cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
23444
Views
0
Helpful
5
Replies

Tunnel Manager has failed to establish an L2L SA. All configured IKE versions failed to establish the tunnel.

Hello everyone
attached the logs of the non-negotiation of the l2l tunnel.
the two peers are on two ASAs on different contexts
If I move one of the two tunnels on the main context, the tunnel is negotiated.
Can you help me?

Thanks in advance

Daniele

5 Replies 5

Hi,
No logs attached, can you also upload your configuration of both ASA's please

Thanks for the quick reply.
I enclose the configurations of both ASAs.
both configurations are of the single context where the L2L tunnel is configured.
Thank you so much again.

Sorry I had forgotten the logs that I attach below

 

 

Can you please run the follow debugs, attempt to establish the vpn and upload the output

debug crypto condition peer X.X.X.X <<- replace with the peer ip address
debug crypto ikev1 200

I solved the problem
the subnet I used as peer had acl on the router only for a / 27 while I was using the IP included in a / 26.
The problem is that the carrier on routers before my ASAs of our MPLS did not extend the acl to this subnet too.
I changed subnet with a / 30 that I had available and now the tunnel is negotiated.
Thank you very much