Which of the following can result in an IPsec VPN establishment failure?
IPsec peers must have reachable paths and compatible traffic selectors and security-association proposals. ACLs must define the required protected traffic, while the negotiated IPsec parameters must have compatible encapsulation and encryption settings. Missing routing to the peer-side network can prevent the required VPN traffic or peer communication from being reached. Cisco documentation identifies mismatched crypto ACLs and transform-set parameters as negotiation problems, and requires appropriate routing for protected VPN traffic.
Community Discussion