Re: site-to-site vpn 4.0 to cisco 3000 SOLVED

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
To: <misc@...>
Cc: <lahrcm@...>
Date: Monday, February 26, 2007 - 5:02 am

On Sun, Feb 25 2007 at 06:20, c l wrote:

There is another potential problem with this configuration. You did not
specify the ike mode: active, passive, dynamic.

The default behavior is to use "active". "dynamic" mode comes with DPD
(Dead Peer Detection) and don't work with some devices. I remember a
post here stating that it doesn't interoperate with Netscreen at the
other end.

You're lucky to not enter into this problem :)

Routing in the enc0 interface is done with the flow statement in the
ipsec.conf file. Your ipsec.conf should include a line like this one :

flow esp from 192.168.1.0/24 to 10.10.0.0/16 peer peer 2.2.2.2

Good luck!

Claer

> cisco

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
site-to-site vpn 4.0 to cisco 3000, c l, (Sun Feb 25, 1:23 pm)
Re: site-to-site vpn 4.0 to cisco 3000, William Bloom, (Sun Feb 25, 5:02 pm)
Re: site-to-site vpn 4.0 to cisco 3000, c l, (Sun Feb 25, 5:48 pm)
Re: site-to-site vpn 4.0 to cisco 3000, William Bloom, (Sun Feb 25, 10:16 pm)
Re: site-to-site vpn 4.0 to cisco 3000, William Bloom, (Sun Feb 25, 9:53 pm)
Re: site-to-site vpn 4.0 to cisco 3000 SOLVED, Claer, (Mon Feb 26, 5:02 am)
Re: site-to-site vpn 4.0 to cisco 3000 SOLVED, William Bloom, (Sun Feb 25, 10:19 pm)