Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

VPN up but can't access remote network

Hi everyone,

I have established a L2L VPN between my Cisco 851 and the remote sites Watchguard. The tunnel comes up fine. From the local side I can ping the remote host only if I set the source address of the packets to the routers vlan1 address. From the remote side I can ping the routers vlan1 address but I can't get pass the router to any of my local devices. I have been over and over my acl's for standard access, ipsec, and nat and all looks well. Anyone have any suggestions?


Re: VPN up but can't access remote network

How about routing? Do all devices on 851 side know how to reach the Watchguard side via 851 router?

You can check encry/decry counter in "show crypto ipsec sa" to see which one is not incrementing.

New Member

Re: VPN up but can't access remote network

Routing is the problem. I added a route to a windows computer and I was then able to ping the remote network. However, I attempted to add the route to the cisco 851 and it doesn't seem to make a difference. Any suggestions?

Re: VPN up but can't access remote network

851 just need routes to its all local networks and the route to the remote network.

Can you post your config here and let me know which remote IP network you wound like to access?