11-21-2007 06:13 AM - edited 03-03-2019 07:38 PM
Hi Experts,
I am going to configure a point to point ipsec tunnelling.Am new in this technology..Anybody can point me to the right location for this info?
And the troubleshooting steps if face with problems?
Thanks!
Solved! Go to Solution.
11-22-2007 01:54 AM
Thanks Jon.. :)
Another question is..how can i determine the tunnel is up and can be passed through?
As you were saying the real test is to pass down the tunnel...
Thanks once again :D
11-22-2007 02:02 AM
Cindy
The tunnel is up because of the output from the "sh crypto ipsec sa". If there was no tunnel up you wouldn't see all that output from your command.
From the output
"local ident (addr/mask/prot/port): (192.168.1.0/255.255.255.0/0/0)
remote ident (addr/mask/prot/port): (192.168.2.0/255.255.255.0/0/0)
"
The local network (local to the router you ran the command on) is
192.168.1.0/24
The remote network is
192.168.2.0/24
So you need to generate traffic from a host on 192.168.1.0/24 network to a host on the 192.168.2.0/24 network.
Don't forget that if you have access-lists on the interfaces on each router that use the public addressing you will need to add the relevant ports into the access-list.
Jon
11-22-2007 05:35 AM
Thanks Jon,
Got it... :)
Will let you know if i face with the problem at a later stage during production..
11-22-2007 08:43 AM
Completely agree Jon, and believe me.. beisde labs and reading links books etc.. I follow your post to lear from , there are quite very good engineers in netpro and you're one among them.
Rgds
Jorge
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide