cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
508
Views
0
Helpful
2
Replies

Site to Site VPN Config

rbdrake22
Level 1
Level 1

I'm having a problem where I can only ping certain IP addresses across the VPN tunnel. I can ping most of them but not all, the CCP has added a whole bunch of duplicate configuration and I suspect that may be part of the cause. Attached is the router1 and router2 configs. Do these configs look okay?

2 Replies 2

p.krane
Level 3
Level 3

If the PIX/ASA is in router mode, some types of traffic cannot pass through the security appliance even if you allow it in an access list. This link as an example LAN-to-LAN configuration:

http://www.cisco.com/en/US/docs/security/asa/asa80/configuration/guide/site2sit.html#wp1042205

Ryan

I have looked at the router configs that you posted. The VPN part of them looks ok. I agree that the repeated parts of the config are strange, but do not think that they produce the problem. I did not look very hard at the zone based firewall stuff but in a quick look I do not see anything that would produce the symptom that you describe.

Are you attempting to ping from the router or to ping from a device on the LAN? (note that only traffic from the LAN will be processed by IPSec) Can you tell us a bit more about the problem? How many devices are you not able to ping? If you attempt to ping from another device do you get the same results? Is it possible that some of the remote devices have firewalls activated and that is why you can not ping them?

HTH

Rick

HTH

Rick
Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card