Autonomous Edge L2VPN Tunnel Fails Due to IPsec Pre-Shared Key Mismatch
search cancel

Autonomous Edge L2VPN Tunnel Fails Due to IPsec Pre-Shared Key Mismatch

book

Article ID: 446973

calendar_today

Updated On:

Products

VMware NSX

Issue/Introduction

  • The environment/infrastructure is experiencing an L2VPN outage.
  • The L2VPN peer-to-peer tunnel between the local network and remote network is down.
  • Firewalls may alert on a shared secret (Pre-Shared Key) mismatch between the two gateways.
  • The Autonomous Edge UI reports the L2VPN session Status is DOWN.

Environment

Autonomous NSX Edge

Cause

The IPsec Pre-Shared Key (PSK) between the managed NSX L2 VPN Server and the Autonomous Edge L2 VPN Client is mismatched. This prevents IKE Phase 1 negotiation from completing successfully, causing the underlying IPsec session and L2VPN tunnel to fail authentication.

Resolution

  • Log in to the remote managed NSX Manager with admin privileges and navigate to Networking > VPN > L2 VPN Sessions.
  • Retrieve the peer_code from the downloaded configuration file.
  • Log in to the local Autonomous Edge web UI and paste the updated peer_code into the session configuration to synchronize the IPsec parameters.

Additional Information