Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations bkrike on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

VPN not working if restricted.

Status
Not open for further replies.

PGRAYSON

MIS
Nov 2, 2001
54
GB
Attempting to allow a customer with a 7000 series router into our PIX via VPN.

I can get the VPN to work fine if I remove all restrictions on both inbound and outbout addresses. However as soon as I add a restriction on either interface, to permit access to or from a specific IP address or subnet, then the connection breaks altogether.

The following appears in the console log:
ISAKMP: IPSec policy invalidated proposal
ISAKMP (0): SA not acceptable!
ISAKMP (0): sending NOTIFY message 14 protocol 3
return status is IKMP_ERR_NO_RETRANS
crypto_isakmp_process_block:src:x.x.x.x, dest:y.y.y.y spt:500 dpt:500

Any ideas?
 
I've resolved it by getting the remote end to set exactly the same access list as this end. It seems that if the lists don't match in this way then no traffic seems to get through.

What could be causing this; it makes configuration a problem as the other site is not under our control, and the same sort of thing doesn't apply to another VPN we have running.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top