archive command won't work from spoke VPN router

Answered Question
Oct 6th, 2008
User Badges:

Central site has 3845 and spoke site a 2811 and they have an IPsec tunnel between them. Say central site LAN 10.10.1.0/24 and remote site LAN 10.10.2.0/24. RTR address central 10.10.1.1 and remote 10.10.2.1. I ran packet level debug and I see that when the archive with tftp command is run - the source address winds up being the WAN interface IP rather than the LAN. So the traffic does not get processed by the crypto map. Is there any way that to get the archive command to work from a spoke site whose only connectivity is via IPsec tunnel?

Correct Answer by Edison Ortiz about 8 years 6 months ago

If the router is acting as a TFTP client, you can set the source interface with:


ip tftp source-interface [interface_name]



This command will change the behavior to use the closest interface to the destination network.


HTH,


__


Edison.

  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 5 (2 ratings)
Loading.
Correct Answer
Edison Ortiz Mon, 10/06/2008 - 13:32
User Badges:
  • Super Bronze, 10000 points or more
  • Hall of Fame,

    Founding Member

If the router is acting as a TFTP client, you can set the source interface with:


ip tftp source-interface [interface_name]



This command will change the behavior to use the closest interface to the destination network.


HTH,


__


Edison.

mmedwid Mon, 10/06/2008 - 13:36
User Badges:

Edison - thanks a million! The archiving now works perfectly from all my sites. Awesome.

Actions

This Discussion