Warning message

  • Cisco Support Forums is in Read Only mode while the site is being migrated.
  • Cisco Support Forums is in Read Only mode while the site is being migrated.

PIX-to-PIX GRE one way only

Unanswered Question
Aug 20th, 2007
User Badges:

I have configured a GRE tunnel between two routers that are each behind PIX firewalls. I have setup a VPN to encrypt all IP traffic between the routers.

The GRE traffic is only flowing from router A to router B.

I can ping from router A to router B and vice versa. I've verified that those pings are going out via the vpn by doing a 'show ipsec sa' and watching the counters. I have also verified that the GRE tunnel keepalives are being sent by both routers but only router A's packets are making it across. Router B receives A's keep-alives but A does not receive B's.

I did a capture on pix B to verify that the GRE packets from router B are making it to the PIX correctly.

I do not have any specific rules anywhere, on either PIX, or either router for gre. The access-list rule looks like this:

access-list tunnel extended permit ip xx.xx.198.40 xx.xx.198.44

When I do a 'packet-tracer' on pix B I see that everything but GRE goes out the VPN but all I get for GRE is:



Result: ALLOW


Additional Information:

Found flow with id 2696171, using existing flow


input-interface: inside

input-status: up

input-line-status: up

Action: allow

I have no idea how to view details on flow id 2696171.

Any ideas?

  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
irisrios Fri, 08/24/2007 - 13:25
User Badges:
  • Silver, 250 points or more

What pix version are you using?


This Discussion