Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations strongm on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

L2L problem between Cisco ASA and Checkpoint FW1

Status
Not open for further replies.

Svanen

Technical User
Dec 15, 2004
10
SE
Hi All!

Have a problem with a L2L tunnel to a customer, I have many other L2L tunnels working fine but this one is not working properly.

Problem is that after a couple of days, everything been running fine it stops.

When looking at the isakmp sa I see the following:

IKE Peer: X.X.X.X
Type : L2L Role : initiator
Rekey : yes State : MM_ACTIVE_REKEY
IKE Peer: X.X.X.X
Type : L2L Role : responder
Rekey : no State : AM_REKEY_DONE_H2

And from the debug log:
Group = X.X.X.X, IP = X.X.X.X, Failure during phase 1 rekeying attempt due to collision.

Anyone seen this before, if there would be a mismatch in the config the tunnel wouldn't be established at all??

Thanks!

/Johan


 
Are the lifetimes the same?

Brent
Systems Engineer / Consultant
CCNP, CCSP
 
Hi!

Customer had their network consultant there last thursday and rechecked the lifetime after I sent them my config for this tunnel, it looks like there been some kind of mismatch because the reply I got from them was that they had tuned the lifetime to match mine, no trouble with the tunnel since then.

Thanks!

 
thought it might be that. glad it works.

Brent
Systems Engineer / Consultant
CCNP, CCSP
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top