I am having strange issues with a couple of ASA 5505's. I have a site to site tunnel connecting two ASA 5505s. At first the tunnel will come up and pass traffic for a short period of time then quit if someone is not actively on it. Once the tunnel breaks you can ping across and the tunnel will come back up but it will not pass traffic. I have to completely strip out the VPN config and put it back in for traffic to pass again.
It seems to be getting worse. Now if Site A pings first it will establish the tunnel (MM_ACTIVE) but no traffic will pass. If Site B pings first it will not bring up the tunnel at all. I get MM_WAIT_MSG4. Which is basically saying it's waiting on Site A to send the keys from my understanding.
I have poured over this website and the web trying to figure out what is going on, but no luck so far. I desperately need some help with this. I'm not seeing how it worked briefly with this config and now it won't do anything. Nothing has been changed on either end of the tunnels.
If Site A pings first:
SiteA:
Active SA: 1
Rekey SA: 0 (A tunnel will report 1 Active and 1 Rekey SA during rekey)
Total IKE SA: 1
1 IKE Peer: 71.xxx.xxx.233
Type : L2L Role : initiator
Rekey : no State : MM_ACTIVE
SiteB:
Active SA: 1
Rekey SA: 0 (A tunnel will report 1 Active and 1 Rekey SA during rekey)
Total IKE SA: 1
1 IKE Peer: 66.xxx.xxx.18
Type : L2L Role : responder
Rekey : no State : MM_ACTIVE
Traffic will not pass.
If Site B pings first:
Site B:
Active SA: 1
Rekey SA: 0 (A tunnel will report 1 Active and 1 Rekey SA during rekey)
Total IKE SA: 1
1 IKE Peer: 66.xxx.xxx.18
Type : user Role : initiator
Rekey : no State : MM_WAIT_MSG4
”The time we save is the biggest benefit of E-E to our team. What could take multiple guys 2 hours or more each to find is accessed in around 15 minutes on Experts Exchange.
-Mike Kapnisakis, Warner Bros
With your subscription - you'll gain access to our exclusive IT community of thousands of IT pros. You'll also be able to connect with highly specified Experts to get personalized solutions to your troubleshooting & research questions. It’s like crowd-sourced consulting.
We can't always guarantee that the perfect solution to your specific problem will be waiting for you. If you ask your own question - our Certified Experts will team up with you to help you get the answers you need.
Our certified Experts are CTOs, CISOs, and Technical Architects who answer questions, write articles, and produce videos on Experts Exchange. 99% of them have full time tech jobs - they volunteer their time to help other people in the technology industry learn and succeed.
We can't guarantee quick solutions - Experts Exchange isn't a help desk. We're a community of IT professionals committed to sharing knowledge. Our experts volunteer their time to help other people in the technology industry learn and succeed.
Our community of experts have been thoroughly vetted for their expertise and industry experience.