08-18-2013 09:08 AM
I am using asa5505(8.2) SiteA iskamp site to site VPN to SiteB asa5515x(8.6) ikev1. The tunnel will up and running only if initial ping from SiteA
I don't know why tunnel cannot up and running if I try to initial ping from siteB. Is there any setup I miss that I can make both site initial ping to bring up tunnel?
Both site A 5505 and B 5515x are using static IP for peer.
Sent from Cisco Technical Support iPhone App
Solved! Go to Solution.
08-18-2013 11:29 PM
There are a couple of parameters in the IPSec-config that can cause this behaviour if they don't match on both sides. Start with checking that the entries in your Crypto-ACL are really mirrored. That's what I have seen most often with this problem. Check also if you have configured "initiate-only" or "respond-only" on your ASAs which could also cause this problem.
Sent from Cisco Technical Support iPad App
08-18-2013 11:29 PM
There are a couple of parameters in the IPSec-config that can cause this behaviour if they don't match on both sides. Start with checking that the entries in your Crypto-ACL are really mirrored. That's what I have seen most often with this problem. Check also if you have configured "initiate-only" or "respond-only" on your ASAs which could also cause this problem.
Sent from Cisco Technical Support iPad App
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide