cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
373
Views
0
Helpful
2
Replies

site to site and remote access inpix 515e

shajil
Level 1
Level 1

i have pix 515e configured with remote access connection,it is working fine.,now there is requirement to configure site to site connection also, but once i configure crypto map for the site to site ,and try to connect using remote access ,am able to connect but not able to ping the internal network,the crypto map for static is of lower number ,am attaching the config,please advise me,i have to remove the config for crypto map site to site ,so that the remote access works fine again.

please advise me how to configure pix to have both site to site and remot acces,

it is pix 515e with pix ios 6.3(5)

2 Replies 2

Patrick0711
Level 3
Level 3

The nat-exempt access-list (102) is also referenced by the crypto map.

You must specify a separate access-list for your site-to-site VPN encryption domain.

thanks so much for the reply,now site to site confgiured between site a and b,when try to ping tunnel getting up,but no ping replies,i see packets get encrypted in show ipsec sa,am attaching the configs please verify and advise what is the problem