cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1558
Views
5
Helpful
1
Replies

Firewall Exceptions for Site to Site IPSec VPN Connection

ThomtheBomb!
Level 1
Level 1

Hello community,

 

I am trying to setup a site to site IPSec VPN tunnel using two Cisco RV340 routers. I have followed the instructions in this link from Cisco: Configure a Site-to-Site Virtual Private Network (VPN) Connection on an RV340 or RV345 Router - Cisco, but their documentation doesn't include any details about how to create the firewall exceptions for this connection and I cannot get the tunnel to work. I have IKEv1 profiles with the strongest encryption available set on both routers identically, and following all other steps in the documentation to the letter. I am using the public IP addresses for the remote and local identifiers (swapping them appropriately for the alternating config) and then using local subnets defined for each respective location. Example local subnets would be 192.168.1.1/24 on one side and 10.0.0.1/27 on the other side. I would like the 192 subnet to access one IP address in the 10. subnet, for example 10.0.0.2. I believe the issue in my config is the firewall rules. I opened IP ports 50/51 bi-directionally on both routers as well as port 500 on both routers. I have no forwarding enabled. I must be missing something though because the tunnel does not work at all. Any help or guidance would be greatly appreciated. 

1 Reply 1

nagrajk1969
Spotlight
Spotlight

Firstly delete ALL THE MANUAL EXPLICIT FIREWALL RULES THAT YOU HAVE ADDED. THEY ARE NOT NEEDED AND NOT TO BE ADDED BY USER. All the required and necessary firewall rules are already applied and added in the background by default. So remove/delete whatever you have added

 

Next, in the S2S tunnel config in each of the peers, change the below vallues of the subnets used in vpn tunnel to

 

192.168.1.0/24 on one side and 10.0.0.0/27 on GW1

and on GW2

- on one side 10.0.0.0/27 and 192.168.1.0/24

Next apply and also do a permanent save

 

 

  

 

 

 

Review Cisco Networking for a $25 gift card