cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
302
Views
0
Helpful
1
Replies

VPN between Cisco 2621 & Nortel Contivity

fitzpatrickjj
Level 1
Level 1

I am trying to establish an IPSEC VPN between a Cisco 2621 and a Nortel Contivity 1010. I am getting most of the way there and then get a debug message on the Cisco saying that it received a unencrypted packet when it should have been encrypted then the tunnel falls over. Is the Contivity looking for some additional authentication before it establishes the tunnel?

If anyone has done this before I would be grateful for help.

1 Reply 1

gfullage
Cisco Employee
Cisco Employee

Sounds like the Nortel and the Cisco don't have the exact opposite crypto ACL's set up. The Nortel is sending unencrypted packets that the Cisco router thinks should be encrypted, so their ACL's don't match up.

Can you run:

> debug crypto ipsec

> debug crypto isakmp

on the router and then try and bring the tunnel up from the Nortel side, this'll tell us exactly what's going on. Check your crypto traffic though, that looks like the problem.