Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

Lan-to-lan tunnel VPN3020 problem

I have a lan-to-lan tunnel between two sites working well but i have an intermitent problem when we connect more than one person from one site (VPN3020) to the same server in the other site (Checkpoint). The tunnel remains ok but there is no application traffic (in an intermitent way). I saw in the VPN logs that there is a continuous renegotiation of the phase 2 just when the problem appears (in the file attached). This log is repeted the same every second. The tunnel is ok in both sides and there is no problem when is used by only one person.

3 REPLIES

Re: Lan-to-lan tunnel VPN3020 problem

Silvestre,

Is the Network List you are using on the concentrator host based or subnet based? Also do you know if the Checkpoint is mirroring the ACL/Network List exactly? I have seen issues before in the past with Checkpoint if this isn't the case.

Please rate any helpful posts

Thanks

Fred

New Member

Re: Lan-to-lan tunnel VPN3020 problem

Hi Fred.

In my side (where the clients and Cisco Concentrator are) the network list is subnet based. In the remote side (servers and Checkpoint) the network list is host based. I?m trying to confirm with the other?s site technicians their Network Lists and checking the logs in their firewall. I?ll post again any new information.

Do you have any information about the Checkpoint problems you talk about?

Thanks.

Silvestre.

Re: Lan-to-lan tunnel VPN3020 problem

Silvestre,

Right there, that is more than likely your problem. The crypto ACLS/Network Lists should be mirrored on both sides. IPSec SA will be setup based on this ACLs and more than likely depending the direction of the flows you might be trying to use a SA that is valid on one end and not valid on the other. First and foremost try to mirror the network lists and see if that resolves your issue.

Please rate any helpful posts

Thanks

Fred

107
Views
0
Helpful
3
Replies