Want to protect your cyber security and still get fast solutions? Ask a secure question today.Go Premium

x
  • Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 279
  • Last Modified:

Cisco 506E to 506E Site to Site with preshared key

Connecting:

506E-1

internal
192.168.1.1
255.255.255.0

506E-2
192.168.134.1
255.255.0.0

Have followed the standard configs for setting up a site to site with preshared keys. Show isakmp sa shows that a connection is successfully made. No traffic passes (or even attempts to pass, according to syslog) between the sites. Do I need some kind of route command due to the different subnets?
0
a32aw11sc
Asked:
a32aw11sc
  • 2
1 Solution
 
lrmooreCommented:
Fundamental issue here:
  192.168.134.1
   255.255.0.0  <== subnet mask *must* be 255.255.255.0

Else, it overlaps with the remote network, and no traffic will ever flow, because to the #2 pix, all 192.168.x.x traffic, including 192.168.1.x is "local" and no need to pass through the VPN..

0
 
HeinekevCommented:
lrmoore has hit the nail on the head with this one.  The only other issue could be your access-lists, but even with proper access-lists, the aforementioned subnet problem would break it anyway.
0
 
lrmooreCommented:
Are you still working on this?
Have you found a solution?
Do you need more information?

This question will be classified as abandoned soon if we don't get some feedback from you.

Can you close out this question? See here for details:
http://www.experts-exchange.com/help.jsp#hs5

Thanks for your attention!
0

Featured Post

Hire Technology Freelancers with Gigs

Work with freelancers specializing in everything from database administration to programming, who have proven themselves as experts in their field. Hire the best, collaborate easily, pay securely, and get projects done right.

  • 2
Tackle projects and never again get stuck behind a technical roadblock.
Join Now