cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2022
Views
0
Helpful
3
Replies

IPSec Tunnel up but cannot ping remote Tunnel IP

mahesh18
Level 6
Level 6

Hi everyone,

I have IPSEC  tunnel between 2 devices.

Tunnel is up up from both ends.

No NAT is taking place on these 2 devices.

I can ping the IP across the tunnel but not the tunnel IP.

Is this normal behaviour ?

Here is info

IPv4 Crypto ISAKMP SA

dst             src             state          conn-id status

192.168.99.2    192.168.99.1    QM_IDLE           2005 ACTIVE

IPv6 Crypto ISAKMP SA

1811w# ping 4.2.2.2

Type escape sequence to abort.

Sending 5, 100-byte ICMP Echos to 4.2.2.2, timeout is 2 seconds:

!!!!!

Success rate is 100 percent (5/5), round-trip min/avg/max = 44/47/48 ms

1811w#ping 192.168.20.2

Type escape sequence to abort.

Sending 5, 100-byte ICMP Echos to 192.168.20.2, timeout is 2 seconds:

!!!!!

Success rate is 100 percent (5/5), round-trip min/avg/max = 1/1/4 ms

1811w#ping 192.168.99.2

Type escape sequence to abort.

Sending 5, 100-byte ICMP Echos to 192.168.99.2, timeout is 2 seconds:

.....

Success rate is 0 percent (0/5)

1811w#

Thanks

MAhesh

1 Accepted Solution

Accepted Solutions

Reza Sharifi
Hall of Fame
Hall of Fame

Hi Mahesh,

Can you post sh run from both routers?

I provided you my lab IPsec config a couple of weeks ago.  Did you try loading it.

Reza

View solution in original post

3 Replies 3

Reza Sharifi
Hall of Fame
Hall of Fame

Hi Mahesh,

Can you post sh run from both routers?

I provided you my lab IPsec config a couple of weeks ago.  Did you try loading it.

Reza

Hi Reza,

I did not load that IPSEC which you provided few weeks ago.

I have loaded the sh run from both devices to this under original post.

Thanks

Mahesh

Hi Reza,

I can ping the Tunnel IP now on other side as below

1811w#   sh crypto isakmp sa

IPv4 Crypto ISAKMP SA

dst             src             state          conn-id status

192.168.99.2    192.168.99.1    QM_IDLE           2005 ACTIVE

IPv6 Crypto ISAKMP SA

1811w# ping 192.168.99.2

Type escape sequence to abort.

Sending 5, 100-byte ICMP Echos to 192.168.99.2, timeout is 2 seconds:

!!!!!

Success rate is 100 percent (5/5), round-trip min/avg/max = 4/4/8 ms

Same issue fixing the ACL  on 3550A  solved my both problems

Regards Again

I know you are always here to help me

Mahesh

Review Cisco Networking products for a $25 gift card