cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1066
Views
0
Helpful
1
Replies

VPN site-to-site with ASA 5506-X (one with dynamic address)

Hi everybody,

I'm trying to configure a site-to-site VPN tunnel between 2 ASA 5506-X but my VPN never goes up. I don't see active tunnels from ASDM.

The site A has a public static IP address connected to the interface Ge 1/1 and the site B has a dynamic public IP address connected to the interface Ge 1/1. Connectivity to Internet is good as I can ping 8.8.8.8 successfully.

I attached the config files and basic infrastructure schema. Can you please help me in finding my mistakes ?

Thanks in advance for your help

1 Reply 1

Philip D'Ath
VIP Alumni
VIP Alumni

It looks good to me.  Note that VPN will only come up with traffic initiated from site b.

So if a machine (not the ASA) from site b tries to ping something at site A it doesn't work? Do a:

debug crypto isakmp
debug crypto ipsec

on site b and post the output please.

Review Cisco Networking for a $25 gift card