troubleshooting Question

Cisco L2L VPN problems Phase 2

Avatar of Member_2_7966454
Member_2_7966454 asked on
CiscoVPNInternet Protocol SecurityHardware Firewalls
3 Comments1 Solution162 ViewsLast Modified:
I have trouble to setup a VPN to another Firewall, for now, it isn't working.

Logging rule i see:

Group = X.X.X.X, IP = X.X.X.X, IKE Initiator: New Phase 2, Intf outside, IKE Peer X.X.X.X  local Proxy Address Y.Y.Y.Y, remote Proxy Address Z.Z.Z.Z,  Crypto map (outside_map)

X.X.X.X = external IP address from remote firewall
Y.Y.Y.Y = Internal IP range on our firewall
Z.Z.Z.Z = internal IP range on remote firewall

Is this correct? is this just a warning I can ignore, or what did I wrong?


crypto map outside_map XX match address outside_32_cryptomap_1
crypto map outside_map XX set peer X.X.X.X
crypto map outside_map XX set transform-set ESP-AES-256-SHA
crypto map outside_map XX set security-association lifetime seconds 3600

access-list outside_32_cryptomap_1 extended permit ip object-group XXXXXXXXX object-group XXXXXXXXX

If I disable PFS isn't working, then I don't pass Phase 1.

Thanks a lot

Our community of experts have been thoroughly vetted for their expertise and industry experience.

Join our community to see this answer!
Unlock 1 Answer and 3 Comments.
Start Free Trial
Learn from the best

Network and collaborate with thousands of CTOs, CISOs, and IT Pros rooting for you and your success.

Andrew Hancock - VMware vExpert
See if this solution works for you by signing up for a 7 day free trial.
Unlock 1 Answer and 3 Comments.
Try for 7 days

”The time we save is the biggest benefit of E-E to our team. What could take multiple guys 2 hours or more each to find is accessed in around 15 minutes on Experts Exchange.

-Mike Kapnisakis, Warner Bros