cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
415
Views
0
Helpful
1
Replies

VPN Tunnel not working

tomf
Level 1
Level 1

Hello, I am looking for suggestions as to how to ascertain which end of the tunnel (PIX to Netscreen Device) is not working. I see the tunnel but no traffic is initiated. Using "how crypto ipsec sa" I see the remote peer but note that there is really no traffic moving.

PIX 515 6.3.4

Netscreen: Not sure????

Several other tunnels work fine. Just the new one.

thank you

1 Reply 1

mhussein
Level 4
Level 4

Hi,

Using show crypto isakmp sa you can find out which side started the tunnel (src). Or during maintenance window, generate interesting traffic and debug crypto engine/isakmp/ipsec.

Since the tunnel is established with no traffic, I'd suspect a routing issue on the remote side. For example, the router connected to the Netscreen should have a static route for the PIX's side LAN.

HTH,

Mustafa