cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2435
Views
0
Helpful
9
Replies

Site-to-Site VPN Tunnel comes up but no traffic

mbroberson1
Level 3
Level 3

I am setting up a site to site VPN Cisco 3825 router to Sonic Wall Pro 4060 firewall. The VPN tunnel comes up great with no erros, but there are no encaps or decaps...just send and recieve errors when each end tries to establish connectivity. Any help would be greatly appreciated.

Thanks in advance.

9 Replies 9

jmia
Level 7
Level 7

Is your crypto ACL's setup correctly on the c3825? Can't comment on the SonicWall.

Jay

mbroberson1
Level 3
Level 3

Thanks for your reply. I feel the crypto ACL's on my side are correct. I'll have to see if I can get the remote Sonic Wall side config. Attached is a config from my lab that is very much like what I am using for the production setup.

Your side looks ok at first glance; take a read of the following document - I've used it in the past to sort out a similar issue - hope it helps.

Please rate posts if it helps!

Thanks for the info. So you think my side looks ok? Strange that it works in my lab Cisco to Cisco.

Brandon

I have not done the combination of VPN and static NAT that you are doing. From your comment am I correct in assuming that you have this set up in your lab and it is working correctly to translate and to protect with IPSec VPN?

I also wonder a little about your comment that the config that you posted is from a lab router that is very much like the production environment. It might be good to think carefully about what things are not exactly the same and whether any of these differences might be affecting things.

On the production router where it is not working are you getting hits on the ACL that identifies traffic for VPN (in the lab it is ACL 100)?

It might be helpful if you could post the output of show crypto map and the output of show crypto ipsec sa.

HTH

Rick

HTH

Rick

Rick,

Thanks for your reply. I just found what the issue was. I had to add my static route and am now getting encaps and decaps.

Brandon

I am glad that you have figured out what the issue was. Frequently it is the small things (like the static route - which seems un-important when you are addressing complex things like IPSec) that turn out to be the problem.

Congratulations on getting it working.

HTH

Rick

HTH

Rick

Rick,

The static nat with IPSec/VPN's works really well. It is only available with a fairly recent IOS version. I really comes in handy when you have an internal host that is accessed over several VPN's and you are nating on one of those VPN's and not the others.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: