Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
Community Member

IPSEC site-to-site Question

Hi!

We are getting this:

IPSEC: Completed outbound permit rule, SPI 0xEE01F27D    Rule ID: 0xCC8CDEE0 IPSEC: No user rule added. No intersection between destination source networks (172.18.0.0/255.255.0.0) and (172.30.20.0/255.255.255.0). IPSEC: New outbound user deny rule, SPI 0xEE01F27D

IPSEC: New outbound user implicit deny rule, SPI 0xEE01F27D

It's denying traffic on the SA. What does it mean when it says No intersection between destination source networks? Any help is greatly appreciated!

1 REPLY

Re: IPSEC site-to-site Question

Hi,

Did you configure any kind of auth-proxy on the device for outgoing traffic?

If so check if the contents of the auth-proxy ACL doesn't conflict with crypto ACL

287
Views
0
Helpful
1
Replies
CreatePlease to create content