Re: IPSec VPN - Interesting traffic only trigger crypto map

From: Ubaid Iftikhar <magmax_at_bigpond.net.au>
Date: Thu, 23 Jul 2009 17:58:24 +1000

Please post your config + $300 per hour with minimum of 4 hours charge

LOL just kidding

crypto isamp identity
Check crypto config
Route to remote subnet other than default route
Run packet-tracer command
Show asp drop
Check NAT
acl bypass with sysopt connection permit vpn command
Ensure intresting traffic acl doesn't overlap with other crypto (one
with lower sequence number)

If still no luck post config and packet-tracer command output

Regards,
Ubaid

Sent from my iPhone

On 23/07/2009, at 1:20 PM, Dale Shaw <dale.shaw_at_gmail.com> wrote:

> Hi,
>
> 2009/7/23 Teu Kim Loon e<5i &e+ <kim.teu_at_gmail.com>:
>> IPSec VPN between ASA 8.0 and PIX 6.3. B I verified identical IKE
>> and IPSec
>> configuration on both ends. B However, I am only able to initiate
>> connection
>> from ASA.
>>
>> Any idea why?
>
> Please provide the relevant configs from each side. You'll get a much
> better response if you include the detail that people need to help
> you.
>
> Without this detail, your query will often fall into the 'too hard'
> basket, and you'll get no responses.
>
> cheers,
> Dale

Blogs and organic groups at http://www.ccie.net
Received on Thu Jul 23 2009 - 17:58:24 ART

This archive was generated by hypermail 2.2.0 : Sat Aug 01 2009 - 13:10:23 ART