08-06-2012 09:21 AM
Hi All,
I am trying to set up a site-to-site VPN between an 1841 Router and an ASA5510 running 8.4. Both ends negotiate their outside interface IP addresses via DHCP and are connected to ADSL lines.
I have setup the 1841 to an ASA with a fixed IP address using Aggresive mode and that works fine, however when i try to replicate the config on the ASA with the negotiated IP address it is as if there is no interesting traffic for the encryption domain and it fails at Phase 1.
I have re-used the same crypto maps, dynamic maps, transform sets, ACL format and static NAT exception as on the working fixed outside addressed ASA, but i cannot seem to get the tunnel to initiate from either side.
From the ASA end debugging i see
(crypto_map_check)-1: Error: No crypto map matched.
from the 1841 end i see
Aug 6 15:57:39.268: ISAKMP:(0:104:SW:1): retransmitting phase 1 AG_INIT_EXCH...
Aug 6 15:57:39.268: ISAKMP (0:134217832): incrementing error counter on sa, attempt 4 of 5: retransmit phase 1
Aug 6 15:57:39.268: ISAKMP:(0:104:SW:1): retransmitting phase 1 AG_INIT_EXCH
Aug 6 15:57:39.268: ISAKMP:(0:104:SW:1): sending packet to x.x.x.x my_port 500 peer_port 500 (I) AG_INIT_EXCH
Is this even possible to setup with both ends having negotiated addresses? I have seen a few posts that seem to suggest not.
Please see attached for configurations,
many thanks
Stuart
Solved! Go to Solution.
08-07-2012 12:54 AM
No, you've guessed it correctly.
You can't have both end having dynamic ip address to be setup with VPN tunnel because if both ends do not know what the IP Address is, it won't be able to establish the VPN tunnel.
You can only have 1 end dynamic, and the other end static IP Address.
08-07-2012 12:54 AM
No, you've guessed it correctly.
You can't have both end having dynamic ip address to be setup with VPN tunnel because if both ends do not know what the IP Address is, it won't be able to establish the VPN tunnel.
You can only have 1 end dynamic, and the other end static IP Address.
08-07-2012 01:02 AM
Hi Jennifer,
Thank you for clarifying this,
regards,
Stuart
08-07-2012 01:13 AM
Cheers, pls kindly mark the post answered so others can learn from your question. Thank you.
08-07-2012 01:14 AM
There could be a solution for that. But it's really dirty and probably not worth it to try:
So, better get a static IP for your box.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide