03-02-2001 09:25 AM - edited 02-21-2020 11:18 AM
I setup to 515 Pixs to create a VPN between them. It all works fine when I tested it on two routers connected back to back. When I connect my pixs on two internet connections and try to establish a VPN I can't. One of the ISPs changed the access list on the router and the other router is without any access list. Please if anybody can help.
Henk
03-06-2001 02:35 PM
I would suggest starting with Configs and debugs in this situation. If it worked back-to-back in the lab, you better look harder at the ISP. Have them check their access-lists for IP protocol 50 & 51 blocking. Remember, if theres an access list at all, and theres no permit statement, there is an implicit deny. Usually ISPs dont run access-lists and leave all the filtering up to their customers. If they are sure they are not blocking anything, I'd suggest opening a TAC case.
03-06-2001 05:42 PM
Hi Henk,
First determine if the two devices can ping each other. Use the debug packet commmand on each PIX to verify if the traffic is making it past your access router. Also make sure you changed your default route to the next hop which appear to be your ISP routers. You also need to create a static entry in your router allowing traffic to go from the lower security interface (outside) to the higher one (inside). It may be easier just to enter the command "sysopt conection permit ipsec".
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide