cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
263
Views
0
Helpful
4
Replies

PIX to PIX VPN trouble

esquared1
Level 1
Level 1

I pretty much copied these from a working config. However I am unable to create a tunnel between these 2 sites.

sh crypto ipsec sa

gives me no activity on either side.

VPN lights are off on both PIX's

I know i have some excess ACL's that dont do anything at the moment, but I am confused as to why this VPN isnt working.

I have attached the Primary site and Remote site configs.

Any help would be appreciated!

4 Replies 4

ajagadee
Cisco Employee
Cisco Employee

What is the source and destination IP Addresses that you are initiating traffic. Also, can you post the outputs of "deb cry is" and "deb cry ipsec" from the pixes when you try and bring up the tunnel.

Thanks,

Arul

esquared1
Level 1
Level 1

I could really use some help here. I am at a loss as to what to do next.. Thanks!

Can you do a show logging and see if logging is enabled on the pix to capture the debug outputs.

If console logging is disabled, then enable it by;

logging console debugging

logging on

and then see if you are seeing any debugs on the pix.

Regards,

Arul

Please verify your ACL's are correct, both for you cryptomaps and your nat 0 statements on both firewalls.

Make sure preshared keys match, and the peers are correct for both sides.

If you have verified all of these things, then please do the aforementioned debugging.

Are the outside interface IP's being nat'ed to anything? ie, is there a NAT device somewhere between the PIXes?

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: