11-15-2006 03:27 AM - edited 02-21-2020 02:43 PM
I have a site to site between my office and a customer using two Pix 515E's. As my office has moved there is a new ip address at my office end. I have been to the clients site and changed the peer address to correspond but it will not connect. When debugging it appears that it is still trying to connect to the old ip address even though there is nothing in the config that relates to that address now. Has anyone come across this before and if so how did you resolve it.
11-15-2006 04:01 AM
can you try commands
clear crypto isakmp sa
clear crypto ipsec sa
M.
11-16-2006 01:20 AM
I have tried the clear crypto ipsec sa and clear crypto isakmp sa but that didnt work.
11-15-2006 07:07 AM
I'm no expert but I know that there are some changes made to a crypto map that aren't dynamic, such as an access-list change.
Even if you issue a clear ipsec sa command the changes won't be reflected in the sa.
Try unbinding the cyrpto map and then re-binding it to the correct interface.
Also, if you are using PSKs, double check that the line isakmp key... is pointing to the correct address.
11-15-2006 11:32 PM
Recently i just experienced this issue, we got an IP address change and must change the site-to-site peer. i use "no" to all our crypto map commands and acl, then enable that again. But then i must restarted the pix to get it to the right peer.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide