Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations biv343 on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Symantec 200R Vpn Connected but Not Connected?!?

Status
Not open for further replies.

NetsNfire

IS-IT--Management
Mar 25, 2004
1
GB
I have two Symantec Boxes one 200R and One 100, the 200R is connected to the internet directly, the other through a Cisco router, (Admin by 3rd Party). The problem arises when i try to create a VPN between the two sites. I get a SA succesful message and the vpn reports "Connected",when i try and ping somthing the other side of the Vpn, or even the Vpn Gateway (Symantec Box) i get a Timeout.
the log is below.

03/25/2004 11:01:36.24 new_vpn - Initiating IKE Aggressive Mode
03/25/2004 11:01:36.54 new_vpn - STATE_AGGR_I1: initiate
03/25/2004 11:01:37.84 new_vpn - STATE_AGGR_I2 sent AI2, ISAKMP SA established
03/25/2004 11:01:37.84 new_vpn - Doing Quick Mode with 193.195.33.106 "new_vpn"
03/25/2004 11:01:37.84 new_vpn - initiating Quick Mode
03/25/2004 11:01:38.19 new_vpn - STATE_QUICK_I1: initiate
03/25/2004 11:01:39.49 new_vpn - STATE_QUICK_I2 sent QI2, IPsec SA established

I have one other VPN running from the 200R box with no problems, If anyone has any ideas, i would appreciate the advice very much.

Thanks

Owain
 
Assuming you've verified that all of the settings between the two devices match, my guess is that the Cisco is blocking ports needed for VPN traffic, so that even though the connection is made the packets are being denied.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top