Hi guy i am doing site-to-site vpn configuration configuration between Routers
R1 and R5 both are sited in behind the ASA on ASA enable the nat-control protocal but my tunnel is not establishing R5 crypto isakmp policy 10 encr 3des authentication pre-share group 2 crypto isakmp key Cisco123 address 49.49.6.1 crypto ipsec transform-set vpn esp-3des esp-md5-hmac ! crypto ipsec profile vpn set transform-set vpn interface Tunnel0 ip address 123.1.1.5 255.255.255.0 tunnel source FastEthernet0/0 tunnel destination 49.49.6.1 tunnel mode ipsec ipv4 tunnel protection ipsec profile vpn interface FastEthernet0/0 ip address 49.49.7.5 255.255.255.0 duplex auto speed auto R1 crypto isakmp policy 10 encr 3des authentication pre-share group 2 crypto isakmp key Cisco123 address 49.49.7.5 crypto ipsec transform-set vpn esp-3des esp-md5-hmac ! crypto ipsec profile vpn set transform-set vpn interface Tunnel0 ip address 123.1.1.1 255.255.255.0 tunnel source FastEthernet0/0 tunnel destination 49.49.7.5 tunnel mode ipsec ipv4 tunnel protection ipsec profile vpn interface FastEthernet0/0 ip address 49.49.6.1 255.255.255.0 duplex auto speed auto ASA interface Ethernet0/0 nameif outside security-level 0 ip address 49.49.6.10 255.255.255.0 ! interface Ethernet0/1 nameif inside security-level 100 ip address 49.49.7.10 255.255.255.0 access-list outside extended permit esp host 49.49.6.1 host 49.49.7.5 access-list outside extended permit udp host 49.49.6.1 host 49.49.7.5 eq isakmp nat-control
_______________________________________________ For more information regarding industry leading CCIE Lab training, please visit www.ipexpert.com Are you a CCNP or CCIE and looking for a job? Check out www.PlatinumPlacement.com
