cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1628
Views
0
Helpful
4
Replies

Issues with IPSec VPN in Packet Tracer

Sam-N
Level 1
Level 1

Hello there (again)

 

Today, I've been configuring IPSec VPN over two LANs (Cafe and ACME), however upon testing (Ping and PDU) I am unable to contact hosts on each LAN. As far as I think, the configuration is correct, the default gateway is configured and extended ACLs in place. I jumped into it with little awareness/insight, so I probably have made a mistake somewhere but I'm not entirely sure. I have attached the .pkt in the latest PT version.

 

Thanks.

1 Accepted Solution

Accepted Solutions

Hello,

 

the file I sent you doesn't work. I think there is a flaw in Packet Tracer where only networks directly connected to the router are encrypted. To demonstrate this (file attached), I have added another network directly to the Cafe router, and changed the VPN access list to encrypt that traffic, and it works right away.

 

Is this a project, with actual requirements, or did you come up with this topology yourself ?

View solution in original post

4 Replies 4

Hello,

 

a few things were misconfigured:

 

1. The VPN access list specified 192.168.0.0/24, that has to be 192.168.0.0/16 (in order to include all networks on the 192 side)

2. The cable between the router and the wireless router needs to be a cross cable

3. (Static) routes to the 20.x.x.x/30 networks were missing

4. The isakmp policy was incomplete

 

Attached the working file (saved in version 7.3.1).

 

 

Hello,

 

the file I sent you doesn't work. I think there is a flaw in Packet Tracer where only networks directly connected to the router are encrypted. To demonstrate this (file attached), I have added another network directly to the Cafe router, and changed the VPN access list to encrypt that traffic, and it works right away.

 

Is this a project, with actual requirements, or did you come up with this topology yourself ?

Thanks for your help Georg. This is a project that I'm working on myself, self teaching myself and being creative. I'm currently on my phone, so I haven't seen the pkt file yet. I'll look at it when I next get a chance.

I looked at the pka you sent across. Thanks for that Georg. Until I get my hands on some actual Cisco equipment, I'll stick with your solution.