ASA L2L VPN Error

Unanswered Question
Jun 11th, 2008
User Badges:
  • Bronze, 100 points or more

Hello all,


Trying to migrate our L2L VPN connections from our 3030 concentrator to our ASA 5520 running 8.0(3). It looks to be trying to establish our test tunnel. But we get the following error on the remote end: *Jun 11 16:13:15.740: No peer struct to get peer description


Any clues?


TIA,


Jim

  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Loading.
JORGE RODRIGUEZ Wed, 06/11/2008 - 19:15
User Badges:
  • Green, 3000 points or more

Jim,


I don't believe the asa or the other end applience will attempt to bring the tunnel up until one side sends interesting traffic, depending on how your tunnel is setup in terms who will be the initiator one side must generate traffic to bring up the tunnel. Have you tried sending pings or whichever tcp traffic you configured in your acls?


If you have sent interesting traffic and no joy I would suggest to troubleshoot fruther with debug crypto isakmp to determin where phase-1 fails.


As double check, make sure both ends coninside and perfectly match/agree on the isakmp policy settings, this is the most common stage where l2l fails at first.



Rgds

-Jorge

jphilope@cswg.com_2 Thu, 06/12/2008 - 03:56
User Badges:
  • Bronze, 100 points or more

Jorge,


Thanks. The error message was debug output. Not sure what it is. Never saw this kind of message before. The ISAKMP policy do indeed match as well as the transforms. This message appears only when traffic is initiated (telnet).


Jim

JORGE RODRIGUEZ Thu, 06/12/2008 - 05:52
User Badges:
  • Green, 3000 points or more

Hi Jim,


Are you generating the interesting traffic from a valid source, I mean from a source that you have permitted in the acl of this tunnel policy.


Can you post the complete output of debug crypto isakmp to see the flow.


After you get the complete output of above debug also post the output of show crypto isakmp sa.



Rgds

-Jorge

jphilope@cswg.com_2 Thu, 06/12/2008 - 08:44
User Badges:
  • Bronze, 100 points or more

Jorge,


Thanks. Ended up being the ACL. I finally did an IP any any and it came up. Then worked backwards to refine the ACL and now all is well. I had also missed a specific route as I assumed the default would take care of it.

JORGE RODRIGUEZ Thu, 06/12/2008 - 12:49
User Badges:
  • Green, 3000 points or more

Jim, thanks for updating the post and glad it all worked out.


Rgds

-Jorge

Actions

This Discussion