Site-to-site VPN down. Need help

Site-to-site VPN down. Need help

NewsGroups | Search | Tools
 comp.dcom.vpn  Post an article  get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content  add this group's latest topics to your Google content  YahooMyWeb Yahoo!  Google Google  Windows Live Favorites Windows Live  del.icio.us del.icio.us  digg digg  Add to Netscape Netscape
Subject Author Date
Site-to-site VPN down. Need help Jon Doe 08-14-2007
Posted by Jon Doe on August 14, 2007, 11:12 am
If you were  Registered and logged in, you could reply and use other advanced thread options
I have an L2L Ipsec VPN set up with one of our vendors via my PIX525 7.2(2).
Within the VPN, two of my VLANs are allowed (e.g 172.24.0.0 and 172.26.0.0).
Yesterday, we noticed that the 172.24.0.0 network could no longer connect,
but the 172.26.0.0 network still had access (and I can ping his addresses
from the 172.26 network).

I called the admin at the other end, and they swore they made no changes,
and I didn't either. We looked through all the VPN settings and they still
matched. He uses sonicwall, so he tried to re-negotiate the connection for
the 172.24.0.0 connection. When he tries to do that, he gets no response
from my PIX address. Whenever I try to ping any of his addresses, I get a
message in my syslog saying this:

%PIX-3-713902: IP = 123.456.789.10, Removing peer from peer table failed, no
match!

I decided as a troubleshooting step to reset the VPN connection on my end as
well. Now, I can even connect from the 172.26.0.0 network either. Any ideas?



NMFall 20%
Posted by Rick Merrill on August 14, 2007, 7:02 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Jon Doe wrote:
> I have an L2L Ipsec VPN set up with one of our vendors via my PIX525 7.2(2).
> Within the VPN, two of my VLANs are allowed (e.g 172.24.0.0 and 172.26.0.0).
> Yesterday, we noticed that the 172.24.0.0 network could no longer connect,
> but the 172.26.0.0 network still had access (and I can ping his addresses
> from the 172.26 network).
>
> I called the admin at the other end, and they swore they made no changes,
> and I didn't either. We looked through all the VPN settings and they still
> matched. He uses sonicwall, so he tried to re-negotiate the connection for
> the 172.24.0.0 connection. When he tries to do that, he gets no response
> from my PIX address. Whenever I try to ping any of his addresses, I get a
> message in my syslog saying this:
>
> %PIX-3-713902: IP = 123.456.789.10, Removing peer from peer table failed, no
> match!
>
> I decided as a troubleshooting step to reset the VPN connection on my end as
> well. Now, I can even connect from the 172.26.0.0 network either. Any ideas?
>
>

i got something similar to work again with 'release' & 'renew'


other useful resources:
The Federal Communications Commission (FCC)
Telecommunications Industry Association
Electronic and Software Security Products and Services
International Telecommunication Union

Custom CGI Perl and PHP programming by 1-Script.com

Contact Us | Privacy Policy
The site map in XML format XML site map