09-18-2017 04:00 AM - edited 03-12-2019 04:32 AM
Hi there Cisco community.
I need some help!
I am implementing a site to site IPSEC/GRE VPN , testing it in GNS3 , and after configuring all the IPSEC parameters on both headend devices, also creating a GRE tunnel, when it comes to the show/verify printouts, the "show crypto isakmp sa"command printout displays the the same ip addresses for the destination and source devices. I have rechecked many times and I am petty sure I have done the right configurations both sites. NAT is also configured at the both edge devices.
When I test the same configuration in Packet Tracer, I receive the expected source and destination at the "show crypto isakmp sa"command printout. Can anyone give any suggestion at what might it be the problem?
The printout shown below is taken from configurations at the GNS3 platform.
Branch_RT# SH CRYpto ISakmp SA
dst src state conn-id slot status
200.x.x.11 200.x.x.28 QM_IDLE 1 0 ACTIVE
HQ_RT# sh crypto isakmp sa
dst src state conn-id slot status
200.x.x.11 200.x.x.28 QM_IDLE 1 0 ACTIVE
09-18-2017 05:59 AM
09-18-2017 01:54 PM
Thank you Mark for the quick response. I was thinking the same, probably a bug on the GNS3 platform. I'll try to run the same config in another IOS router.
v
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide