Skip to main content
This article describes how to troubleshoot IPsec VPN connection with IKEv2 on Aviatrix gateway.

Check External Connection (S2C) Connection Status

In CoPilot, go to Networking > Connectivity > External Connections (S2C). Check if there is a green or red dot next to the name of the external connection. You can also check external connection status from Diagnostics > Cloud Routes > External Connections (look at the Status and Tunnel Status columns). If the Tunnel Status is down, you can perform the following procedure.

Perform the Analysis Diagnostics Action

  1. Go to Diagnostics > Diagnostic Tools > Connectivity Diagnostics.
  2. Select the Gateway Instance and the related Connection.
  3. Select Analysis in the Tools list and click Run. The screen will display analysis results.

Troubleshoot the keyword in the Diagnostics Action “Show logs”

  1. Go to Diagnostics > Diagnostic Tools > Connectivity Diagnostics.
  2. Select the Gateway Instance and the related Connection.
  3. Select Logs in the Tools list.
  4. (optional) Enable or disable verbose logging.
  5. Click Run. The screen displays the related logs. You can copy the results to the clipboard. IKEv2_show_log

Examples of IKEvs Negotiation Failure

Here are some examples of negotiation failure related troubleshooting hints: