11-29-2000 08:56 AM - edited 02-21-2020 11:15 AM
Hi,
I have a few site to site VPNs PIX-PIX. All of these work fine over frame relay connections. However, the first ISDN one I have tried fails?
The ISDN router config is fine and I can ping the outside world from the PIX.
Any ideas?
12-06-2000 07:38 AM
Well, Id like to help but I need some more information to do so.
1. What model router do you have?
2. What IOS image are you running?
3. Have you looked at the debugs?
4. Where is the session failing?
If your running the current IOS I would suggest calling TAC.
12-07-2000 01:16 PM
Hi,
This is between two Cisco PIX 515s both on 5.12.
I have looked at all of the debugs. ISAKMP gets an SA, and transfers the Pre-Shared keys, then the IPSec SA just drops?
Andrew..
12-08-2000 03:24 AM
Hi Andrew,
You don't make it clear wether you are using BRI or PRI for this but the problem you may be having is that VPNs must have at least one end of the link supported by a permanent internet connection. ISDN to ISDN won't work unless both connections happen to be live at the same time. If one end is permanent, then the temporary end must initiate the communication. Thus isdn is ideal for RAS VPNs, but unusable for site to site. To make low cost VPN solutions, I recommend trying to find a cable provider who can give you permanent access, or ideally pay for a small leased line at each end.
Hope this helps,
George W
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide