Re: [c-nsp] 6500 with WS-SVC-IPSEC-1, traffic not reaching module.

2009-12-16 Thread Pär Åslund
Hi Lee, You're right and I'm wrong. Have to use BITW. Thanks for the advise, back to reading more documentation for me. Best regards, .pelle On Tue, Dec 15, 2009 at 4:20 PM, Lee ler...@gmail.com wrote: On Tue, Dec 15, 2009 at 8:45 AM, Pär Åslund psl...@gmail.com wrote: Hi Lee, No, I don't

[c-nsp] 6500 with WS-SVC-IPSEC-1, traffic not reaching module.

2009-12-15 Thread Pär Åslund
Hi, I have problems with a WS-SVC-IPSEC-1 where I'm trying to setup a site-to-site tunnel. Last night, I got the tunnel up. But after applying a acl to the 6500, the tunnel went down and stayed down. Removing configuration just to get the tunnel up again and continue trying to get the

Re: [c-nsp] 6500 with WS-SVC-IPSEC-1, traffic not reaching module.

2009-12-15 Thread Lee
Do you have the inside and outside vlan for your ipsec traffic configured with a crypto connect? eg interface Vlan7 description outside:encrypted traffic no ip address crypto engine subslot 8/0 crypto connect vlan8 ! interface Vlan8 description inside:cleartext traffic ip address xxx

Re: [c-nsp] 6500 with WS-SVC-IPSEC-1, traffic not reaching module.

2009-12-15 Thread Pär Åslund
Hi Lee, No, I don't have it configured with crypto connect. From what I read so far, I don't need that for site-to-site ipsec? The asa in the remote office can ping the remote peer ip configured on the 6500. Just seems like bad magic for me right now that for some reason the traffic doesn't seem

Re: [c-nsp] 6500 with WS-SVC-IPSEC-1, traffic not reaching module.

2009-12-15 Thread Lee
On Tue, Dec 15, 2009 at 8:45 AM, Pär Åslund psl...@gmail.com wrote: Hi Lee, No, I don't have it configured with crypto connect. From what I read so far, I don't need that for site-to-site ipsec? All the docs I read talked about the bump in the wire encryption. Somehow or other you have to