Solved

revive site to site cisco VPN Tunnel

Posted on 2009-06-29
2
350 Views
Last Modified: 2012-05-07
I have 2 firewalls that I have inherited.  Unfortunately I only really understand the ASDM and ever then not to well.

These 2 firewall did have a tunnel between them at one time.  However it was deleted.

However it was not deleted completely, there are still elements of the old tunnel in both firewalls.  Becuase of this ASDM will not let me create a new tunnel as some of the IP Addresses overlap.

What components are necessary for a site to site tunnel?  All the documentation either points to using ASDM, but how to I manually add the missing pieces?

What CLI commands do I run to figure out what is missing, so that I can add them via the CLI?
0
Comment
Question by:brittonv
2 Comments
 
LVL 76

Expert Comment

by:arnold
ID: 24738311
You should start from collecting information about each side.
What information is present and what information is missing for each from the other?
The missing information could be the peer on each side, preshared key, certificate, etc..


0
 
LVL 34

Accepted Solution

by:
Istvan Kalmar earned 500 total points
ID: 24740409
You sholud look booth side:

sh cry isakmp policy
sh cry isakmp key
sh cry ipsec transform-set
sh cry ipsec security-association

It is good if are same on booth side

after you shuld look access-list configs:

ip access-list extended FSZEK_IPSEC
 permit ip x.x.x.x wildcard network address z.z.z.z wildcard network

after you shuld look crypto map configs:

crypto map xxx10 ipsec-isakmp
 set peer zz.zz.zz.zz
 set security-association lifetime seconds 28800
 set transform-set myset
 match address zzzzz_IPSEC

After you should put the outside interface!



0

Featured Post

What Should I Do With This Threat Intelligence?

Are you wondering if you actually need threat intelligence? The answer is yes. We explain the basics for creating useful threat intelligence.

Join & Write a Comment

Suggested Solutions

If you have an ASA5510 then this sort of thing would be better handled with a CSC Module, however on an ASA5505 thats not an option, and if you want to throw in a quick solution to stop your staff going to facebook during work time, then this is the…
Overview The Cisco PIX 501, PIX 506e, ASA 5505 and ASA 5510 (most if not all of this information will be relevant to the PIX 515e but I do not have a working configuration handy to verify the validity) are primarily used within small to medium busi…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

758 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

20 Experts available now in Live!

Get 1:1 Help Now