Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

Site-to-Site VPN Tunnel comes up but no traffic

I am setting up a site to site VPN Cisco 3825 router to Sonic Wall Pro 4060 firewall. The VPN tunnel comes up great with no erros, but there are no encaps or decaps...just send and recieve errors when each end tries to establish connectivity. Any help would be greatly appreciated.

Thanks in advance.

9 REPLIES
Gold

Re: Site-to-Site VPN Tunnel comes up but no traffic

Is your crypto ACL's setup correctly on the c3825? Can't comment on the SonicWall.

Jay

Gold

Re: Site-to-Site VPN Tunnel comes up but no traffic

New Member

Re: Site-to-Site VPN Tunnel comes up but no traffic

Thanks for your reply. I feel the crypto ACL's on my side are correct. I'll have to see if I can get the remote Sonic Wall side config. Attached is a config from my lab that is very much like what I am using for the production setup.

Gold

Re: Site-to-Site VPN Tunnel comes up but no traffic

Your side looks ok at first glance; take a read of the following document - I've used it in the past to sort out a similar issue - hope it helps.

Please rate posts if it helps!

New Member

Re: Site-to-Site VPN Tunnel comes up but no traffic

Thanks for the info. So you think my side looks ok? Strange that it works in my lab Cisco to Cisco.

Hall of Fame Super Silver

Re: Site-to-Site VPN Tunnel comes up but no traffic

Brandon

I have not done the combination of VPN and static NAT that you are doing. From your comment am I correct in assuming that you have this set up in your lab and it is working correctly to translate and to protect with IPSec VPN?

I also wonder a little about your comment that the config that you posted is from a lab router that is very much like the production environment. It might be good to think carefully about what things are not exactly the same and whether any of these differences might be affecting things.

On the production router where it is not working are you getting hits on the ACL that identifies traffic for VPN (in the lab it is ACL 100)?

It might be helpful if you could post the output of show crypto map and the output of show crypto ipsec sa.

HTH

Rick

New Member

Re: Site-to-Site VPN Tunnel comes up but no traffic

Rick,

Thanks for your reply. I just found what the issue was. I had to add my static route and am now getting encaps and decaps.

Hall of Fame Super Silver

Re: Site-to-Site VPN Tunnel comes up but no traffic

Brandon

I am glad that you have figured out what the issue was. Frequently it is the small things (like the static route - which seems un-important when you are addressing complex things like IPSec) that turn out to be the problem.

Congratulations on getting it working.

HTH

Rick

New Member

Re: Site-to-Site VPN Tunnel comes up but no traffic

Rick,

The static nat with IPSec/VPN's works really well. It is only available with a fairly recent IOS version. I really comes in handy when you have an internal host that is accessed over several VPN's and you are nating on one of those VPN's and not the others.

1857
Views
0
Helpful
9
Replies