cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
560
Views
0
Helpful
2
Replies

How do i start VPN l2l initialization?

cisco_himg
Level 1
Level 1

hey there!

I have two PIX501e and trying to set up a LAN2LAN. i have all the settings in place, but for some reason its not negotioating the connection. Is there an enable command to negotiate? i have crypto enabled on both outside interfaces

1 Accepted Solution

Accepted Solutions

busterswt
Level 1
Level 1

You need to initiate traffic from one end to the other in order for the tunnel to build. The traffic you need to generate is defined within the encryption domain. So, if you're tunneling traffic using RFC1918 IPs (ie. 192.168.x.x), be sure to ping that IP and not the public (or vice-versa).

The encryption domain defines 'interesting traffic', or traffic that the firewall determines should be passed over the tunnel and not through the Internet (or any other interface).

James

View solution in original post

2 Replies 2

busterswt
Level 1
Level 1

You need to initiate traffic from one end to the other in order for the tunnel to build. The traffic you need to generate is defined within the encryption domain. So, if you're tunneling traffic using RFC1918 IPs (ie. 192.168.x.x), be sure to ping that IP and not the public (or vice-versa).

The encryption domain defines 'interesting traffic', or traffic that the firewall determines should be passed over the tunnel and not through the Internet (or any other interface).

James

You are right!

Funny thing i was pinging the other device and still nothing, however, when i started AT the other device and pinged me, the tunnel came right up. i guess i was pinging from the wrong side

thank you again!

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: