<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VPN tunnel will only intiate from one end in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/vpn-tunnel-will-only-intiate-from-one-end/m-p/877487#M955613</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Martin&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In my experience there are several things that can result in the symptom that the tunnel can initiate from one end but not from the other:&lt;/P&gt;&lt;P&gt;- it may be that one end has a dynamically learned (and subject to change) IP address and the other end is configured to accept connection requests from any address and authenticate to determine if it is a legitimate peer. In this situation the peer with the dynamic address can initiate the tunnel but not the other peer.&lt;/P&gt;&lt;P&gt;- it may be that there is a mismatch between the peers about what is interesting traffic which can initiate the tunnel (perhaps echo request or echo response is included on one but not on the other).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you get to phase 2 and fail I suspect it is the mismatch issue. Perhaps you can post the appropriate sections of both configs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rick&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 04 Feb 2008 12:53:03 GMT</pubDate>
    <dc:creator>Richard Burts</dc:creator>
    <dc:date>2008-02-04T12:53:03Z</dc:date>
    <item>
      <title>VPN tunnel will only intiate from one end</title>
      <link>https://community.cisco.com/t5/network-security/vpn-tunnel-will-only-intiate-from-one-end/m-p/877486#M955612</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a lan to lan VPN setup with 2 cisco pix 515e.  One of the firewalls is in the uk and the other is in France.  I can intiate the tunnel from France by pinging an IP address in the UK.  If I ping France from the UK the tunnel fails at phase 2.  Any idea why this is?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Martin&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 11:58:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-tunnel-will-only-intiate-from-one-end/m-p/877486#M955612</guid>
      <dc:creator>lord_studley</dc:creator>
      <dc:date>2019-03-11T11:58:41Z</dc:date>
    </item>
    <item>
      <title>Re: VPN tunnel will only intiate from one end</title>
      <link>https://community.cisco.com/t5/network-security/vpn-tunnel-will-only-intiate-from-one-end/m-p/877487#M955613</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Martin&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In my experience there are several things that can result in the symptom that the tunnel can initiate from one end but not from the other:&lt;/P&gt;&lt;P&gt;- it may be that one end has a dynamically learned (and subject to change) IP address and the other end is configured to accept connection requests from any address and authenticate to determine if it is a legitimate peer. In this situation the peer with the dynamic address can initiate the tunnel but not the other peer.&lt;/P&gt;&lt;P&gt;- it may be that there is a mismatch between the peers about what is interesting traffic which can initiate the tunnel (perhaps echo request or echo response is included on one but not on the other).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you get to phase 2 and fail I suspect it is the mismatch issue. Perhaps you can post the appropriate sections of both configs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rick&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 04 Feb 2008 12:53:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-tunnel-will-only-intiate-from-one-end/m-p/877487#M955613</guid>
      <dc:creator>Richard Burts</dc:creator>
      <dc:date>2008-02-04T12:53:03Z</dc:date>
    </item>
    <item>
      <title>Re: VPN tunnel will only intiate from one end</title>
      <link>https://community.cisco.com/t5/network-security/vpn-tunnel-will-only-intiate-from-one-end/m-p/877488#M955614</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the information.  I can't get the configuration of the PIX in France as the tunnel is currently down.  That PIX has a DHCP address on it's outside interface but it is connected to an ADSL router that has a fixed external IP address.  That external address is the address the PIX in the UK looks for as a peer.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Would the DHCP outside interface make a difference?   &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Feb 2008 09:39:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-tunnel-will-only-intiate-from-one-end/m-p/877488#M955614</guid>
      <dc:creator>lord_studley</dc:creator>
      <dc:date>2008-02-05T09:39:40Z</dc:date>
    </item>
    <item>
      <title>Re: VPN tunnel will only intiate from one end</title>
      <link>https://community.cisco.com/t5/network-security/vpn-tunnel-will-only-intiate-from-one-end/m-p/877489#M955615</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Martin&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you can not get to the config of the PIX in France, then the config of the PIX in the UK would be a good starting point.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am having some difficulty in getting my head around how it would work for a PIX to have a DHCP address on its outside interface and to configure peering using the fixed address of the ADSL router. But I am wondering if this falls into the category that I described as one side has a dynamic address.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rick&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Feb 2008 05:03:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-tunnel-will-only-intiate-from-one-end/m-p/877489#M955615</guid>
      <dc:creator>Richard Burts</dc:creator>
      <dc:date>2008-02-07T05:03:58Z</dc:date>
    </item>
  </channel>
</rss>

