cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
418
Views
0
Helpful
6
Replies

unable to get site - to site VPN Up

p.holley
Level 1
Level 1

i have two PIX runing version 6.3(3) and 7.1(1). Following is my topology and attached config showing running configuration and debugs.

(PC)172.16.10.10/24<-->172.16.10.1/24-PIX(6.3)--1.1.1.2/30---WAN(X-Over cable)---1.1.1.1/30--PIX(7.1)--10.10.10.1/24<--->10.10.10.10/24(PC)

What am i missing?

Thanks

1 Accepted Solution

Accepted Solutions

elparis
Cisco Employee
Cisco Employee

By the way, this is the only thing that catches my attention from the 6.3 debugs you provided:

ISAKMP (0): SA is doing pre-shared key authentication using id type ID_FQDN

One thing you can try is to set the ISAKMP identities on both sides:

isakmp identity address (on the 6.3 side)

cry isakmp identity address (on the 7.x side)

View solution in original post

6 Replies 6

elparis
Cisco Employee
Cisco Employee

Hello,

I don't see anything wrong with the configuration. Nothing seems to be missing.

Could you you enable ISAKMP and IPsec debugging on the 7.x side (debug cry isakmp 128 and debug cry ipsec 128) to get more information of where the IPsec tunnel establishment is failing?

change the pre-shared key on both ends to something simple and try it again.

I don't see that phase 1 is even completing.

I was using ciscocisco as pre-shared key

elparis
Cisco Employee
Cisco Employee

By the way, this is the only thing that catches my attention from the 6.3 debugs you provided:

ISAKMP (0): SA is doing pre-shared key authentication using id type ID_FQDN

One thing you can try is to set the ISAKMP identities on both sides:

isakmp identity address (on the 6.3 side)

cry isakmp identity address (on the 7.x side)

Entering the following commands solved it:

isakmp identity address (on the 6.3 side)

cry isakmp identity address (on the 7.x side)

Thanks

Awesome, glad to see it worked.

Cheers,

Eloy Paris.-

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: