08-31-2016 03:57 AM
I have two routers company A 1941 and B 1800
I configured both router to enable vpn connection between COMPANY A & B.
I can ping tunnel 10.10.10.x from routers
I can ping local ip 192.168.x.x from routers
I can ping 10.10.10.x from pc but could not ping 192.168.x.x from pc which is local IP of Company B.
I run sh crypto isakmp from router B
dst src state conn-id status
41.79.x.x 197.149.x.x QM_IDLE 1079 ACTIVE
I run sh crypto isakmp from router A
dst src state conn-id status
197.149.x.x 10.10.x.x MM_NO_STATE 0 ACTIVE
197.149.90.10 10.10.x.x MM_NO_STATE 0 ACTIVE (deleted)
41.79.x.x 197.149.x.x MM_NO_STATE 1001 ACTIVE (deleted)
what could be the issue.
thanks.
semiu
08-31-2016 04:50 AM
Hi Semiu,
Looking at the output, looks like the phase 1 is up from site B router however the phase 2 is not coming up and that is why router in Site A is showing the state as MM_NO_STATE. I would appreciate if you could help me understand which subnet is on site A and which subnet is on site B. Also, I would appreciate if you could share the VPN configuration from both the routers.
Thanks,
Vishnu
09-01-2016 12:38 AM
09-01-2016 12:59 AM
could you please check if phase 2 is coming up or not i no then check the transform set mode is tunnel as I cant see the mode tunnel in 1841 router config for transform set
09-01-2016 01:19 AM
1841 does not display mode tunnel in its config,
so how can I check if phase 2 is coming up?
thanks for your response
09-01-2016 01:44 AM
ok thats what I was suspecting anyway thanks for Info. try to ping remote end PC from Local PC and check the below commands on router
Phase 1- show crypto isakmp sa
Phase 2 - show crypto ipsec sa
09-02-2016 12:12 AM
09-02-2016 12:26 AM
So here is an issue
local crypto endpt.: 10.10.10.1, remote crypto endpt.: 197.149.90.10
On both side you have applied crypto-map on Tunnel0 you have set peer as Internet facing interface so VPN peer and Local vpn endpoint are getting mismatch. Please change the vpn peer IP as Remote end Tunnel IP address. And then test it
on 1941
crypto map VPN-MAP 10 ipsec-isakmp
set peer 10.10.10.2
on 1841
crypto map VPN-MAP 10 ipsec-isakmp
set peer 10.10.10.1
09-02-2016 12:54 AM
thanks I have changed it as requested this is what I get
09-02-2016 01:18 AM
Have changed the IP on both the router. Phase 2 still not seeing up
09-02-2016 01:31 AM
09-02-2016 02:18 AM
We have to verify why phase 2 is not coming up. Could you please debug crypto ipsec on the router to see the logs of Phase 2.
09-02-2016 02:34 AM
how can I debug?
and how can I copy the debugging result .
thanks.
09-02-2016 03:03 AM
09-02-2016 03:33 AM
Sir,
what I want is to be able to establish network between the two routers 1941 and 1841,
presently from local pc I can reach 10.10.10.x
but could not be able reach 192.168.2.x from 192.168.1.x pc and vice versal.
if you can send to me the configuration that will be okay I will appreciate it.
thanks.
semiu
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide