09-19-2017 04:59 AM - edited 02-21-2020 06:19 AM
Dears
i have a L2L vpn from branch to HQ and everthing works fine i am adding a new subnet in the vpn access-list exactly as per the cisco recommendation mirror access-list on both ends, But still the connection to the ISE server on port 1645 fails my branch switches are not able to reach the ISE server in HQ.
The strange part is the packet-tracer some time shows me results all ok and within a seconds if i run again it shows me vpn encrypt packet drop.
Please find the attached packet tracer output.
09-19-2017 07:42 PM
Hello,
Should be nice if you put firewall config here. Only one question, does Firewall has route to the new subneteork?
09-20-2017 12:18 PM
i can paste the config but i have routes pretty sure for that
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide
Subject | Author | Posted | |
---|---|---|---|
07-27-2010 03:40 AM | |||
07-15-2024 04:46 PM | |||
05-12-2014 05:04 PM | |||
02-09-2024 08:30 AM | |||
07-20-2020 11:23 PM |