cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
368
Views
0
Helpful
1
Replies

unable to ping inside host L2L VPN..URGENT

somnath21
Level 1
Level 1

hi,

I have configured L2L von between ASA5520 and PIX525.Both end tunnel is active but unable to ping any inside host or peer IP.I have checked the access-list and its seems ok.

sh crypto isakmp sa (ASA550)

IKE Peer: x.x.x.x

Type : L2L Role : initiator

Rekey : no State : MM_ACTIVE

pdns1# sho crypto isakmp sa (PIX5525)

Total : 1

Embryonic : 0

dst src state pending created

x.x.x.x x.x.x.x QM_IDLE 0 1

Pls help me to slove the probllem

1 Reply 1

pdriscoll
Level 1
Level 1

I suspect you have a NAT issue. Are you bypassing NAT for tunnel traffic?

Run "show ipsec sa" and see if you are getting packets encrypt and de-crypt on both sides of the tunnel.

Patrick

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: