Tuesday, November 14, 2017

Troubleshooting Cisco ASA 5516 Site to Site VPN

Hi everyone,

I recently inherited all of the firewall duty at my workplace. I've gotten at least a bit familiar with the command line and ASDM for it, but there has been an ongoing issue recently that I'm trying to figure out where to start looking.

Basically, we have a IKEv1 IPsec tunnel going to our remote branch.

Over the last few weeks, occasionally it will drop off and kick our users off (services are hosted at main branch and so is the VoIP controller). I've called Cisco a few times and the only thing that "fixes" it is "clear crypto ipsec sa peer xxx.xxx.xxx.xxx"

But I want to find out why this is happening and why they are dropping. I have a sneaking suspicion that the firewalls are okay and that the real villain here is Comcast, but if I could get some insight on why this is happening that would be really great. Thank you.



No comments:

Post a Comment