cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
423
Views
0
Helpful
9
Replies

Connecting peer to peer pfsesnse cisco router IPSEC

bronzenetworker
Level 1
Level 1

I get this error after setting up a ipsec connection with my router and pfsense firewall

ICU4-ROUTER-01#show crypto isakmp sa
IPv4 Crypto ISAKMP SA
dst src state conn-id status
10.2.128.50 10.2.66.52 MM_NO_STATE 0 ACTIVE (deleted)

IPv6 Crypto ISAKMP SA

10.2.128.50 is the router WAN

10.2.66.52 is the WAN interface of the firewall

The idea is to connect a cloud environment with a office site network.

Shortly after the connection gets deleted, how do i solve this problem.

To setup the configuration i used this guide: https://www.cisco.com/c/en/us/support/docs/routers/1700-series-modular-access-routers/71462-rtr-l2l-ipsec-split.html

 

9 Replies 9

marce1000
VIP
VIP

 

 -  Review these bug reports : https://bst.cloudapps.cisco.com/bugsearch?pf=prdNm&kw=MM_NO_STATE&bt=custV&sb=anfr

 M.



-- Each morning when I wake up and look into the mirror I always say ' Why am I so brilliant ? '
    When the mirror will then always repond to me with ' The only thing that exceeds your brilliance is your beauty! '

Can you share router config 

MHM

You need the complete, show running-config ?

Yes' 

And 

Debug crypto isakmp 

MHM

Sorry  I still wating ?

can you share the config to check it 

thanks

MHM

I had nat inside to outside. I turned it off now since, I want the other firewall to do nat for me. But the problem is that my ipsec tunnel that I have established doesnt send network traffic through the tunnel.

 

Thanks for more detail 

Two issue I see

1- you need to exclude encrypt traffic from NAT 

Check this link

https://www.cisco.com/c/en/us/support/docs/security-vpn/ipsec-negotiation-ike-protocols/14132-ios-D.html

2- there is hsrp are you sure the traffic pass correctly through this router' i.e. this router is hsrp active?

Also are Peer is config to deal with two endpoint not one?

MHM

I tried to share the config, for some reason i cant post it in the forum.

No need I take look of config' and I notice two points I list above.

Check it

MHM

Review Cisco Networking for a $25 gift card