<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: vpn initialization from one endpoint only in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/vpn-initialization-from-one-endpoint-only/m-p/1155907#M957528</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is this tunnel created with cisco devices? Can you post configs of both sides?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 20 Feb 2009 20:07:34 GMT</pubDate>
    <dc:creator>Ivan Martinon</dc:creator>
    <dc:date>2009-02-20T20:07:34Z</dc:date>
    <item>
      <title>vpn initialization from one endpoint only</title>
      <link>https://community.cisco.com/t5/network-security/vpn-initialization-from-one-endpoint-only/m-p/1155906#M957524</link>
      <description>&lt;P&gt;We have a site to site vpn established, however to initiate the tunnel the remote endpoint has to ping our local endpoint for the tunnel to negotiate.  However,  I can not initiate the tunnel if it drops by pinging the remote end from the local end.  Any suggestions?  Would be much easier after a drop if I could re-initiate the tunnel here localy&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 11:18:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-initialization-from-one-endpoint-only/m-p/1155906#M957524</guid>
      <dc:creator>gmtimmons</dc:creator>
      <dc:date>2020-02-21T11:18:23Z</dc:date>
    </item>
    <item>
      <title>Re: vpn initialization from one endpoint only</title>
      <link>https://community.cisco.com/t5/network-security/vpn-initialization-from-one-endpoint-only/m-p/1155907#M957528</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is this tunnel created with cisco devices? Can you post configs of both sides?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 20 Feb 2009 20:07:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-initialization-from-one-endpoint-only/m-p/1155907#M957528</guid>
      <dc:creator>Ivan Martinon</dc:creator>
      <dc:date>2009-02-20T20:07:34Z</dc:date>
    </item>
    <item>
      <title>Re: vpn initialization from one endpoint only</title>
      <link>https://community.cisco.com/t5/network-security/vpn-initialization-from-one-endpoint-only/m-p/1155908#M957531</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Mark&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There are several things that I can think of that might result in the tunnel initiating from one end but not from the other. Do any of these apply to your situation:&lt;/P&gt;&lt;P&gt;- does your device have a dynamic crypto map entry? This allows connection from a peer whose address is learned dynamically (DHCP). And an implication of this is that the tunnel can only be initiated by the dynamic peer.&lt;/P&gt;&lt;P&gt;- does your peer VPN translate traffic so that their inside addresses are translated using the outside interface address? Depending on how the translation is configured it may only build a translation when they send traffic. If you try to initiate the tunnel there is no translation for the traffic.&lt;/P&gt;&lt;P&gt;- is it possible that there is a mismatch in the access lists which identify traffic for the VPN. Is it possible that their ping to you matches the access list but that your ping to them does not match your access list?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rick&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 20 Feb 2009 21:16:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-initialization-from-one-endpoint-only/m-p/1155908#M957531</guid>
      <dc:creator>Richard Burts</dc:creator>
      <dc:date>2009-02-20T21:16:07Z</dc:date>
    </item>
    <item>
      <title>Re: vpn initialization from one endpoint only</title>
      <link>https://community.cisco.com/t5/network-security/vpn-initialization-from-one-endpoint-only/m-p/1155909#M957532</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;"vpn initialization from one endpoint only"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is a well KNOWN issue if you have&lt;/P&gt;&lt;P&gt;site-2-site VPN between Cisco and other&lt;/P&gt;&lt;P&gt;VPN vendors such as Checkpoint and/or&lt;/P&gt;&lt;P&gt;Juniper devices.  The issue has to do with&lt;/P&gt;&lt;P&gt;encryption domain mis-match.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Checkpoint likes to "supernet" all the &lt;/P&gt;&lt;P&gt;network together and it is the default&lt;/P&gt;&lt;P&gt;setting where as Cisco does not do that.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The problem you described sound very &lt;/P&gt;&lt;P&gt;much like an encryption mis-match.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 21 Feb 2009 02:12:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-initialization-from-one-endpoint-only/m-p/1155909#M957532</guid>
      <dc:creator>cisco24x7</dc:creator>
      <dc:date>2009-02-21T02:12:44Z</dc:date>
    </item>
  </channel>
</rss>

