VPN stops passing traffic between Meraki Security Appliances and Cisco ASAv devices

Gord719
Here to help

VPN stops passing traffic between Meraki Security Appliances and Cisco ASAv devices

WE have a situation where we manage site to site vpns between Meraki devices and Cisco ASA devices. WE can establish a site to site VPN fine but after a undetermined / random amount of time the tunnel will stop passing traffic and we have to force a rekey on the ASA side or force the vpn down and back up on the Meraki portal side but shutting VPN settings off and turning the back on. 

 

WE have been back and forth with support for both ends, set recommended ph1 and ph2 timeouts, disabled dpd and other misc settings but the issue remains. WE always attempt to be the on the latest firmware on both ends.

 

I am out of ideas. 

 

The strange thing is that the tunnel in the portal shows the green "up" icon and on the asa side it will still show "active" but no traffic will pass until you reset/rekey to force the tunnel reset. 

 

Looking for recommendations, ideas or feedback.

70 Replies 70
Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.
Labels