Solved

revive site to site cisco VPN Tunnel

Posted on 2009-06-29
2
353 Views
Last Modified: 2012-05-07
I have 2 firewalls that I have inherited.  Unfortunately I only really understand the ASDM and ever then not to well.

These 2 firewall did have a tunnel between them at one time.  However it was deleted.

However it was not deleted completely, there are still elements of the old tunnel in both firewalls.  Becuase of this ASDM will not let me create a new tunnel as some of the IP Addresses overlap.

What components are necessary for a site to site tunnel?  All the documentation either points to using ASDM, but how to I manually add the missing pieces?

What CLI commands do I run to figure out what is missing, so that I can add them via the CLI?
0
Comment
Question by:brittonv
2 Comments
 
LVL 78

Expert Comment

by:arnold
ID: 24738311
You should start from collecting information about each side.
What information is present and what information is missing for each from the other?
The missing information could be the peer on each side, preshared key, certificate, etc..


0
 
LVL 34

Accepted Solution

by:
Istvan Kalmar earned 500 total points
ID: 24740409
You sholud look booth side:

sh cry isakmp policy
sh cry isakmp key
sh cry ipsec transform-set
sh cry ipsec security-association

It is good if are same on booth side

after you shuld look access-list configs:

ip access-list extended FSZEK_IPSEC
 permit ip x.x.x.x wildcard network address z.z.z.z wildcard network

after you shuld look crypto map configs:

crypto map xxx10 ipsec-isakmp
 set peer zz.zz.zz.zz
 set security-association lifetime seconds 28800
 set transform-set myset
 match address zzzzz_IPSEC

After you should put the outside interface!



0

Featured Post

Microsoft Certification Exam 74-409

Veeam® is happy to provide the Microsoft community with a study guide prepared by MVP and MCT, Orin Thomas. This guide will take you through each of the exam objectives, helping you to prepare for and pass the examination.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Resource timeout across a VPN 9 31
Voice VLANs across Metro-E 4 38
TZ400 VPN Clients 5 30
Problems with VPN 4 28
This article will cover setting up redundant ISPs for outbound connectivity on an ASA 5510 (although the same should work on the 5520s and up as well).  It’s important to note that this covers outbound connectivity only.  The ASA does not have built…
I've written this article to illustrate how we can implement a Dynamic Multipoint VPN (DMVPN) with both hub and spokes having a dynamically assigned non-broadcast multiple-access (NBMA) network IP (public IP). Here is the basic setup of DMVPN Pha…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

730 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question