Hi, I'm afraid that made no difference to the situation, still could not ping, and still received:
sh crypto ipsec sa
-->there are no ipsec sas
sh crypto isakmp sa
-->there are no isakmp sas
Also, reviewing the other post it looks like that is more for VPN clients and not site to site.
-glaxo
Main Topics
Browse All Topics





by: koudryPosted on 2008-08-09 at 19:02:25ID: 22198484
Possible typo, i.e. 192.168.13/24 instead of 192.168.13.0/24
IPSec UDP port 4500 possibly blocked
At the moment, it looks like IPSec traffic is not taking place and one reason for this may be that the UDP port 4500 or 500 is blocked.
To open the IPSec UDP ports, you need to enable NAT-T. Try the following commands on the ASA device:
see also: http://www.experts-exchang