VPN Troubleshooting Report Details



Router Details

Attribute Value
Router Model 1811W
Image Name c181x-advipservicesk9-mz.124-6.T7.bin
IOS Version 12.4(6)T7
Hostname frontgate3


Test Activity Summary

Activity Status
Checking the tunnel status... Down
Checking interface status... Successful
Checking the configuration... Successful
Checking Routing... Successful
Checking peer connectivity... Successful
Checking NAT... Successful
Checking Firewall... Successful
Debugging the VPN connection ... Completed
Checking the tunnel status... Down


Test Activity Details

Activity Status
Checking the tunnel status... Down
    Encapsulation :0
    Decapsulation :0
    Send Error :0
    Received Error :0
Checking interface status... Successful
    Interface :FastEthernet0
    Interface physical status :Up
    Line protocol status :Up
Checking the configuration... Successful
    Checking IPSec
    Crypto map name : SDM_CMAP_1
    Sequence number : 1
    Crypto map type : Static
    Peer : Configured
    Transform set : Configured
    Interesting traffic : Configured
    IPSec configuration status : Valid
    Checking IKE
    IKE Policies : Configured
    Policies with pre shared key authentication method : Configured
    Global pre shared key with wild cards : Not configured
    Pre-shared key for 64.37.198.169 Configured
    IKE configuration status : Valid
Checking Routing... Successful
    Peer :64.37.198.169:Valid(Routed through the crypto interface)
    Traffic source :67.69.27.154:Invalid(Routed through the crypto interface)
    Traffic destination :64.37.249.63:Valid(Routed through the crypto interface)
Checking peer connectivity... Successful
    Peer :64.37.198.169:Successful
Checking NAT... Successful
Checking Firewall... Successful
Debugging the VPN connection ... Completed
    Peer :64.37.198.169
    Received IKE response from the peer
    Phase one completed
Checking the tunnel status... Down
    Encapsulation :0
    Decapsulation :0
    Send Error :30
    Received Error :0


Troubleshooting Results
Failure Reason(s) Recommended Action(s)
NAT is configured on the interface and VPN traffic is not protected from NAT translation. To protect the VPN traffic on this interface from NAT translation, click the link below:
The following source(s) are routed through the crypto map interface. 1) 67.69.27.154 Go to 'Configure->Routing' and correct the routing table.
There is response from the peer 64.37.198.169 but the tunnel is not up. Ensure that the peer device is configured properly. Generate the mirror configuration from 'Configure->VPN->Site to site VPN->Edit Site to Site VPN' and match it with the peer configuration.
The following source(s) are routed through the crypto map interface. 1) 67.69.27.154 Go to 'Configure->Routing' and correct the routing table.