Advertisement

04.14.2008 at 04:06PM PDT, ID: 23322179 | Points: 125
[x]
Attachment Details

My site to site VPN is up but I cannot communicate with resources on the remote network.

Tags: Networking
I am trying to establish a VPN tunnel from my office to  my client's office. On my end  I have a Sonic Wall Pro 3060 running Enhanced OS. The other end has a Cisco 1841 advanced security. I've already established a tunnel between the client's two sites. They have Cisco routers on both sides and it's working great. The two peers in question  authenticate and the tunnel comes up yet I can not access or even PING any resources on either end. I've actually done this before with the same model routers on each end and did have some trouble. I think the problem is on the Cisco router so I have pasted my config below. I'm leaning towards an ACL problem or a route map configuration issue.  The tunnel in question is 2.2.2.2(for the sake of this post), ACL 101, crypto map SDM_CMAP_1 2 ipsec-isakmp. Any suggestions?

Current configuration : 2815 bytes
!
version 12.4
service timestamps debug datetime msec
service timestamps log datetime msec
service password-encryption
!
hostname router
!
boot-start-marker
boot-end-marker
!
logging buffered 52000 debugging
enable secret 5 $1$chQY$rq8aHlCi41IZlYeTJ.3wZ/
!
no aaa new-model
!
resource policy
!
mmi polling-interval 60
no mmi auto-configure
no mmi pvc
mmi snmp-timeout 180
ip subnet-zero
ip cef
!
!
!!
username user privilege 15 secret 5 $1$DQTY$HRiH2zqdC4TVbHoQLY4ht/
!
!
!
crypto isakmp policy 1
 encr 3des
 hash md5
 authentication pre-share
 group 2
!
crypto isakmp policy 2
 encr 3des
 authentication pre-share
 group 2
crypto isakmp key r(3%nLe2 address 1.1.1.1
crypto isakmp key dms2hapcgraysho100w address 2.2.2.2
!
!
crypto ipsec transform-set ESP-3DES-SHA esp-3des esp-sha-hmac
crypto ipsec transform-set ESP-3DES-SHA1 esp-3des esp-md5-hmac
!
crypto map SDM_CMAP_1 1 ipsec-isakmp
 description Tunnel to 1.1.1.1
 set peer 1.1.1.1
 set transform-set ESP-3DES-SHA
 match address 100
crypto map SDM_CMAP_1 2 ipsec-isakmp
 description VPN Tunnel To DMS
 set peer 2.2.2.2
 set transform-set ESP-3DES-SHA
 match address 101
!
!
!
interface FastEthernet0/0
 description Inside Private Interface$ETH-LAN$
 ip address 10.19.16.254 255.255.255.0
 ip nat inside
 ip virtual-reassembly
 duplex auto
 speed auto
!
interface FastEthernet0/1
 description WAN/Internet Interface To Nuvox T1$ETH-WAN$
 ip address 3.3.3.3 255.255.255.252
 ip nat outside
 ip virtual-reassembly
 duplex auto
 speed auto
 crypto map SDM_CMAP_1
!
interface Serial0/0/0
 description Point-To-Point Circuit To New Iberia
 ip address 10.19.100.2 255.255.255.252
 shutdown
 service-module t1 clock source internal
!
ip classless
ip route 0.0.0.0 0.0.0.0 4.4.4.4
ip route 10.19.16.0 255.255.255.0 10.19.100.1
!
ip http server
no ip http secure-server
ip nat inside source route-map SDM_RMAP_1 interface FastEthernet0/1 overload
ip nat inside source static tcp 10.19.16.9 80 3.3.3.3 80 extendable
!
access-list 100 permit ip 10.19.16.0 0.0.0.255 10.0.0.0 0.0.0.255
access-list 101 permit ip 10.19.16.0 0.0.0.255 192.168.111.0 0.0.0.255
access-list 102 deny   ip 10.19.16.0 0.0.0.255 192.168.111.0 0.0.0.255
access-list 110 deny   ip 10.19.16.0 0.0.0.255 10.0.0.0 0.0.0.255
access-list 110 permit ip 10.19.16.0 0.0.0.255 any
route-map SDM_RMAP_1 permit 1
 match ip address 110
!!!
Start your free trial to view this solution
Question Stats
Zone: Software
Question Asked By: mboudreaux
Question Asked On: 04.14.2008
Participating Experts: 1
Points: 125
Views: 0
Translate:
Loading Advertisement...
04.15.2008 at 05:08AM PDT, ID: 21357819

Rank: Genius

All comments and solutions are available to Premium Service Members only.

