I've got a PIX-to-PIX VPN Tunnel between CO and Chicago that works when the regular link is up. My ISP's main link in Chicago just failed, but they have routed it through some emergency links they put in place. The temporary links include a NAT from a new IP to the old.
So, I have modified the PEER on my CO PIX and restarted the CRYPTO MAP. I can SSH into the remote (CH) PIX via the NATed external IP address, and the VPN appears to be up, but I can't pass traffic across it.
The inbound ESP SAS SPI in CO matches the outbound ESP SAS SPI in CH, and vice-versa. It seems like a routing problem, but I don't see where.
Any other thoughts?
Tim