cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
728
Views
0
Helpful
3
Replies

problem with 2 cisco RV215W to make a vpn site to site

baptistechaput
Level 1
Level 1

Bonjour

J'ai 2 sites distants que je veux reliés via un vpn. Ces 2 sites ont chacun un RV215W. J'accède les 2 sites en PPTP mais impossible de créer un vpn site to site qui me serait bien utile pour une sauvegarde.

Merci pour votre aide. Vous trouverez ci joint toute la configuration

3 Replies 3

mrsethi
Cisco Employee
Cisco Employee

Hi,

Going through the query as i understand that you are trying to establish a site to site vpn between two 215w routers.

Please let me know are the routers using a PPTP connection for internet connectivity.

-Mrutunjay Sethi

BOnjour

Tout d'abord merci de vous pencher sur mno problème.

Je vous ai fait un document que vous trouverez ci-joint pour détailler on réseau.

Encore merci et bonne journée.

Cordialement,

Baptiste

Hi,

Thanks for sharing the doc file.

Going through the doc file, i fail to get much clarity. I have went through the PDF that you had initially attached and see that you are configuring the VPN using aggressive mode for exchange.


Router-1

1-As per the configuration on router1, I see that the peer ip(router2) is configured as 83.196.111.15

2-The VPN summary details on router1 shows that the local ip is 10.0.2.2 and remote ip as 83.196.111.15

Router-2

1-As per the configuration on router2, I see that the peer ip(router1) is configured as 92.140.231.12

2-The VPN summary details on router2 shows that the local ip is 10.0.1.2 and remote ip as 92.140.231.12

>>While VPN negotiation each device will send the ID payload.

>>In the above config i see that none of the routers does have the public ip on them so when they will send the ID payload , it will be as follows:

-Router1 will send the ID payload value as 10.0.2.2

-Router2 will send the ID payload value as 10.0.1.2

>>By default each device would be set to validate the remote peer using the IP address from which it is receiving the negotiation request so the ID field will not match and the negotiation will fail.

Could you please send me the following debug logs from Router2:

deb cry condition peer 92.140.231.12

deb cry isa

deb cry ipsec

-Now initiate the VPN negotiation from Router1.

-Once you see the negotiation failed, please stop the logs using the command " un all".

-Please enable monitoring on terminal before you start the debugs so that the logs could be seen on the terminal window.

-The command to enable monitoring on terminal is "term mon".

Regards,

Mrutunjay Sethi