Start your 7 day free trial and see for yourself why Experts Exchange is the easiest and most proven technology resource in the world. Get Started

Already a member? Login to view this solution.

 
04.15.2008 at 07:07AM PDT, ID: 21358807

All comments and solutions are available to Premium Service Members only.

Start your 7 day free trial and see for yourself why Experts Exchange is the easiest and most proven technology resource in the world. Get Started

Already a member? Login to view this solution.

 
04.15.2008 at 04:54PM PDT, ID: 21363763

Rank: Genius

All comments and solutions are available to Premium Service Members only.

Start your 7 day free trial and see for yourself why Experts Exchange is the easiest and most proven technology resource in the world. Get Started

Already a member? Login to view this solution.

 
 
Loading Advertisement...
Microsoft
  • Internet Protocols
  • Applications
  • Development
  • OS
  • Hardware
  • Windows Security
Apple
  • Operating Systems
  • Hardware
  • Programming
  • Networking
  • Software
Internet
  • Search Engines
  • File Sharing
  • WebTrends / Stats
  • Spy / Ad Blockers
  • Web Browsers
  • New Net Users
  • Web Development
  • Chat / IM
  • Anti Spam
  • Web Servers
  • Anti-Virus
  • Email Clients
Gamers
  • Tips
  • Online / MMORPG
  • Puzzle
  • Emulators
  • Action / Adventure
  • Role Playing
  • Consoles
  • Game Programming
  • Strategy
  • Sports
  • Misc
  • Computer Games
Digital Living
  • Hardware
  • New Net Users
  • New Users
  • Software
  • Digital Music
  • Gaming World
  • Home Security
  • Apple
  • Networking Hardware
Virus & Spyware
  • Vulnerabilities
  • IDS
  • Encryption
  • Anti-Virus
  • Operating Systems Security
  • Software Firewalls
  • WebApplications
  • Cell Phones
  • Operating Systems
  • Internet
  • Hardware Firewalls
Hardware
  • Handhelds / PDAs
  • Displays / Monitors
  • Components
  • Networking Hardware
  • Peripherals
  • Laptops/Notebooks
  • Storage
  • Servers
  • Desktops
  • New Users
  • Misc
  • Apple
Software
  • System Utilities
  • Industry Specific
  • Network Management
  • Photos / Graphics
  • Page Layout
  • VMWare
  • Misc
  • Web Development
  • OS
  • CYGWIN
  • Voice Recognition
  • Message Queue
  • Quality Assurance
  • Security
  • Firewalls
  • MultiMedia Applications
  • Development
  • Database
  • Office / Productivity
  • Business Management
  • OS/2 Apps
  • Server Software
  • Internet / Email
ITPro
  • OS
  • Storage
  • Encryption
  • Operating Systems Security
  • Apple Hardware
  • Laptops & Notebooks
  • Servers
  • Networking Hardware
  • Peripherals
  • Devices
  • Displays / Monitors
  • WebTrends / Stats
  • Search Engines
  • Firewalls
  • WebApplications
  • IDS
  • Vulnerabilities
  • Email Clients
  • File Sharing
  • Spy / Ad Blockers
  • Web Browsers
  • Web Servers
  • Networking
  • Anti-Virus
  • Chat / IM
  • Anti Spam
Developer
  • Web Servers
  • Web Browsers
  • Game Programming
  • Dev Tools
  • Industry Specific
  • Office / Productivity
  • Database
  • CYGWIN
  • Web Development
  • Search Engines
  • File Sharing
  • WebTrends / Stats
  • Programming
  • Content Management
  • Application Servers
  • Protocols
Storage
  • Removable Backup Media
  • Storage Technology
  • Servers
  • Grid
  • Remote Access
  • Backup / Restore
  • Misc
  • Hard Drives
OS
  • Miscellaneous
  • Security
  • Development
  • Linux
  • VMWare
  • MainFrame OS
  • Unix
  • Apple
  • OS / 2
  • AS / 400
  • BeOS
  • Microsoft
  • VMS / OpenVMS
Database
  • Oracle
  • Miscellaneous
  • MySQL
  • Software
  • Sybase
  • Contact Management
  • PostgreSQL
  • Data Manipulation
  • Clarion
  • InterSystems Cache
  • Siebel
  • MUMPS
  • OLAP
  • SQLBase
  • SAS
  • GIS & GPS
  • 4GL
  • Berkeley DB
  • DB2
  • Informix
  • Interbase / Firebird
  • FoxPro
  • Reporting
  • LDAP
  • Filemaker Pro
  • MS SQL Server
  • dBase
  • MS Access
Security
  • Misc
  • Web Browsers
  • Software Firewalls
  • Operating Systems Security
  • File Sharing
  • Spy / Ad Blockers
  • Vulnerabilities
  • WebApplications
  • IDS
  • Anti-Virus
  • Encryption
  • Anti Spam
  • Email Clients
  • VPN
  • Chat / IM
Programming
  • Editors IDEs
  • Installation
  • Handhelds / PDAs
  • Multimedia Programming
  • System / Kernel
  • Algorithms
  • Game
  • Signal Processing
  • Project Management
  • Open Source
  • Database
  • Misc
  • Languages
  • Processor Platforms
  • Theory
Web Development
  • Scripting
  • Blogs
  • Web Servers
  • Software
  • Search Engines
  • Web Graphics
  • Images
  • Internet Marketing
  • Images and Photos
  • Components
  • Document Imaging
  • Web Languages/Standards
  • Illustration
  • WebApplications
  • Fonts
  • WebTrends / Stats
  • Authoring
  • Digital Camera Software
  • Miscellaneous
Networking
  • Protocols
  • Apple Networking
  • Network Management
  • Message Queue
  • Application Servers
  • Content Management
  • File Servers
  • Email Servers
  • Misc
  • Java Editors & IDEs
  • Wireless
  • Networking Hardware
  • Backup / Restore
  • System Utilities
  • ISPs & Hosting
  • Web Servers
  • Storage Technology
  • Removable Backup Media
  • Servers
  • Broadband
  • Grid
  • OS / 2
  • Novell Netware
  • Unix Networking
  • Windows Networking
  • Security
  • Telecommunications
  • Operating Systems
  • Linux Networking
Other
  • Community Advisor
  • Lounge
  • Community Support
  • New Net Users
  • Philosophy / Religion
  • Math / Science
  • Miscellaneous
  • URLs
  • Expert Lounge
  • Politics
  • Puzzles / Riddles
Community Support
  • Suggestions
  • New to EE
  • New Topics
  • Community Advisor
  • CleanUp
  • Announcements
  • General
  • Feedback
  • Input
  • EE Bugs
 
04.15.2008 at 05:08AM PDT, ID: 21357819

Rank: Genius

access-list 110 deny   ip 10.19.16.0 0.0.0.255 10.0.0.0 0.0.0.255
access-list 110 deny ip 10.19.16.0. 0.0.0.255 192.168.111.0 0.0.0.255  <<==== ADD THIS
access-list 110 permit ip 10.19.16.0 0.0.0.255 any
 
04.15.2008 at 07:07AM PDT, ID: 21358807

Irmoore,

access-list 110 deny   ip 10.19.16.0 0.0.0.255 10.0.0.0 0.0.0.255
access-list 110 deny ip 10.19.16.0. 0.0.0.255 192.168.111.0 0.0.0.255  <<==== ADD THIS
access-list 110 permit ip 10.19.16.0 0.0.0.255 any
 
That worked! Thanks. ACLs always get me confused.
 
04.15.2008 at 04:54PM PDT, ID: 21363763

Rank: Genius

Glad it worked out for you.
This particular ACL's purpose is to bypass NAT for the VPN traffic (denied through NAT), and permit all other traffic to be natted.
 
 
20080236-EE-VQP-29 / EE_QW_2_20070628