Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations bkrike on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

PIX 501 Lan to Lan VPN with Cisco Concentrator

Status
Not open for further replies.

vasquea1

IS-IT--Management
Dec 18, 2002
47
US
Well our Cisco guy just quit on friday and one of our clients replaced his PIX 501 and can not connect to our 3015 Cisco Concentrator for a LAN to LAN VPN. He says all the setting are the same. Do I need to do anything on my end. This client says his other tunnels came back up with other clients.
 
First and foremost, make sure the Preshare keys weren't changed and not saved on their FW.
 
nothing on our end has changed. They connected to us this morning with the old pix.
 
That's what I mean. If the preshare key changed and they didn't do a write mem since the change, the key on their end would be the one from the last time it was saved, assuming they built the new PIX from the old one's config.
 
If it is a matter of a botched key or ACL then the your concentrator event log is pretty good place to look for a quick answer.
You might have to turn on the events that you need to appear
first though, under config/events/classes Send IPSEC and IKE stuff to the log. The menu structure has changed a little with different software versions, so their example might not be exact, but the idea is the same.

Logging is under monitoring. If the keys mismatch it will outright tell you. Other problem might be mismatched access list, again it will tell you. You can watch the live monitor while you ping them and see what error you get.

You can view the key in plain text on the concentrator. On the pix end once it gets entered it is unviewable. My bet is with Narizz28 in that they botched their key
 
Thanks 308win, They fixed the problem on there end. I am with you guys with the botched Key. I am awaiting the solution from their end. Well keep ya posted.

MCSE lost in cisco lan
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top