08-24-2008 07:18 AM - edited 03-03-2019 11:14 PM
I have configured the Crypto IPSEC VPN Tunnel in Cisco 2600 but the phase 1 is not established I am sure configuration is correct .. please any one help.
Note : Internet is woeking fine.
08-24-2008 07:50 AM
Hi Thiru
Can you post the config of the router ???
regds
08-24-2008 10:47 AM
Thiru
If you are sure that the configuration of your router is correct there are a couple of other possibilities that you should check:
- is it possible that you do not have correct IP connectivity from the IP address that is the source of your IPSec VPN to the address of the remote peer?
- is it possible that the peer is not configured correctly?
- is it possible that some device (firewall etc) in between your router and your peer is filter and is denying your VPN ISAKMP traffic?
The output of debug for ISAKMP negotiation would help to determine what kind of problem it might be.
HTH
Rick
08-24-2008 01:16 PM
you might wanna look again on these:
* matching IKE policies on both local and remote devices
* check ACL if udp port 500 (IKE), ip ports 50 (ESP) and 51 (AH) are permited
* issue debug crypto isakmp sa and see if phase 1 and 2 are established
08-24-2008 06:09 PM
HI All,
I have upgrade the IOS verson.
to c2600-advsecurityk9-mz.124-15.T6.bin. now the Crypto tunnels are up and running Fine. All for response
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide