01-05-2006 07:01 AM
Hello, I´m having two problems with four VPN´s mounted on a PIX 515E connected to the Internet by a direct concection. Other peers are Linksys BEFSX41 with DSL.
1) I set up different crypto maps (each one with it´s own isakmp key), associating those keys with the remote peer IP address (Two peers have static IP address). The problem is this: the other two peers have dynamic ip addresses. I configured one crypto dynamic-map for one of them, using a preshared-key associated to the ip 0.0.0.0 netmask 0.0.0.0
How can I configure ANOTHER DIFFERENT preshared-key for the second crypto dynamic-map, if it has dynamic IP address too?
2) Two VPN´s are working perfect, but one of them in a random time (2 days aprox) hangs and don´t work any more.
When it happened I ran show isakmp sa in the pix. It says that there are:
Total : 583
Embryonic : 0
And it gave me a list of the 583 connections, all in a QM_IDLE state.
What does it mean? Where can I found any information about this problem? Why one VPN works perfect and the other hangs if both are configured in the same way?
I´m new in Cisco PIX...
Thank you for your help!!!
Alejandro.
01-10-2006 10:04 AM
1. unfortunately, one single key has to be deployed for all ezvpn client.
2. is this happening frequently? it's fine if it happens only once or twice; as sometimes vpn freezes and pix/router won't be able to rebuild the tunnel automatically. what you need to do then is do "clear crypto ips sa peer
12-29-2006 09:15 AM
Hi Jack
So is the only option to get static IPs from ISP if we have multiple sites?
regards
venkat
01-04-2007 01:19 AM
Hi Alejandro,
You can create a remote access group instead of the site to site if the devices on the other end can work as VPN clients. This way you can map each device a different group and all of them can connect in the same time.
However, asking the ISP to provide you static IPs and do site-to-site is better, due to the fact that in a remote-access scenario only the client can initiate the connection.
Rate if this helped.
Daniel
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide