Troubleshooting a Cisco Router VPN tunnel

Posted on 2004-08-12
Last Modified: 2010-04-17
I'm having a challenge troubleshooting a 1 way VPN tunnel terminating at my Cisco 3620 router and customers Checkpoint Firewall. After debugging the crypto I know the tunnel is built and I can successfully send ICMP traffic into their internal network, however TCP traffic doesn’t flow. The customer indicates he doesn’t see TCP traffic hitting his Firewall. I have 2 other VPN connections built in a similar configuration and they work fine TCP and ICMP. I've run out of ideas.
Question by:ubergenius
LVL 13

Accepted Solution

td_miles earned 100 total points
ID: 11789171
Assuming that you have an access-list to define interesting traffic to be encrypted, enable logging of the ACL, then see if the traffic you are attempting to send is matching the acl (and hence being encrypted on your ends).

Also ensure that the ACL's that you are using match identically on both ends.
LVL 50

Expert Comment

by:Don Johnston
ID: 15651278
No comment has been added to this question in more than 21 days, so it is now classified as abandoned..
I will leave the following recommendation for this question in the Cleanup topic area:

RECOMMENDATION: Delete - No Refund

Any objections should be posted here in the next 4 days. After that time, the question will be closed.

EE Cleanup Volunteer

Featured Post

Is Your Active Directory as Secure as You Think?

More than 75% of all records are compromised because of the loss or theft of a privileged credential. Experts have been exploring Active Directory infrastructure to identify key threats and establish best practices for keeping data safe. Attend this month’s webinar to learn more.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Wifi(LAN) GW being picked up 2 45
Can Cisco resolve internet address internally 4 34
Cisco 4500 - Supervisor cards and licensing 2 47
Destination host unreachable 12 69
The Cisco RV042 router is a popular small network interfacing device that is often used as an internet gateway. Network administrators need to get at the management interface to make settings, change passwords, etc. This access is generally done usi…
In the world of WAN, QoS is a pretty important topic for most, if not all, networks. Some WAN technologies have QoS mechanisms built in, but others, such as some L2 WAN's, don't have QoS control in the provider cloud.
After creating this article (, I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (, I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

895 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

12 Experts available now in Live!

Get 1:1 Help Now