12-29-2020 10:58 AM
Hello there (again)
Today, I've been configuring IPSec VPN over two LANs (Cafe and ACME), however upon testing (Ping and PDU) I am unable to contact hosts on each LAN. As far as I think, the configuration is correct, the default gateway is configured and extended ACLs in place. I jumped into it with little awareness/insight, so I probably have made a mistake somewhere but I'm not entirely sure. I have attached the .pkt in the latest PT version.
Thanks.
Solved! Go to Solution.
12-29-2020 03:51 PM
Hello,
the file I sent you doesn't work. I think there is a flaw in Packet Tracer where only networks directly connected to the router are encrypted. To demonstrate this (file attached), I have added another network directly to the Cafe router, and changed the VPN access list to encrypt that traffic, and it works right away.
Is this a project, with actual requirements, or did you come up with this topology yourself ?
12-29-2020 01:14 PM
Hello,
a few things were misconfigured:
1. The VPN access list specified 192.168.0.0/24, that has to be 192.168.0.0/16 (in order to include all networks on the 192 side)
2. The cable between the router and the wireless router needs to be a cross cable
3. (Static) routes to the 20.x.x.x/30 networks were missing
4. The isakmp policy was incomplete
Attached the working file (saved in version 7.3.1).
12-29-2020 03:51 PM
Hello,
the file I sent you doesn't work. I think there is a flaw in Packet Tracer where only networks directly connected to the router are encrypted. To demonstrate this (file attached), I have added another network directly to the Cafe router, and changed the VPN access list to encrypt that traffic, and it works right away.
Is this a project, with actual requirements, or did you come up with this topology yourself ?
12-29-2020 04:01 PM
Thanks for your help Georg. This is a project that I'm working on myself, self teaching myself and being creative. I'm currently on my phone, so I haven't seen the pkt file yet. I'll look at it when I next get a chance.
12-30-2020 05:52 AM
I looked at the pka you sent across. Thanks for that Georg. Until I get my hands on some actual Cisco equipment, I'll stick with your solution.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide