troubleshooting Question

Vyatta & Adtran IPSEC VPN Help

Avatar of LeviDaily
LeviDailyFlag for United States of America asked on
RoutersVPNInternet Protocol Security
3 Comments2 Solutions2215 ViewsLast Modified:
I have a Vyatta instance running in Amazon EC2. I have an Adtran router at our office on our Comcast internet connection. I am wanting to create a site to site vpn with the two.

My Adtran router public IP is 173.12.191.XXX & internal is 192.168.0.1
My Vyatta (Amazon Elastic IP) is 50.18.193.XXX & eth0 ip is 10.243.175.10

I have the site to site VPN configured and am getting the IKE UP and IPSEC down. I am not too sure where to start. On the Vyatta when I run "show vpn debug peer 173.12.191.XXX tunnel 1" and am getting the below error


vyatta@VyattaAMI:~$ show vpn debug peer 173.12.191.XXX tunnel 1
000 "peer-173.12.191.XXX-tunnel-1": 10.243.175.0/24===10.243.175.10[10.243.175.10]...173.12.191.XXX[173.12.191.XXX]===192.168.0.0/24; unrouted; eroute owner: #0
000 "peer-173.12.191.XXX-tunnel-1":   ike_life: 28800s; ipsec_life: 28800s; rekey_margin: 540s; rekey_fuzz: 100%; keyingtries: 0
000 "peer-173.12.191.XXX-tunnel-1":   policy: PSK+ENCRYPT+TUNNEL+UP; prio: 24,24; interface: eth0;
000 "peer-173.12.191.XXX-tunnel-1":   newest ISAKMP SA: #0; newest IPsec SA: #0;
000 #67: "peer-173.12.191.XXX-tunnel-1" STATE_MAIN_I3 (sent MI3, expecting MR3); EVENT_RETRANSMIT in 13s
000 #67: pending Phase 2 for "peer-173.12.191.XXX-tunnel-1" replacing #0


Not too sure where to start, but feel like I am close?? If anyone can let me know what I need to do, I will gladly do it.
ASKER CERTIFIED SOLUTION
Steve JenningsNetwork Development Engineer

Our community of experts have been thoroughly vetted for their expertise and industry experience.

Join our community to see this answer!
Unlock 2 Answers and 3 Comments.
Start Free Trial
Learn from the best

Network and collaborate with thousands of CTOs, CISOs, and IT Pros rooting for you and your success.

Andrew Hancock - VMware vExpert
See if this solution works for you by signing up for a 7 day free trial.
Unlock 2 Answers and 3 Comments.
Try for 7 days

”The time we save is the biggest benefit of E-E to our team. What could take multiple guys 2 hours or more each to find is accessed in around 15 minutes on Experts Exchange.

-Mike Kapnisakis, Warner Bros