troubleshooting Question

cisco 837 VPN Tunnel

Avatar of awilderbeast
awilderbeastFlag for United Kingdom of Great Britain and Northern Ireland asked on
RoutersVPN
57 Comments1 Solution1916 ViewsLast Modified:
hi im trying to use my cisco 837 to connect my to private networks together

my 192.168.170.0/24 and 192.168.174.0/24 networks

the .170 address has a static global io whilst the 174 netowrk has a dynamic global ip

i have been told the below info about the static end (it is the dynamic end im configuring)
213.249.241.43
192.168.170.0/24
IPSec ike
pre shared keyword is "xxxxxxxxxxxxxxx"
3des
sha

im currentyl studying for icnd2 and its a little out my depth at the moment so tryint to do my best...

i just found this guide n cisco and followed the CLI commands fr the dr_whoovie router

http://www.cisco.com/en/US/tech/tk583/tk372/technologies_configuration_example09186a0080093f86.shtml 

hwever upon applying the crypto map ptc to the dialer1 interface i lsot cnnectin to the web and the tunnel didnt work below is my config befre i tk off the crypto map

how am i doing?
and can anyone help me make it work?

Thanks


Current configuration : 2734 bytes
!
version 12.3
no service pad
service timestamps debug datetime msec
service timestamps log datetime msec
service password-encryption
!
hostname CWADSL
!
enable secret 5 xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
!
username xxxxxxxxxx privilege 15 password 7 xxxxxxxxxxxxxxxxxxxxxxxxx
 
no aaa new-model
ip subnet-zero
ip domain name cityworks.org.uk
!
!
ip audit notify log
ip audit po max-events 100
no ftp-server write-enable
!
!
!
!
crypto isakmp policy 1
 encr 3des
 authentication pre-share
crypto isakmp key 0 xxxxx address 192.168.175.1
crypto isakmp key 0 xxxxxx address 213.249.241.43
!
!
crypto map ptc 1 ipsec-isakmp
 ! Incomplete
 set peer 213.249.241.43
!
!
!
!
interface Loopback0
 ip address 192.1.1.1 255.255.255.0
 ip nat inside
!
interface Ethernet0
 ip address 192.168.175.1 255.255.255.0
 ip nat inside
 hold-queue 100 out
!
interface ATM0
 description LAN
 no ip address
 no atm ilmi-keepalive
 pvc 1/50
  dialer pool-member 1
  protocol ppp dialer
 !
 dsl operating-mode auto
!
interface FastEthernet1
 no ip address
 duplex auto
 speed auto
!
interface FastEthernet2
 no ip address
 shutdown
 duplex auto
 speed auto
!
interface FastEthernet3
 no ip address
 shutdown
 duplex auto
 speed auto
!
interface FastEthernet4
 no ip address
 shutdown
 duplex auto
 speed auto
!
interface Dialer1
 description ADSL Dialer to Karoo
 ip address negotiated
 ip nat outside
 encapsulation ppp
 dialer pool 1
 ppp chap hostname xxxxxxxxxxxxxxxxxxxxxxxxxx@kcinternet
 ppp chap password 7 xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
 crypto map ptc
!
ip nat inside source list 1 interface Dialer1 overload
ip nat inside source list 100 interface Dialer1 overload
ip nat inside source route-map nonat interface Dialer1 overload
ip nat inside source static tcp 192.168.175.2 500 interface Dialer1 500
ip classless
ip route 0.0.0.0 0.0.0.0 Dialer1
ip http server
ip http authentication local
ip http secure-server
ip http timeout-policy idle 600 life 86400 requests 10000
!
access-list 100 permit ip 192.168.175.0 0.0.0.255 any
access-list 101 permit ip 192.168.175.0 0.0.0.255 192.168.170.0 0.0.0.255
access-list 101 deny   ip 192.168.175.0 0.0.0.255 any
access-list 102 deny   ip 192.168.175.0 0.0.0.255 192.168.170.0 0.0.0.255
access-list 102 permit ip 192.168.175.0 0.0.0.255 any
route-map nonat permit 10
 match ip address 102
!
tftp-server flash
tftp-server system
tftp-server webflash
tftp-server nvram
tftp-server null
!
line con 0
 no modem enable
line aux 0
line vty 0 4
 privilege level 15
 password 7 xxxxxxxxxxxxxxxxxxxxxxxxx
 login local
 transport input telnet ssh
!
scheduler max-task-time 5000
!
end
Join the community to see this answer!
Join our exclusive community to see this answer & millions of others.
Unlock 1 Answer and 57 Comments.
Join the Community
Learn from the best

Network and collaborate with thousands of CTOs, CISOs, and IT Pros rooting for you and your success.

Andrew Hancock - VMware vExpert
See if this solution works for you by signing up for a 7 day free trial.
Unlock 1 Answer and 57 Comments.
Try for 7 days

”The time we save is the biggest benefit of E-E to our team. What could take multiple guys 2 hours or more each to find is accessed in around 15 minutes on Experts Exchange.

-Mike Kapnisakis, Warner Bros