05-31-2008 04:08 AM - edited 03-11-2019 05:53 AM
Hi, I am trying to make tunnel between two sites and I have setup all configuration and check configuration multiple times but still not able to recognize the issue. when I execute the below commands:-
show crypto isakmp sa
Result of the command: "show crypto isakmp sa"
There are no isakmp sas
Anyone tell me what should I do??? Thanks!
show crypto isakmp sa
Result of the command: "show crypto isakmp sa"
There are no isakmp sas
Can anyone tell me
Solved! Go to Solution.
05-31-2008 09:19 AM
Hi Ray
In Rwanda
no crypto map outside_map 1 match address outside_1_cryptomap
crypto map outside_map 1 match address outside_cryptomap_1
Try setting pre-shared-key to 1 in both ends untill you resolve the issue.
Try reloading firewalls in both ends.
If reload doesnt work, try using a different transform set for l2l ESP-3DES-MD5 for example. Dont forget to define isakmp policy for this in India.
Regards
06-01-2008 07:00 AM
Sure you can
05-31-2008 04:48 AM
There could be multiple issues - but the first thing I would check is - if you have defined the interesting traffic, you have to identify what traffic should pass over the VPN - this in turn will bring the VPN up.
If you have no isakmp sa's - you don't have an active VPN.
HTH.
05-31-2008 05:26 AM
05-31-2008 08:23 AM
Hi, can anyone respond as I need to make site to tunnel on priority basis. Thanks
05-31-2008 08:24 AM
Hi, can anyone respond as I need to make site to tunnel on priority basis. Thanks
05-31-2008 09:19 AM
Hi Ray
In Rwanda
no crypto map outside_map 1 match address outside_1_cryptomap
crypto map outside_map 1 match address outside_cryptomap_1
Try setting pre-shared-key to 1 in both ends untill you resolve the issue.
Try reloading firewalls in both ends.
If reload doesnt work, try using a different transform set for l2l ESP-3DES-MD5 for example. Dont forget to define isakmp policy for this in India.
Regards
05-31-2008 07:48 PM
Thanks, now the tunnel has been created. Can I change in the access list instead of following commands and change outside_cryptomap_1 to outside_1_cryptomap.
no crypto map outside_map 1 match address outside_1_cryptomap
crypto map outside_map 1 match address outside_cryptomap_1
06-01-2008 07:00 AM
Sure you can
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide