Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Community Member

Easy VPN server compatible with VPN between routers?

Hi I have a router 837 that have to be a Easy VPN server for software clients and too do a VPN with other router, but I see that only works the VPN with the other router.

This is the configuration of the router:

barcelona#sh run

Building configuration...

Current configuration : 3106 bytes

!

version 12.2

no service pad

hostname barcelona

!

boot system flash c837-k9o3y6-mz.123-2.T1.bin

logging queue-limit 100

!

aaa new-model

!

!

aaa authentication login vpnusers local

aaa authorization network barcelona local

aaa session-id common

ip subnet-zero

ip domain name barcelona.es

ip host girona x.x.10.16

!

!

ip audit notify log

ip audit po max-events 100

no ftp-server write-enable

!

crypto isakmp policy 10

encr 3des

hash md5

authentication pre-share

group 2

!

crypto isakmp policy 20

hash md5

authentication pre-share

group 2

crypto isakmp key 0 aba address x.x.10.16 no-xauth

crypto isakmp identity hostname

crypto isakmp client configuration address-pool local mipool

crypto isakmp xauth timeout 60

!

crypto isakmp client configuration group barcelona

domain barcelona.es

pool mipool

acl 150

!

!

crypto ipsec transform-set mitrans esp-3des esp-md5-hmac

!

crypto dynamic-map mapadinamico 10

set transform-set mitrans

reverse-route

!

!

crypto map mimapa client authentication list vpnusers

crypto map mimapa isakmp authorization list barcelona

crypto map mimapa client configuration address respond

crypto map mimapa 20 ipsec-isakmp

set peer x.x.10.16

set transform-set mitrans

match address 102

crypto map mimapa 30 ipsec-isakmp dynamic mapadinamico

!

interface Ethernet0

ip address 192.168.201.246 255.255.255.0

ip nat inside

hold-queue 100 out

!

interface ATM0

no ip address

no atm ilmi-keepalive

dsl operating-mode auto

!

interface ATM0.1 point-to-point

ip address x.x.x.22 255.255.255.192

ip nat outside

pvc 8/32

encapsulation aal5snap

!

crypto map mimapa

!

ip local pool mipool 192.168.201.100 192.168.201.105

ip nat inside source route-map nonat interface ATM0.1 overload

ip classless

ip route 0.0.0.0 0.0.0.0 ATM0.1

ip route 192.168.200.0 255.255.255.0 23.98.10.16

ip http server

no ip http secure-server

!

access-list 102 permit ip 192.168.201.0 0.0.0.255 192.168.200.0 0.0.0.255

access-list 110 deny ip 192.168.201.0 0.0.0.255 192.168.200.0 0.0.0.255

access-list 110 permit ip 192.168.201.0 0.0.0.255 any

access-list 150 permit ip 192.168.201.0 0.0.0.255 any

route-map nonat permit 10

match ip address 110

!

radius-server authorization permit missing Service-Type

!

scheduler max-task-time 5000

!

end

Can anybody help me please?

1 REPLY
Community Member

Re: Easy VPN server compatible with VPN between routers?

Most of the times, this kinda problems has got to do with access-list. Plsease check your ACL again.

227
Views
0
Helpful
1
Replies
CreatePlease to create content