12-15-2012 10:27 AM - edited 03-07-2019 10:37 AM
Hi everyone,
I have IPSEC tunnel between 2 devices.
Tunnel is up up from both ends.
No NAT is taking place on these 2 devices.
I can ping the IP across the tunnel but not the tunnel IP.
Is this normal behaviour ?
Here is info
IPv4 Crypto ISAKMP SA
dst src state conn-id status
192.168.99.2 192.168.99.1 QM_IDLE 2005 ACTIVE
IPv6 Crypto ISAKMP SA
1811w# ping 4.2.2.2
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 4.2.2.2, timeout is 2 seconds:
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 44/47/48 ms
1811w#ping 192.168.20.2
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 192.168.20.2, timeout is 2 seconds:
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 1/1/4 ms
1811w#ping 192.168.99.2
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 192.168.99.2, timeout is 2 seconds:
.....
Success rate is 0 percent (0/5)
1811w#
Thanks
MAhesh
Solved! Go to Solution.
12-15-2012 11:03 AM
Hi Mahesh,
Can you post sh run from both routers?
I provided you my lab IPsec config a couple of weeks ago. Did you try loading it.
Reza
12-15-2012 11:03 AM
Hi Mahesh,
Can you post sh run from both routers?
I provided you my lab IPsec config a couple of weeks ago. Did you try loading it.
Reza
12-15-2012 01:23 PM
Hi Reza,
I did not load that IPSEC which you provided few weeks ago.
I have loaded the sh run from both devices to this under original post.
Thanks
Mahesh
12-15-2012 02:13 PM
Hi Reza,
I can ping the Tunnel IP now on other side as below
1811w# sh crypto isakmp sa
IPv4 Crypto ISAKMP SA
dst src state conn-id status
192.168.99.2 192.168.99.1 QM_IDLE 2005 ACTIVE
IPv6 Crypto ISAKMP SA
1811w# ping 192.168.99.2
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 192.168.99.2, timeout is 2 seconds:
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 4/4/8 ms
Same issue fixing the ACL on 3550A solved my both problems
Regards Again
I know you are always here to help me
Mahesh
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: