Site to Site VPN Establishes Tunnel - Unable to Pass Traffic

Posted on 2009-05-15
Medium Priority
Last Modified: 2012-05-07
All my site to site VPN users are able to establish the tunnel and pass phase 1 and 2.  They are unable to access the servers/workstations on our network.  Our PPTP VPN users are working as normal.  All connections were working fine until we replaced a core switch in our main location.  We are running the same build on this switch as the one we replaced.  I feel this is a security issue on the switch, but unable to pinpoint. Any help is appreciated.
Question by:AdminBWC
LVL 13

Accepted Solution

Quori earned 375 total points
ID: 24407698
What is terminating the IPsec tunnels? Can you provide a network diagram and any relevant configs?

Assisted Solution

equarando earned 375 total points
ID: 24419307
Please post make and model of switches/hardware and configs

Author Comment

ID: 24425324
Thanks to you both for responding, but we were able to resolve the issue with Cisco support.  It was not a logical resolve as no one can tell me "why" it occurred, but they did find a fix.  When asked why it had been working fine for years and now it is not, I believe the term "magic" occurred in one engineer's response.  
And to help those with the same issue in the future, ACLs permitting outside traffic coming in had to be added for all my crypto clients. Clients running just fine for up to 3 years without any problem and no changes just magically stopped working.
I'm giving the points to both of you even though the issue was resolved on my end.  Good day to you both!

Featured Post

WEBINAR: GDPR Implemented - Tips & Lessons Learned

Join the WatchGuard team on Thursday, March 29th as we recount some valuable lessons learned in weighing the needs of a business against the new regulatory environment, look ahead at the two months left before implementation, and help you understand the steps you can take today!

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

Join & Write a Comment

I've written this article to illustrate how we can implement a Dynamic Multipoint VPN (DMVPN) with both hub and spokes having a dynamically assigned non-broadcast multiple-access (NBMA) network IP (public IP). Here is the basic setup of DMVPN Pha…
If you use NetMotion Mobility on your PC and plan to upgrade to Windows 10, it may not work unless you take these steps.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Windows 10 is mostly good. However the one thing that annoys me is how many clicks you have to do to dial a VPN connection. You have to go to settings from the start menu, (2 clicks), Network and Internet (1 click), Click VPN (another click) then fi…

619 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question