Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

Can the VPN3000 initiate a LAN-to-LAN tunnel?

I have a VPN3000 (ver 3.5) at the hub site with PIX 501's deployed remotely. Remote sites can bring up a tunnel without any problem. Once the tunnel is up traffic can be initiated by either side and there's full connectivity.

When the tunnel drops only traffic from the remote site can bring it back up. With PIX's or routers it doesn't matter where the traffic starts from but the VPN3k seems to care. This seems like basic functionality to me so I can't believe it doesn't do it. What's the secret?


Cisco Employee

Re: Can the VPN3000 initiate a LAN-to-LAN tunnel?

Make sure your ACL's (or local and remote networks in the 3000) are the exact opposite of each other. Then make sure your Phase 1 lifetime is the same on all devices (check what IKE Proposal the L2L tunnel is using, then check the lifetime for that proposal under the IKE Proposals section).

Other than that, clear the log on the 3000, try and bring up the tunnel and see what it says. If you enable the IKE, IKEDBG, IPSEC and IPSECDBG event classes at Severity to Log of 1-13, then you'll get a bunch more info, feel free to paste it back in here and we can check it out.