cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1220
Views
0
Helpful
3
Replies

Crypto Access-list is not fully utilizing in site-to-site VPN

kashifglobal12
Level 1
Level 1

Dear Concern,

 

I am using access-list containing Source ip 192.168.101.8 and 101.43 and Destination Ip 192.168.102.93. In phase 2 what i am seeing is that phase 2 tunnel is established only between 192.168.101.8 and 192.168.102.93 and not between  192.168.101.43 and 192.18.102.93.

 

Kindly help.

3 Replies 3

Marvin Rhoads
Hall of Fame
Hall of Fame

Have you presented the VPN device with interesting traffic from the unused address pairs? An IPsec security association will only be formed (and kept up) in the event of interesting traffic.

Have you presented the VPN device with interesting traffic from the unused
address pairs? Sir didn't get you... I have configured same interesting
traffic on both sides....

When we say "interesting traffic" we mean actual packets flowing  on the network from the defined source address(es) to the defined destination address(es).

Review Cisco Networking for a $25 gift card