ok problem solved.
the isp this afternoon reexamined their equipment. still not finding any port blockage, completely cleared their configuration. the cisco vpn then became operational.
i would still like to know if anyone has a better way to trouble shoot the outside connections. thanks for...
hello all,
this weekend i pulled both routers off line (one at a time) and tested in an off line mockup. all security associations were established without problem.
the isp claims to be blocking nothing that would affect the sa's. my port scans show end to end connectivity for port 500 although...
yes, i do have a spare router,in fact a mockup was done successfully before installation on the network. the configuration has changed since then with the addition of the 192 network on fstpres. in retrospect the configuration was not tested thoroughly enough, i didnt read the debug output but...
let me clarify my last post, i first enabled cef and then tested with ping. then ip route-cache was disabled on e1/0 and tested with ping. neither has been returned to its initial state.
hi,
yes i can ping the outside interfaces of each router from inside the other router and from the nat inside nodes. everything is functional except the vpn.
i've run a port scanner on both exterior interfaces to check port 500 and it seems to be open. the isp indicates that there are no ports...
hi guys, i.m having problems establishing a vpn between a 2610 ios c2600-ik9o3s-mz.122-10a and a 3620 ios c3620-ik9o3s6-mz.123-9a. copied below are the debug ipsec/isakmp outputs.
i,m a relative newby so be nice, but it seems unusual to me that i only get debug info from the initiating router...
This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
By continuing to use this site, you are consenting to our use of cookies.