01-08-2018 02:01 PM - edited 03-12-2019 04:53 AM
I tried to lab up a IPsec VPN between to IOS routers on GNS3.
The VPN is not working and tried a few VPN tutorial guides with no luck.
Phase 1 seems to work but my encrypt counters for phase two does not increment. I'm I missing a command?
Site_1#sh crypto isakmp sa
IPv4 Crypto ISAKMP SA
dst src state conn-id status
2.2.2.2 1.1.1.2 QM_IDLE 1001 ACTIVE
Site_2#sh crypto isakmp sa
IPv4 Crypto ISAKMP SA
dst src state conn-id status
2.2.2.2 1.1.1.2 QM_IDLE 1001 ACTIVE
Solved! Go to Solution.
01-09-2018 02:38 PM
01-08-2018 03:51 PM
01-09-2018 06:25 AM
I changed the routes/removed them and that did not help.
My bgp route table does see site 1 and 2 on both routers (Only Public IPs).
as for version I used the
(C7200-ADVENTERPRISEK9-M), Version 15.2(4)S3,
The GNS3 image used was the
c7200-adventerprisek9-mz.152-4.S3.bin
01-09-2018 01:37 PM
01-09-2018 01:51 PM
I attached a Tar of the Project folder.
In the project I imported a different router to see if it was a gns3 or IOS bug.
I still had the same luck. Phase one will not start until I put a permit ip any any in the VPN ACL.
my most recent export files are under the \VPN\Policy Based VPN\7200
I did not export a config for the 3725 router.
01-09-2018 02:32 PM
01-09-2018 02:35 PM
01-09-2018 02:38 PM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide