cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
287
Views
0
Helpful
2
Replies

One way traffic on PIX VPN

bbohan
Level 1
Level 1

I have a VPN tunnel between a 3000 Concentrator and a PIX 501. The users at the remote office and get out to the Internet, the tunnel comes up but there is only oneway traffic. The Concentrator is sending, encrypting packets but not receiving them from the PIX. On a "show crypto ipsec sa" command on the PIX, it receives and decrypts the packets but is not sending or encrypting packets. Is this a routing issue?

2 Replies 2

xiaoj
Level 1
Level 1

Most of time it's caused by mismatching ACL, or it be a problem when you have more routes to get to the remote side.

We located the problem. I had someone who was on site put in the command "nat (inside) 0 access-list 101" but he made a typo. Once he corrected the command, the traffic was flowing over the tunnel.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: