• Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 307
  • Last Modified:

VPN Tunnel will not complete

I am wondering if anyone else runs into issues like this.  Phase 1 at the remote site(Cisco 881 series router) will complete, but then comes back to the main firewall(clustered 5520s) and Phase 2 does not complete.  In the past I have rebooted our 5520 cluster and that seems to fix it everytime, but i have over 140 remote sites and when I do that, it usually takes a long time for all tunnels to rebuild.  Are there certain commands that can be used in CLI on the 5520 cluster that will clear any caching issues?
0
mikhall
Asked:
mikhall
1 Solution
 
CyberwrathCommented:
You can clear an individual problematic tunnel as follows

ASA2-5520(config)# clear crypto isakmp sa ?

exec mode commands/options:
  Hostname or A.B.C.D     IP address
  Hostname or X:X:X:X::X  IPv6 address
  <cr>

Much cleaner than rebooting the cluster.
0

Featured Post

Evaluating UTMs? Here's what you need to know!

Evaluating a UTM appliance and vendor can prove to be an overwhelming exercise.  How can you make sure that you're getting the security that your organization needs without breaking the bank? Check out our UTM Buyer's Guide for more information on what you should be looking for!

Tackle projects and never again get stuck behind a technical roadblock.
Join Now