QuestionQ25

Site-to-site Virtual Private Networks on Routers and Firewalls

Question Image

Refer to the exhibit. An IKEv2 site-to-site tunnel between an ASA and a remote peer is failing to establish. Based on the debug output, what will resolve the issue?

Explanation

TS_UNACCEPTABLE indicates that the received IKEv2 traffic selectors do not match a configured IPsec policy. In a policy-based ASA site-to-site VPN, the crypto access list defines those protected source and destination networks, so the crypto access lists must match as mirrored local/remote pairs on the two VPN devices. Cisco documents this error when no matching IPsec policy exists for the received traffic selectors.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!