<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[21.02 Upgrade Broke IPSec site-2-site to Cisco ASA]]></title><description><![CDATA[<p dir="auto">Reading the advise of the other thread, I'm opening a new thread based on my specific IPSec issue with 21.02....</p>
<p dir="auto">Had a previous 2.4.5 install working fine with Site-2-site VPN to a Cisco ASA.<br />
Upgraded to 21.02 and the VPN connects fine, but no traffic flows.</p>
<p dir="auto">The only negative comment in the logs I can find is:<br />
Feb 20 10:11:11 	charon 	45335 	12[IKE] &lt;con100000|5&gt; nothing to initiate</p>
<p dir="auto">I've looked at the ID change/issue, but my P1 session ID is Local IP, and the connection appears to be coming up - I just get no packets flowing.</p>
<p dir="auto">I'm assuming the ASA config is good as it worked fine for a long time on 2.4.5.</p>
<p dir="auto">Any ideas?</p>
]]></description><link>https://forum.netgate.com/topic/161149/21-02-upgrade-broke-ipsec-site-2-site-to-cisco-asa</link><generator>RSS for Node</generator><lastBuildDate>Wed, 22 Apr 2026 17:26:32 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/161149.rss" rel="self" type="application/rss+xml"/><pubDate>Sat, 20 Feb 2021 17:13:56 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to 21.02 Upgrade Broke IPSec site-2-site to Cisco ASA on Mon, 22 Feb 2021 21:42:39 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/sgw">@<bdi>sgw</bdi></a> I can confirm disabling hw crypto on our SG-1100 running 21.02 fixed our tunnels to a Sonicwall.  We had the same issues as the OP, tunnels connected but no traffic flowing inside.</p>
]]></description><link>https://forum.netgate.com/post/966928</link><guid isPermaLink="true">https://forum.netgate.com/post/966928</guid><dc:creator><![CDATA[it.subscriptions]]></dc:creator><pubDate>Mon, 22 Feb 2021 21:42:39 GMT</pubDate></item><item><title><![CDATA[Reply to 21.02 Upgrade Broke IPSec site-2-site to Cisco ASA on Mon, 22 Feb 2021 10:10:42 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/mystic330">@<bdi>mystic330</bdi></a> I am not sure if I hit the same issue as you, but:</p>
<p dir="auto">when I enable hw crypto one of my tunnels does not work (I am quite sure it's a Cisco on the other side).</p>
<p dir="auto">After disabling hw crypto and a reboot the same tunnel config works. Tested again right now.</p>
]]></description><link>https://forum.netgate.com/post/966572</link><guid isPermaLink="true">https://forum.netgate.com/post/966572</guid><dc:creator><![CDATA[sgw]]></dc:creator><pubDate>Mon, 22 Feb 2021 10:10:42 GMT</pubDate></item><item><title><![CDATA[Reply to 21.02 Upgrade Broke IPSec site-2-site to Cisco ASA on Sun, 21 Feb 2021 05:39:17 GMT]]></title><description><![CDATA[<p dir="auto">Really not a happy camper....</p>
<p dir="auto">After loading my old config, my IPsec remote clients aren’t working either....</p>
<p dir="auto">So I needed to go back to 2.4.5.... so I threw in the USB with the image I got from Netgate and it erased the flash and then booted and said “unsupported system, no serial number”....🤬<br />
This is a real deal SG1100!!!!<br />
So now I’ve got a brick....</p>
]]></description><link>https://forum.netgate.com/post/966150</link><guid isPermaLink="true">https://forum.netgate.com/post/966150</guid><dc:creator><![CDATA[mystic330]]></dc:creator><pubDate>Sun, 21 Feb 2021 05:39:17 GMT</pubDate></item><item><title><![CDATA[Reply to 21.02 Upgrade Broke IPSec site-2-site to Cisco ASA on Sun, 21 Feb 2021 02:53:26 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/mmapplebeck">@<bdi>mmapplebeck</bdi></a> Thanks!<br />
That patch did fix the Ipsec status page.</p>
<p dir="auto">Lots of issues indeed :-(<br />
I will play with it for another day or two, but then I'll need to revert back to code that I know works...</p>
<p dir="auto">If anybody needs any logs, testing, etc. to troubleshoot this issue please let me know.</p>
]]></description><link>https://forum.netgate.com/post/966133</link><guid isPermaLink="true">https://forum.netgate.com/post/966133</guid><dc:creator><![CDATA[mystic330]]></dc:creator><pubDate>Sun, 21 Feb 2021 02:53:26 GMT</pubDate></item><item><title><![CDATA[Reply to 21.02 Upgrade Broke IPSec site-2-site to Cisco ASA on Sun, 21 Feb 2021 01:43:03 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/mystic330">@<bdi>mystic330</bdi></a> If you install the System Patches package, and install patch ead6515637a34ce6e170e2d2b0802e4fa1e63a00 from <a class="plugin-mentions-user plugin-mentions-a" href="/user/jimp">@<bdi>jimp</bdi></a> , it will fix the display issue, as for the other problem of packets not flowing properly, I have seen a few posts mention it, and I am having the same issue.</p>
<p dir="auto">Sadly, there seems to be something very wrong with strongswan/IPSec in 21.02, from invalid values(rekey time breaks if 0 is in field, should be blank), mismatched tunnel IDs(the above patch addresses this), widget problems, reports of secrets getting mangled, P2 that are no longer transmitting data.</p>
]]></description><link>https://forum.netgate.com/post/966115</link><guid isPermaLink="true">https://forum.netgate.com/post/966115</guid><dc:creator><![CDATA[MMapplebeck]]></dc:creator><pubDate>Sun, 21 Feb 2021 01:43:03 GMT</pubDate></item><item><title><![CDATA[Reply to 21.02 Upgrade Broke IPSec site-2-site to Cisco ASA on Sun, 21 Feb 2021 01:03:13 GMT]]></title><description><![CDATA[<p dir="auto">Another FYI - I'm seeing two strange things:</p>
<p dir="auto">1 - On the IPSec status screen I see a Child SA entry (I'm assuming P2?) under the main IPSec entry (P1?) - This Child SA entry has my local and remote subnets as defined in my P2 config.  The stats show that there are packets out, but no packets in.</p>
<p dir="auto">2 - On this same screen, under the above entries, I see another entry with the same configuration (I only have one VPN configured) that says it's Disconnected.  I've clicked the Connect button numerous times and nothing changes.</p>
<p dir="auto">I don't see anything that stands out in the logs as an obvious issue - It's almost like the routing is not correct.  Should I be seeing an entry in netstat -r for my remote network? (I'm not).</p>
<p dir="auto">Definitely something strange going on with IPSec in this release.</p>
]]></description><link>https://forum.netgate.com/post/966096</link><guid isPermaLink="true">https://forum.netgate.com/post/966096</guid><dc:creator><![CDATA[mystic330]]></dc:creator><pubDate>Sun, 21 Feb 2021 01:03:13 GMT</pubDate></item><item><title><![CDATA[Reply to 21.02 Upgrade Broke IPSec site-2-site to Cisco ASA on Sat, 20 Feb 2021 17:15:59 GMT]]></title><description><![CDATA[<p dir="auto">FYI - I have deleted all the VPN config and re-configured fresh on 21.02 - Same results.</p>
]]></description><link>https://forum.netgate.com/post/965937</link><guid isPermaLink="true">https://forum.netgate.com/post/965937</guid><dc:creator><![CDATA[mystic330]]></dc:creator><pubDate>Sat, 20 Feb 2021 17:15:59 GMT</pubDate></item></channel></rss>