Phase 1 is down but phase 2 is up- test vpn phase 1 and 2

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Phase 1 is down but phase 2 is up- test vpn phase 1 and 2

Cyber Elite
Cyber Elite

we have tunnel from PA  to vendor which is using Cisco ASA.

When there is no interesting traffic tunnel is down by design this part is ok.

 

but today i saw phase 1 as red and phase 2 as green on gui.

I did the 

 

test vpn ike command and phase 1 was green

but i was unable to ping across tunnel i see traffic going via tunnel but no replies.

 

Then i did

 

test vpn ipsec 

 

i was able to ping lan device at other end.

 

need to know when phase shows down then is it best practice to use the test command  for both phase 1 and 2?

when both phase 1 and 2 shows green and you can not ping across tunnel, you traffic going but no reply then should we use test command for phase 1 and  phase 2?

 

MP

Help the community: Like helpful comments and mark solutions.
1 accepted solution

Accepted Solutions

Cyber Elite
Cyber Elite

@MP18,

Phase 1 doesn't need to show as active to still have a tunnel up and running. Essentially Phase 1 is just there to setup a secure channel for phase 2, and once that association has been made phase 1 doesn't matter. Therefore, Phase 1 can show as down and the tunnel will still be perfectly operational. 

I would honestly guess here that your issue is more to do with not having a tunnel-monitoring profile assigned to the tunnel, which means the PA might not notice if your ASA closes the tunnel due to inactivity. Which means you kind of have two options:

1) Apply a tunnel monitoring profile so your PA actually knows when the ASA side of the tunnel goes down. 

2) Configure the ASA so 'vpn-idle-timeout none' is present within the assigned group-policy attributes. 

View solution in original post

2 REPLIES 2

Cyber Elite
Cyber Elite

@MP18,

Phase 1 doesn't need to show as active to still have a tunnel up and running. Essentially Phase 1 is just there to setup a secure channel for phase 2, and once that association has been made phase 1 doesn't matter. Therefore, Phase 1 can show as down and the tunnel will still be perfectly operational. 

I would honestly guess here that your issue is more to do with not having a tunnel-monitoring profile assigned to the tunnel, which means the PA might not notice if your ASA closes the tunnel due to inactivity. Which means you kind of have two options:

1) Apply a tunnel monitoring profile so your PA actually knows when the ASA side of the tunnel goes down. 

2) Configure the ASA so 'vpn-idle-timeout none' is present within the assigned group-policy attributes. 

we do not have tunnel monitoring setup as Cisco side is configured for tunnel down after 30 mins idle timeout.

 

Will ask Vendor to configure the  ASA so 'vpn-idle-timeout none

MP

Help the community: Like helpful comments and mark solutions.
  • 1 accepted solution
  • 5508 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!