Solved

Site to Site VPN - cannot ping

Posted on 2007-11-21
5
818 Views
Last Modified: 2008-02-01
All,

I created a vpn tunnel between my office (Cisco ASA 5520) and home (SonicWall TZ 170 StandardOS)using 3DES MD5, Aggressive Mode and PFS.  My home network is using 192.168.90.0/24 and is connected to the OPT port of the Sonicwall.  My office LAN is 10.60.0.0/16 and 10.50.0.0/16.  The VPN tunnel is established however I cannot ping across and all my settings look correct.  Any ideas?
0
Comment
Question by:bigz71
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
  • 2
5 Comments
 
LVL 12

Expert Comment

by:dlan75
ID: 20333022
Hi,
I guess you connect from home to your office.
How do you connect ? Do you use the Cisco VPN client ? When you are connected, can you check your IPs to see if you get a new one from your vpn ?
0
 
LVL 4

Expert Comment

by:CCIE8122
ID: 20335177
Umm, he is doing site-to-site, not RAS VPN.

Can you post debug output of the following on the ASA:

deb cry is sa
deb cry ip sa

Without that, it is nearly impossible to say what the issue is.

kr
0
 

Author Comment

by:bigz71
ID: 20335361
CCIE8122,

I'm still new with Cisco and not exactly sure how to use the debug commands.  I ran the commands you asked and get an error the command is not found.

fw# debug cry is sa
                 ^
ERROR: % Invalid input detected at '^' marker.
fw#

0
 
LVL 4

Accepted Solution

by:
CCIE8122 earned 75 total points
ID: 20339113
sorry, dont need the trailing "sa."  should be

debug crypto isakmp
debug crypto ipsec

(you can abbreviate these if you wish)

also make sure you are logging to the console:

logging on
logging monitor debugging
terminal monitor

when you are done:

undebug all
0
 

Author Comment

by:bigz71
ID: 20339896
I was able to fix the problem by recreating the VPN tunnel.  Thanks for your help and points will be awarded to you.
0

Featured Post

NFR key for Veeam Backup for Microsoft Office 365

Veeam is happy to provide a free NFR license (for 1 year, up to 10 users). This license allows for the non‑production use of Veeam Backup for Microsoft Office 365 in your home lab without any feature limitations.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Concerto Cloud Services, a provider of fully managed private, public and hybrid cloud solutions, announced today it was named to the 20 Coolest Cloud Infrastructure Vendors Of The 2017 Cloud  (http://www.concertocloud.com/about/in-the-news/2017/02/0…
Let’s face it: one of the reasons your organization chose a SaaS solution (whether Microsoft Dynamics 365, Netsuite or SAP) is that it is subscription-based. The upkeep is done. Or so you think.
Windows 10 is mostly good. However the one thing that annoys me is how many clicks you have to do to dial a VPN connection. You have to go to settings from the start menu, (2 clicks), Network and Internet (1 click), Click VPN (another click) then fi…
As a trusted technology advisor to your customers you are likely getting the daily question of, ‘should I put this in the cloud?’ As customer demands for cloud services increases, companies will see a shift from traditional buying patterns to new…
Suggested Courses
Course of the Month7 days, 20 hours left to enroll

617 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question