cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
3919
Views
0
Helpful
0
Replies

Session status: DOWN-NEGOTIATING

itanium2k2
Level 1
Level 1

Ipsec tunnel between 2951 and RV110w:

 

crypto isakmp policy 1

 encr aes

 authentication pre-share

 group 2

 lifetime 3600

crypto isakmp key MEGAKEY address 93.73.*.*   

!

!

crypto ipsec transform-set COMPANY-TRSET esp-aes esp-sha-hmac 

 mode tunnel

!

!

crypto ipsec profile dmvpn_profile

 set transform-set COMPANY-TRSET 

!

!         

interface Tunnel2

 description Tunnel to PIB 10.1.0.0/24

 ip address 10.11.0.1 255.255.255.0

 tunnel source GigabitEthernet0/2

 tunnel mode ipsec ipv4

 tunnel destination 93.73.*.*

 tunnel protection ipsec profile dmvpn_profile

 

 

 

2951#sh cry sess de

 

Interface: Tunnel2

Session status: DOWN-NEGOTIATING

Peer: 93.73.*.* port 500 fvrf: (none) ivrf: (none)

      Desc: (none)

      Phase1_id: (none)

  IKEv1 SA: local 89.184.*.*/500 remote 93.73.*.*/500 Inactive 

          Capabilities:(none) connid:0 lifetime:0

  IPSEC FLOW: permit ip 0.0.0.0/0.0.0.0 0.0.0.0/0.0.0.0 

        Active SAs: 0, origin: crypto map

        Inbound:  #pkts dec'ed 0 drop 0 life (KB/Sec) 0/0

        Outbound: #pkts enc'ed 0 drop 0 life (KB/Sec) 0/0

 

Interface: Tunnel2

Uptime: 00:35:41

Session status: UP-ACTIVE     

Peer: 93.73.*.* port 82 fvrf: (none) ivrf: (none)

      Phase1_id: 192.168.1.32

      Desc: (none)

  IKEv1 SA: local 89.184.*.*/500 remote 93.73.*.*/82 Active 

          Capabilities:(none) connid:10226 lifetime:00:24:18

  IPSEC FLOW: permit ip 10.55.0.0/255.255.255.252 host 10.10.0.2 

        Active SAs: 2, origin: crypto map

        Inbound:  #pkts dec'ed 0 drop 0 life (KB/Sec) 4608000/1458

        Outbound: #pkts enc'ed 0 drop 0 life (KB/Sec) 4608000/1458

 

 

Advice is appreciated, thanks.

0 Replies 0
Review Cisco Networking for a $25 gift card