If I have a L2L VPN tunnel configured and it is not coming up,
What is the sequence of the tunnel coming up?
For example, at what point should I see the access-lists for interesting traffic getting hits in the process?
If the tunnel does not succesfully come up, should I expect to see no hits on the access-list even though the routing is ok?
My understanding is that the interesting traffic access-list are part of phase 2, but it seems that these access-lists would have to be the first thing in the process to initiate phase 1.
Doesn't there have to be traffic destined for the remote tunnel LAN in order for phase 1 to start?
Also,I have seen several posts indicating to check the sa liftimes on both ends, my understanding is that these do not have to match, that the end with the shortest time will cause a rekey.
Is that not correct?