Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Community Member

Problem with IPSEC/GRE tunneling with NAT-T

I am in the midst of deploying between 25-40 871s to users@home, they are building tunnels to 2 2811s in different locations with active routing.

I am running into issues when the users put the 871s behind their home equipment which is handing out 192.168.1.x addresses. This all works fine until 2 users have been given the same 192.168.1.x address. When this happens the Crypto mapdb already has an entry for the destination address, so IPSEC is invalidating the proposal with a "peer address not found.

Does anyone know a way around this problem?

1 REPLY
Silver

Re: Problem with IPSEC/GRE tunneling with NAT-T

Many reasons there . one is IPSec policy invalidated proposal another one is SA policy not acceptable

Better solution is clear SA's from both routers and test the connection again.

156
Views
0
Helpful
1
Replies
CreatePlease to create content