Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations biv343 on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Problem from cisco 1811 to Juniper

Status
Not open for further replies.

lagcat

Technical User
May 18, 2007
52
GB
Hello i am having a problem with me VPN connect i can see the problem but no way to change this which is the most annoying this:

(remote and local address has been changed to save people fiddling, the 146.81.200.61 is the correct)

crypto isakmp policy 11
encr 3des
authentication pre-share
group 2
lifetime 28800
crypto isakmp key ********* address 81.171.200.154
!
!
crypto ipsec transform-set TSLVPN esp-3des esp-sha-hmac
!
crypto map VPNMAP 11 ipsec-isakmp
set peer 81.171.200.154
set transform-set TSLVPN
set pfs group2
match address 101

this is all correctly on the interface and had this double checked which looks correct to everyone else

but obviously not connecting

when i do 'show crypto session'

Interface: FastEthernet0
Session status: DOWN
Peer: 81.200.200.154 port 500
IPSEC FLOW: permit ip 10.0.0.0/255.0.0.0 172.16.0.0/255.255.0.0
Active SAs: 0, origin: crypto map

Interface: FastEthernet0
Session status: DOWN-NEGOTIATING
Peer: 146.81.200.61 port 500
IKE SA: local 217.200.200.234/500 remote 146.81.200.61/500 Inactive
IKE SA: local 217.200.200.234/500 remote 146.81.200.61/500 Inactive
IKE SA: local 217.200.200.234/500 remote 146.81.200.61/500 Inactive
IKE SA: local 217.200.200.234/500 remote 146.81.200.61/500 Inactive

on the IKE SA where is it getting that remote address from as its completely wrong the remote address should be the same as my set peer address 81.200.200.154

i have tried re-creating the all details on the router and still no joy....the 146 cannot be pinged so no idea where it is

also when doing a trace route from both site the 146 address is not mentioned in either on the results

really scratching my head on this one....even more as its my first solo VPN setup that i want to do with people checking and now i have hi this problem

if you can help could you please explain in detail possibly with some command examples...thankyou

any help would be great cheers



 
What kind of juniper device is at the remote end? I work with juniper routers/switches and can offer some support.


First glimpse, it sounds like their source IP address for the SA's is configured improperly. Or perhaps you're peering to the wrong IP.
 
worked it out

the 146 address was spamming my address for some unknown reason....

have to create and ACL to deny inbound traffic from that address then it all kicked in

CCENT, CCNA
MCP, MCSA
Comptia: Network Essentials, Security +, A+
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top