<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>Topic &#x27;Need a Little help with Easy VPN&#x27; in forum &#x27;Cisco&#x27; - dslreports.com</title>
<link>http://www.dslreports.com/forum/Need-a-Little-help-with-Easy-VPN-8108888</link>
<description></description>
<language>en</language>
<pubDate>Wed, 19 Jun 2013 14:04:44 EDT</pubDate>
<lastBuildDate>Wed, 19 Jun 2013 14:04:44 EDT</lastBuildDate>

<item>
<title>Re: An Update</title>
<link>http://www.dslreports.com/forum/Re-An-Update-8266610</link>
<description><![CDATA[Gramzster posted :  <BLOCKQUOTE><SMALL>said by <a href="/profile/834366" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=834366');">Covenant</a>:</SMALL><HR>looks like you applied the crypto map to the wrong interface on the 806.<HR></BLOCKQUOTE><br><B> THANK YOU!!!!!</B><br><br>Man, I feel so stupid now.  I was doing this at 2am last night.... and I was so tired that I must not have realized what interface I accidentally placed the crypto map into.  I guess also, that I was gettin kinda frustrated with it today (and I was more focusing on the crypto commands) I just.... overlooked the mistake.<br><br>Thanks Again!<br><br>(now I just gotta combine this with the commands for the Easy VPN Clients.... but that shouldn't be that hard, and if it is, I know where ask :))]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-An-Update-8266610</guid>
<pubDate>Sat, 18 Oct 2003 21:30:37 EDT</pubDate>
</item>

<item>
<title>Re: An Update</title>
<link>http://www.dslreports.com/forum/Re-An-Update-8266408</link>
<description><![CDATA[Covenant posted : Hi  Gramzster <A HREF="/useremail/u/653135"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>,<br><br>After a quick eyeball through the configs, (and I apologise for the brevity of the eyeballing but it is 1.57am and I am HAMMERED :)), looks like you applied the crypto map to the wrong interface on the 806. Apply it to the interface:<br><br>Ethernet1<br> ip address dhcp<br> ip nat outside<br> no cdp enable<br><br>That's all I can spot in my current state, hey I could not even spot my house when I was walking down and ended up past my house, half-a-mile down so consider yourself lucky. LOL.<br><br>Try that and if you are still having problems, post again and I shall try to remain sober when I look over it again. ;)<br><small>--<br>When you post a question, you expect a reply. When I post a reply, I expect a response. Not only if the problem still exists, but also when it works. Its nice to know that the reply I gave works AND it also helps others with  that problem to solve it.</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-An-Update-8266408</guid>
<pubDate>Sat, 18 Oct 2003 20:59:53 EDT</pubDate>
</item>

