IPsec Connectivity Down
Change Review
- Review any recent changes to:
- VPN profiles
- Pre-shared keys (PSKs)
- Certificates
- Peer settings
Diagnostic Actions
- Use the
ike -snoop
command to inspect IKE negotiations. - Capture VPN-related traffic on the WAN interface (UDP 500/4500).
- Check IPsec tunnel status using CLI commands.
- Review logs for Phase 1 or Phase 2 negotiation errors.
- Confirm availability of the remote peer and verify routing and NAT.
Recovery Milestones
- Tunnel is up and passes traffic.
- Negotiation completes successfully; peer is unresponsive.
- Reverting VPN configuration restores connectivity.
Related articles
No related articles found.