Cisco Pix site to Site VPN

I am adding a new location to an existing Cisco site to site VPN.  

We cannot get the new sites VPN tunnel up.

Can someone help?  I've attached the configs.  The main site already has another VPN connected to it. and its working fine.  I've verified the IP addresses in the config are correct.  There is Internet Access on the new site.  Just no VPN tunnel.
mschiradAsked:
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

mschiradAuthor Commented:
Jody LemoineNetwork ArchitectCommented:
On your main site PIX, you have the following statements:

access-list 101 permit ip 192.168.1.0 255.255.255.0 192.168.2.0 255.255.255.0
access-list 102 permit ip 192.168.1.0 255.255.255.0 192.168.3.0 255.255.255.0
nat (inside) 0 access-list 101

This will prevent traffic to your first site's 192.168.2.0/24 address space from being translated, which allows it to work properly.  You're not doing the same for your second site's 192.168.3.0/24 and so traffic to it is subject to NAT and will be coming from the wrong IP address.  Try adding the following:

access-list 100 permit ip 192.168.1.0 255.255.255.0 192.168.2.0 255.255.255.0
access-list 100 permit ip 192.168.1.0 255.255.255.0 192.168.3.0 255.255.255.0
no nat (inside) 0 access-list 101
nat (inside) 0 access-list 100

This will create a new access list covering both sites for your NAT exception rule.

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
mschiradAuthor Commented:
yes of course!

thanks so much!
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Cisco

From novice to tech pro — start learning today.