11-17-2010 05:55 AM
Hi, wondering if anyone has any ideas on a problem I have.
I have 2 networks, one private and one internet, connecting to 2 interfaces on a 3745 router. I have mobile client routers (netscreens) that are moving from one network to the other.
The problem I have is the tunnel comes up when the client is on internet but when connected via the client network it needs a static route on the PoP pointing to the client network.
Without the static route the SA shows as QM_IDLE but it does not pass traffic. I also have an issue where when the router moves from internet to the private network the SA stays on the 3745 and causes SPI problems until it clears. Reducing idle-time seems to do nothing to help this.
11-17-2010 06:53 AM
I think maybe Reverse Route Injection might be a partial solution?
11-19-2010 06:50 AM
Hi,
So to clarify the problem, we have VPN termination on 2 different interfaces on a 3745, "internet" and "private". When connecting to "internet" all works fine. When connecting to "private", connection is up but no traffic passes unless a static route is added.
Could you elaborate more on what is the exact command you add? It will be much easier to understand if you could post a sanitized config and a topology as well.
Regards,
Prapanch
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide