No IKE (ISAKMP) Message Exchange Between Huawei Eudemon 200 and Cisco ASA 5520
Posted on 2010-08-13
The requirement to secure the traffic is to establish L2L (Site-to-Site) IPSec VPN between Huawei Eudemon 200 and Cisco ASA 5520. Both outside interfaces of these 2 firewalls are reachable and the configuration is done on both ends with the mirrored ACLs on the firewalls. I turn on the debug on both firewalls but there is no any negotiation message for phase 1 between them, neither on Huawei Eudemon 200 nor on Cisco ASA 5522.
Debugging commands On Huawei Eudemon 200:
debugging ike all
Debugging commands On Cisco ASA 5520:
debug crypto isakmp 127
I am wonder what are the main reasons behind the fact that there is any single phase I negotiation message exchanged between both firewalls. I appreciate your suggestions to have these 2 firewalls negotiate successfully for Phase I. Why I cannot see any message related to Phase I negotiation between Huawei firewall and Cisco ASA?
Note: I have tried to reset/clear SA but there is no hope to see the negotiation message among them neither from Eudemon 200 nor from Cisco ASA 5520.