1. Separate connection states
A fictional connection between a processing site and a partner supports closing reports. The dashboard shows established IKE, but the file never arrives. This is not contradictory: the IKE association supports negotiation and control, while Child SAs protect selected traffic. The RFC allows an IKE SA to exist when the first Child SA fails for reasons such as unacceptable selectors. Before changing parameters, record peer, identity, version, time, stage and outcome. Do not use “VPN up” as a synonym for delivered service. Acceptance also requires representative traffic, a return path, applicable policy and application confirmation of the result.
2. Interpret stage and error
The worksheet presents three independent clues. NO_PROPOSAL_CHOSEN during IKE_SA_INIT calls for comparing IKE proposals; the same error type during Child SA creation directs analysis to that proposal. TS_UNACCEPTABLE points to selector scope rather than proving a wrong password. AUTHENTICATION_FAILED calls for reviewing identity and authentication method without exposing the key in the ticket. For certificates, include validity, chain and observed clock. A shared proposal must remain within approved policy. Do not add old algorithms broadly to obtain any green connection. Retain stage and context because error text alone may not identify the component.
3. Follow protected traffic
In the worksheet, A protects 10.60.10.0/24 toward 10.70.20.0/24, but B accepts only source 10.60.10.0/25. Host.30 lies within both.200 is outside the half accepted by B. Reconcile that difference against authorized scope without widening everything to any source. Also consider NAT translation and effective rule order. A route-based VPN requires routing toward the VTI and suitable access policy; creating the interface does not magically create a working route. Compare counters before and after one scoped attempt on both peers. Encrypting without receiving a reply can have remote, return-path or application causes and does not itself establish a wrong key.
4. Validate change and continuity
Configuration saved in the manager may still await deployment. Confirm the effective revision and both ends before measuring results. On a backup VTI, the backup label alone does not select the path: routing participates in selection. Continuity testing should measure transactions, reconvergence and capacity after an authorized failure rather than only an SA reappearing. A periodic interruption calls for correlation with rekey, expiry, routing and both peers’ logs; convenient timing alone does not establish rekey. Define rollback conditions and a partner contact able to execute and confirm actions on the equipment they manage.
5. Hand useful diagnosis to RUN
Handover includes permitted flows, selectors, routes, identity, owners, alarms and evidence of positive and negative tests. Capture only what the investigation needs and treat credentials as secrets. Debugging can consume significant CPU; define window, scope, duration, stop criteria and confirmation that it was disabled. General event guidance recommends avoiding beginning/end duplication where possible, while the VPN diagnostic chapter requests both for its view. That difference calls for a contextual decision and volume control. The worksheet is a tabletop exercise without an executed Cisco tunnel. Summary: separate control, data and service, progressing through evidence that distinguishes the next hypothesis.
Host 10.60.10.30 belongs to /25; 10.60.10.200 does not. Active IKE resolves neither selector differences nor report delivery.
Common pitfalls
IKE state as application acceptance; changing keys for every error; widening selectors without authorization; unlimited debug.
Related topics: IPsec and IKEv2 · Routing and NAT · Change management
VPN diagnosis needs stage, flow, direction and observed outcome.
Reference: Site-to-Site VPN · 350-701 SCOR v2.0, effective 2026-08-27; core component of CCNP Security