Cisco ASA 5505 does not initiate site to site VPN

cisco-asacisco-vpn

I am using Cisco ASA 5505 to establish a site to site VPN tunnel.

The problem is that, my ASA 5505 does not seem to initiate the negotiation but once the device on the other starts the negotiation the tunnel establishes successfully!

Is there any such configuration that enables the initiation of phase 1 negotiation?

Any clues what am I missing?

Thanks,

Best Answer

I would run through these steps:

  1. Before the L2L P2 is up, go ahead and ping an interesting traffic host. If everything is set up correctly, this will initiate the tunnel. Apologies if you already knew that but some do not.
  2. On the ASA, ensure that you have set up a crypto map entry for the interesting traffic. What could be happening, and this is just a guess, but perhaps you do not have the correct crypto map in place and instead when the peer initiates you are establishing using the dynamic crypto map.
  3. Using ASDM you can check out your connection profile and check your setting under Crypto Map and make sure that it is on "Bidirectional" rather than "answer only"
  4. Finally, make sure that is not your peer that is the issue.