have other VPNs that continue working fine. While it is failing I have run the command "show crypto isakmp sa" and I have found that I have two entries for the peer that is failing:
9 IKE Peer: x.x.x.x
Type: L2L Role: responder
Rekey: no State: AM_REKEY_DONE_H2
10 IKE Peer: x.x.x.x
Type: L2L Role: initiator
Rekey: yes State: MM_ACTIVE_REKEY
Any idea about what is happening?
On the other hand at the moment the only way to solve this has been using the command "clear crypto isakmp sa" but the problem is that this command clear all the entries and I lose the connectivity in all the other tunnels until the are established again. Is there any way to clear only the tunnel that has problems?
Regards, Fernando.
08-22-2007 06:30 AM
ISAKMP key will stay active if you use this command
08-22-2007 07:15 AM
Hi Fernando,
Yes, you can use "clear crypto session remote x.x.x.x " to reset the tunnel.
This command allows you to clear both IKE and IPSec with a single command and you can specify remote peer IP address to clear only single tunnel.
HTH
MD
08-23-2007 12:07 AM
Hi MD,
I have tried to use the command that you said but that option doesn't appear in my ASA.
asa# clear crypto ?
accelerator Clear accelerator statistics
ca Certification authority
ipsec Clear IPsec operational data
isakmp Clear ISAKMP operational data
protocol Clear protocol statistics
asa(config)# clear crypto ?
exec mode commands/options:
accelerator Clear accelerator statistics
ca Certification authority
ipsec Clear IPsec operational data
isakmp Clear ISAKMP operational data
protocol Clear protocol statistics
Do you know any other possibility?
On the other hand, do you know why I am having this issue?
Regards, Fernando.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide