Skip to content

How do I resolve KEv1 and IKEv2 errors for Site-to-Site VPN connections?

2 minute read
0

I want to resolve IKEv1 and IKEv2 errors for my AWS Site-to-Site VPN connection.

Resolution

Use the AWSSupport-TroubleshootVPN runbook to run automated checks for IKEv1 or IKEv2 error messages that are related to VPN tunnels in your Site-to-Site VPN connection. 

Prerequisites:

Run the automation runbook

Note: The automation makes Amazon CloudWatch Logs Insights API calls on the CloudWatch log group that you configured for VPN logging. For CloudWatch Logs Insights pricing, see Amazon CloudWatch pricing.

Complete the following steps:

  1. Open the AWS Systems Manager console.
  2. In the navigation pane, choose Documents.
  3. In the search bar, enter AWSSupport-TroubleshootVPN.
  4. Choose AWSSupport-TroubleshootVPN.
  5. Choose Execute automation.
  6. Choose Execute.
  7. Review the Outputs section in the Systems Manager console for detailed results. The output lists each error with its resolution and the total number of unique errors.

Related information

Run an automation operation powered by AWS Systems Manager Automation

Setting up Automation

Systems Manager Automation runbook reference