<item>
<title>An Update</title>
<link>http://www.dslreports.com/forum/An-Update-8265991</link>
<description><![CDATA[Gramzster posted : Well, sorry for the late reply, however I think I have almost got it.... but I just it a small snag.<br>I tried using the configuration from &raquo;<A HREF="http://www.cisco.com/en/US/tech/tk583/tk372/technologies_configuration_example09186a00800946b8.shtml" >www.cisco.com/en/US/tech/tk583/t&middot;&middot;&middot;b8.shtml</A> - however I have run into a slight problem.<br><br>I have attached the configurations for both the 806 and the 2621.  Before I attached them, I used a word processor to replace the 806 IP address with <I>200.2.2.2</I> and the 2621 IP address with <I>100.1.1.1</I> . I have also replaced the key with <I>Test</I>.  I figured that it would be better to remove the actual ip addresses for security, and that it would also show that the ip addresses and keys entered are the same on both sides (as they wouldn't have been replaced by the text editor if they were different).<br><br><B>Now... aside from all I said above, here is the problem</B><br>Whenever I try to initiate data through the tunnel, it won't go through. Every time I try this, I receive an error message on the 2621:<br><B>*Mar  1 02:58:38.515: %CRYPTO-4-RECVD_PKT_NOT_IPSEC: Rec'd packet not an IPSEC packet.<br>        (ip) vrf/dest_addr= /100.1.1.1, src_addr= 200.2.2.2, prot= 47</B><br><br>I only receive this message on the 2621, not the 806.  Also, this message shows up if I try to establish traffic from either side.<br><br>Now, one odd thing I have found is that if I try (from the 806 CLI) to ping the 806's tunnel0 interface, it is successful. However, if I try (from the 2621 CLI) to ping the 2621's tunnel0 interface, it fails.<br><br>One final thing:  I did a check on the Cisco site to determine if I can find any solutions to that error message I stated above, however all I was able to find is that something might be wrong with the transform-set, even though it's the same on both sides.<br><br>Thanks for all of your help!<div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap WIDTH=33%><A HREF="/r0/download/450964~cc24c616eae35bd167ecfebb881d33c7/configfrom2621.zip"><IMG  align=absmiddle style="vertical-align:middle;" TITLE="download" SRC="http://i.dslr.net/silk/compress.png" border=0 width=16 height=16><IMG SRC="http://i.dslr.net/1ptrans.gif" WIDTH=10 HEIGHT=1 border=0><big>configfrom2621.zip</big></A> <small>921 bytes</small><br><small>(configfrom2621.txt)</small></TD><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap WIDTH=33%><A HREF="/r0/download/450965~1a3bc9efd90d246155a0820596cb9edd/configfrom806.zip"><IMG  align=absmiddle style="vertical-align:middle;" TITLE="download" SRC="http://i.dslr.net/silk/compress.png" border=0 width=16 height=16><IMG SRC="http://i.dslr.net/1ptrans.gif" WIDTH=10 HEIGHT=1 border=0><big>configfrom806.zip</big></A> <small>846 bytes</small><br><small>(configfrom806.txt)</small></TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/An-Update-8265991</guid>
<pubDate>Sat, 18 Oct 2003 20:00:32 EDT</pubDate>
</item>

<item>
<title>Re: Need a Little help with Easy VPN</title>
<link>http://www.dslreports.com/forum/Re-Need-a-Little-help-with-Easy-VPN-8200583</link>
<description><![CDATA[nozero posted : The post above was added to the FAQ here: <A HREF="http://www.dslreports.com/faq/8228">http://www.dslreports.com/faq/8228</A>.<br>:-)]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Need-a-Little-help-with-Easy-VPN-8200583</guid>
<pubDate>Sat, 11 Oct 2003 11:26:17 EDT</pubDate>
</item>

