Solved

Unable to establish VPN tunnel between ASA 5505 and PIX 515E

Posted on 2008-10-10
4
565 Views
Last Modified: 2011-09-20
We have two offices in the same building. We have a cable run between the two offices. Security policy dictates that we encrypt the data that passes between the two offices. We have a Cisco PIX 515E in Office A and a Cisco ASA 5505 in Office B. They are directly connected with a cat5 cable.... so they're on the same subnet.

I've been unable to get a tunnel working between the two devices - all of the encryption and key exchange settings and PFS settings match - and I've tried several different combinations of DES, 3DES, AES, etc. but it makes no difference. I'm seeing nothing on the PIX when I run 'debug crypto isakmp'.

I have IPSEC rules at each end that match all ip and icmp traffic from the relevant inside networks to the remote side's inside network and visa versa.

I used the wizards to build the config.

Is it a problem that they're on the same subnet?
0
Comment
Question by:tlcsupport
  • 2
4 Comments
 
LVL 2

Expert Comment

by:scottbortis
ID: 22689281
Check this document
http://www.cisco.com/en/US/tech/tk583/tk372/technologies_configuration_example09186a00800ef796.shtml

may give you an idea what you are up against.
0
 
LVL 1

Author Comment

by:tlcsupport
ID: 22689865
Thanks for the link. I've done a bit of reading and I *think* the problem is down to the fact that the VPN tunnel it not going over the 'out' interface of the PIX, but a tertiary interface. I've not routed the traffic out of this interface, so it's probably attempting to go out of the 'out' interface as this is the default route.

Gonna give the routing and NAT a closer look in the morning.
0
 
LVL 28

Expert Comment

by:batry_boy
ID: 22690128
Post your configs and let's have a look...
0
 
LVL 1

Accepted Solution

by:
tlcsupport earned 0 total points
ID: 22694950
okay, so it was routing. Basically, if the traffic doesn't flow properly before implementing the ipsec, the ipsec isn't going to establish.

Found this link quite useful:

http://www.cisco.com/en/US/products/ps6120/products_tech_note09186a00807e0aca.shtml
0

Featured Post

Windows Server 2016: All you need to know

Learn about Hyper-V features that increase functionality and usability of Microsoft Windows Server 2016. Also, throughout this eBook, you’ll find some basic PowerShell examples that will help you leverage the scripts in your environments!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Some of you may have heard that SonicWALL has finally released an app for iOS devices giving us long awaited connectivity for our iPhone's, iPod's, and iPad's. This guide is just a quick rundown on how to get up and running quickly using the app. …
From Cisco ASA version 8.3, the Network Address Translation (NAT) configuration has been completely redesigned and it may be helpful to have the syntax configuration for both at a glance. You may as well want to read official Cisco published AS…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Both in life and business – not all partnerships are created equal. As the demand for cloud services increases, so do the number of self-proclaimed cloud partners. Asking the right questions up front in the partnership, will enable both parties …

813 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

18 Experts available now in Live!

Get 1:1 Help Now