Hi guy

i am doing site-to-site vpn configuration configuration between Routers

R1 and R5 both are sited in behind the ASA on ASA enable the nat-control
protocal

but my tunnel is not establishing

R5

crypto isakmp policy 10
 encr 3des
 authentication pre-share
 group 2
crypto isakmp key Cisco123 address 49.49.6.1

crypto ipsec transform-set vpn esp-3des esp-md5-hmac
!
crypto ipsec profile vpn
 set transform-set vpn

interface Tunnel0
 ip address 123.1.1.5 255.255.255.0
 tunnel source FastEthernet0/0
 tunnel destination 49.49.6.1
 tunnel mode ipsec ipv4
 tunnel protection ipsec profile vpn

interface FastEthernet0/0
 ip address 49.49.7.5 255.255.255.0
 duplex auto
 speed auto

R1

crypto isakmp policy 10
 encr 3des
 authentication pre-share
 group 2
crypto isakmp key Cisco123 address 49.49.7.5

crypto ipsec transform-set vpn esp-3des esp-md5-hmac
!
crypto ipsec profile vpn
 set transform-set vpn

interface Tunnel0
 ip address 123.1.1.1 255.255.255.0
 tunnel source FastEthernet0/0
 tunnel destination 49.49.7.5
 tunnel mode ipsec ipv4
 tunnel protection ipsec profile vpn

interface FastEthernet0/0
 ip address 49.49.6.1 255.255.255.0
 duplex auto
 speed auto


ASA

interface Ethernet0/0
 nameif outside
 security-level 0
 ip address 49.49.6.10 255.255.255.0
!
interface Ethernet0/1
 nameif inside
 security-level 100
 ip address 49.49.7.10 255.255.255.0


access-list outside extended permit esp host 49.49.6.1 host 49.49.7.5
access-list outside extended permit udp host 49.49.6.1 host 49.49.7.5 eq
isakmp
nat-control
_______________________________________________
For more information regarding industry leading CCIE Lab training, please visit 
www.ipexpert.com

Are you a CCNP or CCIE and looking for a job? Check out 
www.PlatinumPlacement.com

Reply via email to