Hej,
now that MR-1 has appeared, I wanted to ask when MR-2 will appear? The problems and instabilities of IPSec in v17 (especially in connection with V16.5) are very annoying.
This thread was automatically locked due to age.
Hej,
now that MR-1 has appeared, I wanted to ask when MR-2 will appear? The problems and instabilities of IPSec in v17 (especially in connection with V16.5) are very annoying.
Support has sent me a couple of new things to try. I'm waiting to get some time scheduled with the network engineer on the other end to try them out, but thought someone else might be able to test them before I get to. Here's what they said.
The lifetimes need to be set to Phase1: 10800 and Phase2: 3600
If you are using SHA2 you have to select the option for 96-bit truncation
In my case I'm not using SHA2, so that's not my issue, but it might help someone else. I'm curious to see if the lifetime settings have any effect.
In the meantime I have brought a decommissioned ASA back online in our network and have removed the affected tunnel from our XG and am now running it off of that. I'll continue testing because I'd like to just have the XG if possible. This issue has been so aggravating....
Just a quick update. I've been working with the GES team, but so far no changes. I was able to upgrade to MR3 and they got the tunnel to establish. It ran for almost a week and then started disconnecting every few hours. High availability completely breaks the tunnel.
The thing that still seems to work, even though it shouldn't, is that if I switch the ipsec profile from Main Mode to Aggressive Mode the tunnel becomes more stable and will only disconnect about once a day rather than every few hours. This is strange because the ASA on the other end is set to Main Mode, and the vpn profile is not even supposed to be compatible with Aggressive Mode. It actually makes the selection list on tunnel profile blank. So this appears to be a definite bug. We're discussing switching back to Cisco. This issue has become a deal breaker for us.
Anyone else had any luck?
We're in the same boat. Not an ASA but connecting to a Cisco Router at HQ. Disconnects multiple times a day. In our case the tunnel loses some of it's SA's that get established. Out of 9 SA's that are part of the tunnel only one or two show green in the vpn connection and the site goes down. A reconnect will re-establish it, but what a pain in the butt.
If anyone as a rock solid VPN connection to a cisco device I would love to know what configuration you're using.
-Scott