Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements
Step-by-Step Configuration and Troubleshooting Best Practices for the NGFW, NGIPS and AMP Technologies A Visual Guide to the Cisco Firepower Threat Defense (FTD)
Community Member

two VPNs into a PIX from two routers that share the same branch LAN?

does anyone know if its possible to have two routers at a remote branch (one primary, the other backup with HSRP) connecting back via IPsec VPN's to a Head office PIX 515E with ver6.3.5.

When I lab the scenario, the pix seems to get confused in fail-over scenarios and I need to clear the vpns (clear crypto sa) on the routers to make the vpns come back up. thoughts?

the pix has the two routers as peers under the one crypto map:

access-list vpn400 permit ip 172.21.0.0 255.255.0.0 10.86.200.0 255.255.255.0

crypto ipsec transform-set avalanche esp-des esp-md5-hmac

crypto map forsberg 21 ipsec-isakmp

crypto map forsberg 21 match address vpn400

crypto map forsberg 21 set peer 221.133.231.6

crypto map forsberg 21 set peer 100.0.0.2

crypto map forsberg 21 set transform-set avalanche

crypto map forsberg 21 set security-association lifetime seconds 3600 kilobytes 4608000

crypto map forsberg interface outside

i

sakmp enable outside

isakmp key ******** address 221.133.231.6 netmask 255.255.255.255

isakmp key ******** address 100.0.0.2 netmask 255.255.255.255

1 REPLY

Re: two VPNs into a PIX from two routers that share the same bra

on routers you should enable RRI

on PIX and routers try to enable "crypto isakmp keepalive"

106
Views
0
Helpful
1
Replies
CreatePlease to create content