Policy IPSec tunnel status showing degraded: IPSec negotiation not started
search cancel

Policy IPSec tunnel status showing degraded: IPSec negotiation not started

book

Article ID: 415771

calendar_today

Updated On:

Products

VMware NSX

Issue/Introduction

The IPSec tunnel information in the NSX UI, it can be seen the tunnel is in a degraded status with the message "IPSec negotiation not started". 

Environment

VMware NSX

Cause

  • IKESA is not established
  • There is no traffic matching the IPSec IP

Please note the list above is not exhaustive. 

Resolution

  • Verify configurations between endpoints, ensuring they match
  • Verify connectivity by pinging between endpoints
  • Ensure upstream configurations can pass the IPSec traffic and has the IPSec IP
  • Refer to Troubleshooting NSX L2 VPN for more detailed processes with troubleshooting NSX VPN issues. 

If contacting VMware by Broadcom Support for this issue, please provide the following log bundles:

  • NSX Manager 
  • NSX Edge Nodes involved with the IPSec VPN
  • Any other specific error messages seen in the environment regarding IPSec VPN

Please refer to Creating and managing Broadcom support cases for further details on the processes of creating VMware by Broadcom support cases.