09-14-2015 06:19 AM - edited 03-11-2019 11:35 PM
Hello,
I have created to two site-to-site VPN profiles, one test and one production. They have separate inside and outside private IPs, but are part of the same network object group. Both connections show as connected, however, the production connection does not pass traffic. I do a packet trace from the test ip with no problem. Doing a packet trace from the production ip and the packet is dropped: "(acl-drop) Flow denied by configured rule". What am I missing?
09-14-2015 08:12 AM
Call 1-855-935-7526 US & Canada Toll-Free For Router Help & Support.
Official help and support Number for Routers. Links to Router customer support and technical solutions, set-up, help, and answers to top issues.
09-14-2015 01:32 PM
Hi tstrode1,
Have you tried putting them in separate network object groups, and using a unique acl for each one? Can you paste in the portions (acls, network object groups, and crypto map) that apply?
Thanks
09-15-2015 12:47 PM
I've tried putting them in separate network object groups and using a separate acl for each one. Still no traffic.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide