 TedS @skyepartners.org | Phase 1 comes up on one direction only We are trying to build a ipsec vpn L2L tunnel between a Cisco 2811 router and Cisco VPN 3000 concentrator, using ESP/SHA/HMAC-160.
we can bring up the tunnel when we initiate traffic from the 2811 router but we cannot bring it up when traffic is initiated from the concentrator or it never gets through phase 1.
Any input is appreciated.
Thank you |
|
 | The configs from both sides (minus your sensitive stuff) would be helpful to start.
Regards |
|
 | reply to TedS Try doing a "sh run | section crypto" on each device to do a line-by-line comparison and then check to see if either the "transform-set" or "set peer" address (under "crypto map") is misconfigured.
Also, if your run "debug crypto isakmp" that should tell you "exactly" where the issue is.
Jay |
|