cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
278
Views
0
Helpful
2
Replies

VPN public IP & ACL

mwwg
Level 1
Level 1

i have c1841, with 2 ipsec tunnels to other sites, do i need to put the peer site public iP into my ACL & ios firewall to allow routing between all 3 sites (hub & both spoke)?

pinging the LAN ip of the other spoke site from hub router CLI fails, & same on the spoke sites, what could be wrong or missing

thanks

2 Replies 2

spremkumar
Level 9
Level 9

Hi

Can you post the configs of your hub site and the remote locations ?

So that they can be verified and suggestions can be made ?

regds

grant.maynard
Level 4
Level 4

Any ACL on internet-facing interface must allow UDP500 and ESP between the VPN peers.

In old IOS versions you must also allow the unencrypted traffic too.