Cisco Pix site to Site VPN

I am adding a new location to an existing Cisco site to site VPN.  

We cannot get the new sites VPN tunnel up.

Can someone help?  I've attached the configs.  The main site already has another VPN connected to it. and its working fine.  I've verified the IP addresses in the config are correct.  There is Internet Access on the new site.  Just no VPN tunnel.
Who is Participating?
Jody LemoineConnect With a Mentor Network ArchitectCommented:
On your main site PIX, you have the following statements:

access-list 101 permit ip
access-list 102 permit ip
nat (inside) 0 access-list 101

This will prevent traffic to your first site's address space from being translated, which allows it to work properly.  You're not doing the same for your second site's and so traffic to it is subject to NAT and will be coming from the wrong IP address.  Try adding the following:

access-list 100 permit ip
access-list 100 permit ip
no nat (inside) 0 access-list 101
nat (inside) 0 access-list 100

This will create a new access list covering both sites for your NAT exception rule.
mschiradAuthor Commented:
mschiradAuthor Commented:
yes of course!

thanks so much!
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

All Courses

From novice to tech pro — start learning today.