cancel
Showing results for 
Search instead for 
Did you mean: 
cancel

Who Me Too'd this topic

VTI endpoints can't be pinged by LAN clients

Damir Reic
Level 1
Level 1

Hello,

I setup simple lab environment in GNS3 and found interesting problem. Used setup from https://www.cisco.com/en/US/docs/ios/12_3t/12_3t14/feature/guide/gtIPSctm.html#wp1080079(Configuration Examples for IPsec Virtual Tunnel Interface). So in this simple setup, tunnel interface is UP, from the router I can ping everything, but from the server on left and right side I can't ping tunnel endpoint or LAN IP of the other router. I have no idea why, it's totally not logical, servers are using LAN IP as default gateway.

 

So workstation PC1 can ping tunnel IP on R1 but can't ping tunnel IP on R2. Both ends have proper routes otherwise I wouldn't be able to ping "lan" interface from the router on the other side of the tunnel.

Who Me Too'd this topic