cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
434
Views
0
Helpful
2
Replies

vpn site-to-stie w/wpn clients

jestoner7
Level 1
Level 1

I inherited an issue with a site-to-site vpn connection. It's looks like below w/nat being done on r1 for the pix. The vpn clients can connect but the site-to-site won't come up. To compound the issue R1 has two internet connections so policy routing is being used. Any assistance would be greatly appreciated.

Pix--R1--Internet--R2--checkpt

I've attached pix, router, and isakmp debug.

thanks.

Josh

2 Replies 2

ajagadee
Cisco Employee
Cisco Employee

I see that the isakmp gets stuck in the below state, which could be something to do with the PSK>

69.25.174.245 172.16.200.1 MM_KEY_EXCH

Can you make sure that the preshared key is matching on both the sides.

Regards,

Arul

** Please rate all helpful posts **

thanks Arul, the keys do match. The tunnel works when I take out the nat-traversal command, but when added back the far end still see me trying port 4500 to connect.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: