IPSec VPN phase2 partial up

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

IPSec VPN phase2 partial up

L2 Linker

hello everyone

 

I have a IPSec tunnel with Cisco ASA, and the proxy-id config is:

entry1: local 1.1.1.1 remote 2.2.2.2

entry2: local 1.1.1.1 remote 2.2.2.3

 

The very annoying things the phase2 is partial UP, when "show vpn flow", either entry1 is active and entry2 is inactive OR entry2 is active or entry1 is inactive.

DongQu_0-1619102922750.png

 

Is this due to the incorrect config in somewhere?

 

Thanks

1 accepted solution

Accepted Solutions

L2 Linker

the palo told me that the DH group for the phase2 needs to use group 20 with Cisco while have multiple proxy-id, I was using group5.

The issue was gone after changing to group 20.

View solution in original post

6 REPLIES 6

Hi @DongQu ,

 

Most probably you don't have constant traffic running for both remote networks.

If you see both active at different time this means negotiation is successfull for both and if there is real traffic tunnel should be fine.

hi @aleksandar.astardzhiev 

I tried to use "test vpn ipsec-sa tunnel" to Initiate the IPSec SA, after 1 of them getting "active", the other 1 cannot get up anymore.

 

L6 Presenter

First your proxy id seems wrong as it should be the private sybnets that  are internal for the firewalls (also check the ipsec timers if they match like the "lifetime"):


https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClJ3CAK

 

 

https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClE6CAK

 

 


If you still have issue:


%%%%%%%%%%%%%%%%%%%%%%%


Can you make the Palo Alto the responder as this way you will get more data in the GUI System log (or Globalprotect log in newer version)?


https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClMZCA0

 

Also you can do a debug on the ikemgr:


> debug ike global on debug
> less mp-log ikemgr.log

https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClivCAC

 


Also check if DPD is disabled as maybe the ASA may have issues with it and test without it.


https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClFaCAK


%%%%%%%%%%%%%%%%%%%%%%%%

L2 Linker

the palo told me that the DH group for the phase2 needs to use group 20 with Cisco while have multiple proxy-id, I was using group5.

The issue was gone after changing to group 20.

Hi @DongQu ,

I am not sure I understadn your last comment.

Run

> test vpn ipsec-sa tunnel tu-ITIVIT:tu-ITIVIT
> show vpn flow

What is that status of this tunnel?

Immediately run 

> test vpn ipsec-sa tunnel tu-ITIVIT:tu-ITIVIT-2
> show vpn flow

What is the status of second tunnel?

If you execute "test vpn" for both proxy-id immediately one after another, are one still showing inactive?

Have you checked the logs? Go to system logs (where the ipsec s2s log are located) and you can add this filter

( object contains tu-ITIVIT )

while using the DH is group5 on the PA and Cisco ASA

> test vpn ipsec-sa tunnel tu-ITIVIT:tu-ITIVIT
> show vpn flow

What is that status of this tunnel?   ------ tu-ITIVIT:tu-ITIVIT -----> active

Immediately run 

> test vpn ipsec-sa tunnel tu-ITIVIT:tu-ITIVIT-2
> show vpn flow

What is the status of second tunnel?   ---------  tu-ITIVIT:tu-ITIVIT-2------> inactive

 

after changing DH to group20 on both sides.

> test vpn ipsec-sa tunnel tu-ITIVIT:tu-ITIVIT
> show vpn flow

What is that status of this tunnel?   ------ tu-ITIVIT:tu-ITIVIT -----> active

Immediately run 

> test vpn ipsec-sa tunnel tu-ITIVIT:tu-ITIVIT-2
> show vpn flow

What is the status of second tunnel?   ---------  tu-ITIVIT:tu-ITIVIT-2------> active

  • 1 accepted solution
  • 3919 Views
  • 6 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!