Expiring Today—Celebrate National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17

x
?
Solved

Cisco ASA L2L VPNs down after ISP Change

Posted on 2011-03-06
8
Medium Priority
?
690 Views
Last Modified: 2012-05-11
Hello
We just changed ISPs and thus have new IPS.  We have a new WAN IP and then a block of IPS (CIDR).   After this change our two site to site VPN tunnels stopped working.  We changed the IP of the remote site to the new WAN interface IP (on the two remote routers) but the connections still won't work.  All of the devices are Cisco ASA apliances.  Are we missing something in regards to ACL or routing ?    Usually changing the remote site VPN on the remote routers brings things right back up.

Thanks for your help.

0
Comment
Question by:corpdsinc
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
  • 2
  • 2
8 Comments
 
LVL 79

Accepted Solution

by:
lrmoore earned 1000 total points
ID: 35049913
Do you have any route statements left over pointing to the old ISP gateway?
0
 
LVL 1

Author Comment

by:corpdsinc
ID: 35049972
Nope, all of the static routes point to the new WAN IP.... now that I think about it...the WAN INT Ip is a /28 ..  Do you think that fact that the 0.0.0.0 0.0.0.0 static route is set to the WAN INT IP instead of the WAN INT gateway could be the problem?
0
 
LVL 9

Assisted Solution

by:predragpetrovic
predragpetrovic earned 1000 total points
ID: 35050812
Hi,

can you send debug outputs... i think that the remote ends did not update the peer IP addresses.
0
Concerto Cloud for Software Providers & ISVs

Can Concerto Cloud Services help you focus on evolving your application offerings, while delivering the best cloud experience to your customers? From DevOps to revenue models and customer support, the answer is yes!

Learn how Concerto can help you.

 
LVL 79

Expert Comment

by:lrmoore
ID: 35051194
>Do you think that fact that the 0.0.0.0 0.0.0.0 static route is set to the WAN INT IP instead of the WAN INT gateway could be the problem?
Absolutely! It must point to the next hop, never to your own interface ip!
0
 
LVL 1

Author Comment

by:corpdsinc
ID: 35051292
Ok..my bad.  I forgot that i did change the default routes  for the WAN INT default gateway yesterday..I was excited about that being the fix...but no luck.  Any other ideas?  

Pedraq:  I have verified that that peer IPs are correct.  In fact, I recreated the VPN on one of the remote sites via the wizzard creating new tunnel group and Peer IP etc.  

0
 
LVL 9

Expert Comment

by:predragpetrovic
ID: 35051837
ok,

could you do the following on your ASA device:

debug crypto ipsec
debug crypto isakmp
terminal monitor

and try to send traffic from one site to another (traffic which matches the crypto maps), send the debugs.
0
 
LVL 1

Author Comment

by:corpdsinc
ID: 35058185
I was unable to do th debug.  But using ASDM monitoring I see that the lan2lan tunnel is established.  At the remote side it is passing two way traffic.  HOWEVER, at the main site (where the public IP was changed) it is receiving data but not transmitting (0 TX bytes 970 RX bytes)
0
 
LVL 1

Author Comment

by:corpdsinc
ID: 35061687
I now have both VPN connected now...but still not passing traffic.  I have included a JPG of the ASDM monitor showing one way traffic. ASDM
0

Featured Post

[Webinar] Lessons on Recovering from Petya

Skyport is working hard to help customers recover from recent attacks, like the Petya worm. This work has brought to light some important lessons. New malware attacks like this can take down your entire environment. Learn from others mistakes on how to prevent Petya like worms.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Concerto Cloud Services, a provider of fully managed private, public and hybrid cloud solutions, announced today it was named to the 20 Coolest Cloud Infrastructure Vendors Of The 2017 Cloud  (http://www.concertocloud.com/about/in-the-news/2017/02/0…
During and after that shift to cloud, one area that still poses a struggle for many organizations is what to do with their department file shares.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Both in life and business – not all partnerships are created equal. As the demand for cloud services increases, so do the number of self-proclaimed cloud partners. Asking the right questions up front in the partnership, will enable both parties …

718 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question