VPN Troubleshooting

Cadillo,A,Adolfo,JRGH R 0 Reputation points
2024-08-01T13:36:46.5633333+00:00

My client and I changed our encryption domain and now the tunnel doesn't come up at all. What troubleshooting tools can I use to see why the tunnel doesn't come up. On my cisco FW I can do a debug or look at logs but what can I use on Azure to do this?

Azure VPN Gateway
Azure VPN Gateway
An Azure service that enables the connection of on-premises networks to Azure through site-to-site virtual private networks.
1,543 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. ChaitanyaNaykodi-MSFT 26,201 Reputation points Microsoft Employee
    2024-08-02T02:41:38.53+00:00

    @Cadillo,A,Adolfo,JRGH R

    Thank you for reaching out.

    For Azure VPN you can go through following steps to help troubleshoot the issue.

    • Check the cryptographic requirements for Azure VPN gateway documentation here to see if any un-supported encryption algorithm was selected.
    • You can also enable diagnostic logging for VPN Gateway and check the IKEDiagnosticLog. The IKEDiagnosticLog table offers verbose debug logging for IKE/IPsec. This is useful to review when troubleshooting disconnections, or failure to connect VPN scenarios.
    • You can also utilize the Packet Capture feature of Azure VPN Gateway to help troubleshoot this issue.

    Hope this helps! Please let me know if you have any additional questions. Thank you!


    Please "Accept the answer" if the information helped you. This will help us and others in the community as well.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.