<item>
<title>Re: Need a Little help with Easy VPN</title>
<link>http://www.dslreports.com/forum/Re-Need-a-Little-help-with-Easy-VPN-8176897</link>
<description><![CDATA[Covenant posted :  <BLOCKQUOTE><SMALL>said by <a href="/profile/653135" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=653135');">Gramzster</a>:</SMALL><HR>I do have a quick question, When I was looking through the example configurations on the Cisco site, it seemed that GRE was what I wanted to try to configure, since it supported routing protocols.  Does this type of IPSEC tunnel also support routing protocols? (basically, what's the difference between a GRE tunnel, and this type of tunnel?) <HR></BLOCKQUOTE><br><br>In a nutshell, the VPN tunnel never forwards the routing broadcasts through the tunnels. Neither do they send the routing updates. To send the routing updates (so that the remote location can learn the network on the local side) you must use IPSec over GRE. With this feature,the routing updates are first encapsulated over a new GRE packet and then forwarded through the VPN tunnel. This is useful and required if you are using OSPF, RIP, EIGRP in your internal network and need to build a routing tunnel.<br><br><HR><br>Here's some more detail and links/differences between a pure IPSec vpn tunnel and a GRE over IPSec tunnel:<br><br>Pure IPSec vpn tunnel<br>=====================<br><br>In a pure IPSec vpn tunnel, only ip traffic is encrypted/decrypted.<br><br>If you have non ip traffic, example, ipx, then it is not able to go into the vpn tunnel.<br><br>OSPF, EIGRP, are not transferred in the tunnel.<br><br>The urls below might be helpful for you about IPSec,<br><br>&raquo;<A HREF="http://www.cisco.com/en/US/tech/tk583/tk372/technologies_tech_note09186a0080094203.shtml" >www.cisco.com/en/US/tech/tk583/t&middot;&middot;&middot;03.shtml</A><br><br>&raquo;<A HREF="http://www.cisco.com/en/US/netsol/ns110/ns170/ns172/ns334/networking_solutions_design_guide_chapter09186a008017e272.html" >www.cisco.com/en/US/netsol/ns110&middot;&middot;&middot;272.html</A><br><br>&raquo;<A HREF="http://www.cisco.com/en/US/products/sw/secursw/ps2133/products_user_guide_chapter09186a00800d9f4c.html" >www.cisco.com/en/US/products/sw/&middot;&middot;&middot;f4c.html</A><br><br>GRE over IPSec vpn tunnel<br>=========================<br><br>In a GRE over IPSec vpn tunnel, the original packet whether ip, ipx, etc... is first going to be GRE encapsulated and then this packet is then subjected to IPSec encapsulation.<br><br>Therefore, in a GRE over IPSec tunnel, all routing traffic (ip and non ip) can be routed through because when the original packet (ip/non ip) is GRE encapsulated, then it will have an ip header (as defined by the GRE tunnel (normally the tunnel interface ip addresses)) then the IPSec protocol can understand the ip packet and and can therefore be able to encapsulate the GRE packet to make it GRE over IPSec.<br><br>please visit the urls below for more info.,<br><br>&raquo;<A HREF="http://www.cisco.com/en/US/tech/tk583/tk372/technologies_tech_note09186a00800946ba.shtml" >www.cisco.com/en/US/tech/tk583/t&middot;&middot;&middot;ba.shtml</A><br><br>&raquo;<A HREF="http://www.cisco.com/en/US/tech/tk583/tk372/technologies_tech_note09186a0080094865.shtml" >www.cisco.com/en/US/tech/tk583/t&middot;&middot;&middot;65.shtml</A><br><br><HR><br>Last but not least, here's another link for a sample config. which uses GRE/IPSEC, CBAC and NAT but I am sure that you will be able to remove the CBAC if you do not want it.<br><br>Hope that helps.<br><br>&raquo;<A HREF="http://www.cisco.com/warp/public/707/quicktip.html" >www.cisco.com/warp/public/707/quicktip.html</A><br><small>--<br>When you post a question, you expect a reply. When I post a reply, I expect a response. Not only if the problem still exists, but also when it works. Its nice to know that the reply I gave works AND it also helps others with  that problem to solve it.</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Need-a-Little-help-with-Easy-VPN-8176897</guid>
<pubDate>Wed, 08 Oct 2003 16:45:17 EDT</pubDate>
</item>

<item>
<title>Re: Need a Little help with Easy VPN</title>
<link>http://www.dslreports.com/forum/Re-Need-a-Little-help-with-Easy-VPN-8170303</link>
<description><![CDATA[Gramzster posted :  <BLOCKQUOTE><SMALL>said by <a href="/profile/834366" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=834366');">Covenant</a>:</SMALL><HR>Let me know if this link works, if not post back and we will need to take a look at your config. to try to custom fit it around your requirements:<br><br>&raquo;<A HREF="http://www.cisco.com/en/US/tech/tk583/tk372/technologies_configuration_example09186a0080094634.shtml" >www.cisco.com/en/US/tech/tk583/t&middot;&middot;&middot;34.shtml</A><br><br>Good luck :).<HR></BLOCKQUOTE> Thanks, however I do remember doing that config, and I couldn't get it to work, (most likely I was really tired when I did it, and probably overlooked a portion of it.) What I'll try doing, is instead of adding it to my current configuration (Which is for the Cisco VPN Client), I'll try configuring it on the router from a 'clean slate' (config with no ipsec or isakmp entries) and go from there. <br><br>I do have a quick question, When I was looking through the example configurations on the Cisco site, it seemed that GRE was what I wanted to try to configure, since it supported routing protocols.  Does this type of IPSEC tunnel also support routing protocols? (basically, what's the difference between a GRE tunnel, and this type of tunnel?)]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Need-a-Little-help-with-Easy-VPN-8170303</guid>
<pubDate>Tue, 07 Oct 2003 21:42:28 EDT</pubDate>
</item>

