Site to Site VPN initial connection fails then works second time

Unanswered Question
Nov 5th, 2007
User Badges:

I have setup a site to site vpn and during testing I am trying to telnet to a device at the other end of the vpn tunnel on port 80 to simulate web access. The tunnel initiates but no traffic is passed and the telnet times out. Once the tunnel is setup and I try again straight afterwards I can connect successfully, it only seems to be the first connection that drops while the tunnel is forming can someone tell me what I have done wrong please?

  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
smahbub Mon, 11/12/2007 - 07:12
User Badges:
  • Silver, 250 points or more

There might be many reasons that a VPN tunnel fails to come up on a router. However, one of the most common reasons is if a router is also configured for a VPN Client connection.

In order to resolve this issue, use the no-xauth keyword with the command crypto isakmp key if router-to-router IPsec is on the same crypto map as a VPN Client-to-Cisco-IOS IPsec. This keyword prevents the router from prompting the peer for Xauth information (username and password).

ciscoacs Mon, 11/12/2007 - 07:24
User Badges:

The site to site vpn has been setup between two firewalls would this cause the same issues as above?

andyjames Fri, 11/16/2007 - 07:49
User Badges:

It is quite normal for the first "interesting traffic" flow to timeout whilst the vpn session is esablished.

Try using a ping to bring the tunnel up, you will see the first 1 or 2 pings timeout and then succeed. If you try the telnet then it will work.


This Discussion