Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 

IPSec Site To Site VPN

crypto isakmp policy 10
encr 3des

hash md5
authentication pre-share
group 2
crypto isakmp key XXX address

// set your key insted of XXX and it must match with your remote site. after that write address of your peer
crypto isakmp invalid-spi-recovery
crypto ipsec transform-set XXX esp-3des esp-md5-hmac
crypto map YYY  local-address <<<FastEthernet0/0 your local int>>>
crypto map YYY 10 ipsec-isakmp
set peer
set transform-set ZZZ
match address 101

interface <<<FastEthernet0/ your public int>>>
crypto map YYYY

access-list 101 permit ip (Remote user)
access-list 101 permit ip user)

After that configure NAT with req. access-list

For troubleshooting

sh cry ipsec sa peer

sh cry session

hope your IPSec site to site VPN tunnel is working fine

Version history
Revision #:
1 of 1
Last update:
‎01-01-2013 01:09 AM
Updated by:
Labels (1)
Everyone's tags (2)