<item>
<title>Re: Need a Little help with Easy VPN</title>
<link>http://www.dslreports.com/forum/Re-Need-a-Little-help-with-Easy-VPN-8169611</link>
<description><![CDATA[Covenant posted : Let me know if this link works, if not post back and we will need to take a look at your config. to try to custom fit it around your requirements:<br><br>&raquo;<A HREF="http://www.cisco.com/en/US/tech/tk583/tk372/technologies_configuration_example09186a0080094634.shtml" >www.cisco.com/en/US/tech/tk583/t&middot;&middot;&middot;34.shtml</A><br><br>Good luck :).<br><small>--<br>When you post a question, you expect a reply. When I post a reply, I expect a response. Not only if the problem still exists, but also when it works. Its nice to know that the reply I gave works AND it also helps others with  that problem to solve it.</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Need-a-Little-help-with-Easy-VPN-8169611</guid>
<pubDate>Tue, 07 Oct 2003 20:30:39 EDT</pubDate>
</item>

<item>
<title>Re: Need a Little help with Easy VPN</title>
<link>http://www.dslreports.com/forum/Re-Need-a-Little-help-with-Easy-VPN-8161856</link>
<description><![CDATA[Gramzster posted : Thanks for your help,<br>I decided to scrap the idea of using the Easy VPN Client on the 800 series router, and I am now attempting to create a LAN-to-LAN tunnel, however I have been having slight issues with getting this working, since I think that the NAT on the router is translating the traffic.  I was wondering if anyone has created a LAN-to-LAN tunnel using two cisco routers, with NAT implemented on both routers? (yes, I do know that there are many config examples on cisco.com, however the majority to not apply to NAT, and the ones that do, I was unable to get much progress with them)]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Need-a-Little-help-with-Easy-VPN-8161856</guid>
<pubDate>Mon, 06 Oct 2003 22:59:05 EDT</pubDate>
</item>

<item>
<title>Re: Need a Little help with Easy VPN</title>
<link>http://www.dslreports.com/forum/Re-Need-a-Little-help-with-Easy-VPN-8109658</link>
<description><![CDATA[MaxXPower posted : On the 800 series config, I would start with confirming the accuracy of the shared key. Make sure it's the same as on the 2600.<br>try some trouble shooting commands on both routers. While doing so, do a continuous ping from a machine inside the client network to one inside the destination network. Here's a few show and debugs.<br><br>ON THE 2600 <br>debug crypto engine   -  This will give you the status and details of your key exchange.<br><br>debug crypto isakmp   -  Will show debug data on the policy matching, and the setup of IPSEC Security Associations. <br><br>debug crypto ipsec    -  Will show you if your the setup of your SA's were successful.<br><br>show crypto isakmp sa - To view isakmp Security Associations<br> <br>show crypto ipsec sa  - To view IPsec Security Associations<br><br>clear crypto sa       - Clear the Sa's then do the previous two show commands again to see fresh data. Clear after making changes to the config to see how it effects the crypto.<br><br>Another thing to consider is just using router to router VPN between the 800 and 2600 series.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Need-a-Little-help-with-Easy-VPN-8109658</guid>
<pubDate>Tue, 30 Sep 2003 22:09:50 EDT</pubDate>
</item>

