Really in Cisco troubleshooting we are basically unable to help properly without the configuration file, I am not offending you or your remote fellow but it is hard to give help by guessing.
but if I am going to guess I would say:
This message means: MM = Main Mode, WAIT = Waiting, MSG2 = Message 2 sent by the remote host accepting your certificate
so it could mean that the remote host message is being dropped before reaching your firewall or maybe there is a firewall in the remote end blocking some TCP or UDP ports required by isakmp used by your site-to-site VPN.
if your Site-to Site VPN was already working fine before but now is making this behavior then there would be other suggestions than the one I proposed, for this please provide us with more detailed information and a simple design to help you more.
Re: MM_WAIT_MSG2 in site-site vpn
9 years 8 months ago #30987