5 Posts

June 6th, 2007 12:00

Does the VPN connection's access lists permit traffic from the tunnel that does not work? You have access lists on the firewalls that determine which traffic gets tunnelled. Do you admin the pix on the far side of the tunnel? The capture command (on 6.2+ PIX OS) is very handy. That, and debug icmp (or debug ip icmp) might be helpful. On the pix, a show crypto ipsec sa would show if there is a SA for the subnet that is problematic - the sh cry ips sa output should have a SA for each subnet to subnet pairing that deserves encryption as defined by the crypto access-lists

June 6th, 2007 13:00

I do not have access to the other side. All I can do is ask them to add or delete commands.
I do have the access lists set up on both sides of the tunnels to permit each of the VLANs ranges.
As it appears there are 2 VLAN address ranges enabled through 1 tunnel.
No Events found!

Top