<item>
<title>Need a Little help with Easy VPN</title>
<link>http://www.dslreports.com/forum/Need-a-Little-help-with-Easy-VPN-8108888</link>
<description><![CDATA[Gramzster posted : Hey Everyone,<br>(first of all, sorry for the long post). For the past couple of weeks, I have been setting up my first VPN.  There has been highs (and of course some lows), but I have had a lot of success. This has been a result of troubleshooting, and using almost every document relating to VPN on the cisco Site.  I am ALMOST there, but I have a slight problem<br><br>Anyways (just so not one says you need a hardware accelerator), I am configuring the Easy VPN server on a Cisco 2621XM with the AIM-VPN/EPII VPN Encryption Acclerator, so it will be able to handle the load :)<br><br>So about the VPN.  I have been creating a VPN, where the 2621XM is the VPN server and approximately 8 people will connecting in with the Cisco VPN Client Software, as well as a Cisco 806 Router, with the 12.3(2)T1 software, so it supports the Easy VPN Client.<br><br>On the 2621 Router, I have added the following commands to allow it operate as the VPN server.  And so far, I have been successful with having the VPN (software) Clients log in with 3DES encryption and without any problems.<br><br>aaa new-model<br>!<br>aaa authentication login default local<br>aaa authentication login userauthen local<br>aaa authorization network groupauthor local<br>aaa session-id common<br>!<br>crypto isakmp policy 3<br> encr 3des<br> authentication pre-share<br> group 2<br>!<br>crypto isakmp client configuration group (REMOVED)<br> key (REMOVED)<br> dns 10.0.0.10<br> wins 10.0.0.10<br> domain (REMOVED)<br> pool ippool<br> acl 108<br>!<br>crypto ipsec transform-set myset esp-3des esp-sha-hmac<br>!<br>crypto dynamic-map dynmap 10<br> set transform-set myset<br>!<br>crypto map clientmap client authentication list userauthen<br>crypto map clientmap isakmp authorization list groupauthor<br>crypto map clientmap client configuration address respond<br>crypto map clientmap 10 ipsec-isakmp dynamic dynmap<br>!<br>interface Ethernet1/0<br> ip address dhcp<br> ip nat outside<br> half-duplex<br> crypto map clientmap<br>!<br>ip local pool ippool 10.254.0.1 10.254.0.254<br>ip nat inside source route-map nonat interface Ethernet1/0 overload<br>ip classless<br>!<br>access-list 100 permit ip any any<br>access-list 102 deny   ip 10.0.0.0 0.0.0.255 10.254.0.0 0.0.0.255<br>access-list 102 permit ip any any<br>access-list 108 permit ip 10.0.0.0 0.0.0.255 10.254.0.0 0.0.0.255<br>!<br>route-map nonat permit 10<br> match ip address 102<br>!<br><br>However, I have been having a problem with the 806 router connecting in (which I will talk about a little bit lower)<br><br>Before I was able to get the Software VPN clients working, I had a slight problem.  The problem was that I had not enabled 3DES encryption for the ISAKMP policy (<I>crypto isakmp policy 3</I> in the running config of the 2621), causing an error to show up on the router:<I> %CRYPTO-6-IKMP_MODE_FAILURE: Processing of Aggressive mode failed with peer at (IP Address of VPN Client) </I>. However, I found out that once I enabled 3DES encryption for the ISAKMP policy, the VPN software clients were able to connect sucessfully.<br><br>Now, I have seem to have had a similar problem with my 806 router. For the Easy VPN client, I have entered in these commands into the router.<br>!<br>crypto ipsec client ezvpn Test<br> connect auto<br> group (REMOVED) key (REMOVED)<br> mode client<br> peer (REMOVED)<br>!<br>interface E0<br> crypto ipsec client ezvpn Test inside<br>!<br>interface E1<br> crypto ipsec client ezvpn Test outside<br>!<br>and the 806 Router tries to connect to the 2621, however it can't.... and the same message as above shows up on the router <I> %CRYPTO-6-IKMP_MODE_FAILURE: Processing of Aggressive mode failed with peer at (IP Address of 806) </I>, which makes me assume that there is a problem with the encrpytion of the ISAKMP packets.  In odrer to try to resolve this, I added the following to the 806:<br>!<br>crypto isakmp policy 3<br> encr 3des<br> authentication pre-share<br> group 2<br>!<br>And it still didn't connect, however I got a different message this time on the 2621. And although I don't have it with me, I am almost sure that it said <I>IKE packet from peer (Address of 806) is not encrypted and it should've been</I><br><br>So can any of you help me? I have a feeling that I am ALMOST there, but I just need a little help with getting the 806 to connect<br><br>Thanks A Lot]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Need-a-Little-help-with-Easy-VPN-8108888</guid>
<pubDate>Tue, 30 Sep 2003 20:51:04 EDT</pubDate>
</item>

</channel>
</rss>
