L2 VPN fails to establish connection
search cancel

L2 VPN fails to establish connection

book

Article ID: 416164

calendar_today

Updated On:

Products

VMware NSX

Issue/Introduction

  • syslog says:
    <TIMESTAMP> <FQDN> NSX <NUMBER> VPN [nsx@6876 comp="nsx-edge" subcomp="iked" s2comp="iked-event" level="INFO"] Request for IKE session status update for session: <SESSION_ID>, local_ip: <LOCAL_IP>, peer_ip: <PEER_IP> status: IKE_STATUS_DOWN, error: Peer not responding
  • CLI command "get ipsecvpn session down" or edge/vpn-session-down in edge support bundle show peer IP addresses that went down.

Environment

NSX 4.2

Cause

Peer may not responding or there may be underlying network connectivity issue.

Resolution

Check IP reachability with ping command on NSX Edge CLI.

For example

  1. List logical routers Service Router (SR) of VPN Gateway.
    get logical-routers to find VRF ID.
  2. Run ping from the SR.
    ping <Peer IP Address> vrfid <VRF ID>