Question about Computers & Internet
Send me the configs from both routers and I will look at it for you and advise. Sounds like an ACL issue.
Posted on May 12, 2009
Depending on the version of code, sometimes you have to implicitly deny the decrytped traffic. I.e the traffic is matched pre and post decryption (again, depending on code version I thiink). Also, those devices still nat the traffic if it matches the rules. So if you are patting (natting to one address with the overload command), you will need to doe it with an extended acl that "denies" the traffic first so it will not be translated. This will have to happen on both ends prior to you being able to see the result. On static nat entries, that can even be worse and there are some hairy techniques to get around this.
So make sure you are actually sending traffic by looking at the output from a "show crypto ipsec sa". If so, look at nat. My .02.
Posted on Jan 11, 2009
First, check if you are able to ping the default gateway IP, then check if you have configured your NAT for inward request.
Posted on Jan 11, 2009
Hi,
A 6ya expert can help you resolve that issue over the phone in a minute or two.
Best thing about this new service is that you are never placed on hold and get to talk to real repairmen in the US.
The service is completely free and covers almost anything you can think of (from cars to computers, handyman, and even drones).
click here to download the app (for users in the US for now) and get all the help you need.
Good luck!
Posted on Jan 02, 2017
Jan 11, 2011 | Arris SURFboard SBG900 Wireless Router...
on May 05, 2011 | Computers & Internet
Apr 09, 2010 | Cisco 3845 Integrated Services Router...
Jan 18, 2010 | Cisco ASA 5505 Firewall
Nov 16, 2009 | D-Link AirPlusG DI-524UP Wireless Router
Oct 26, 2009 | Computers & Internet
Jun 13, 2009 | Cisco 1841 Advanced Security Feature Pack...
Apr 06, 2009 | Cisco 805 Router
87 people viewed this question
Usually answered in minutes!
I can ping my own gateway and the TIP ip address on the other side. The problem is with configuring the access lists i believe.
I have the config's from both routers and i need a cisco expert to review it with me.
×