l2l vpn

400 pts.
Tags:
Cisco PIX
Cisco PIX 525
Cisco VPN
Cisco VPN Error Messages
L2L VPN
VPN
we have vpn l2l tunnel name xyz 192.168.2.5, 192.168.2.6 are maped to the tunnel the vpn tunnel working fine but we added another ip 192.168.2.6 to vpn tunnel and move this server to dmz It is showing that the traffic cumming from outside is decrypting but it is not encrypting and going back. access-list DMZ-XCHG-nat0 extended permit ip host 192.168.2.6 172.20.1.5 255.255.252.0 access-list WEBDMZ_access_in1 extended permit ip host 192.168.2.6 172.20.1.5 255.255.252.0

same access list for other 2 ip is implemented in inside network and it is working fine. What should be the problem ?

message showing in my pix firewall like this

#pkts encaps: 0, #pkts encrypt: 0, #pkts digest: 0

#pkts decaps: 9, #pkts decrypt: 9, #pkts verify: 9



Software/Hardware used:
cisco pix firewall 525

Answer Wiki

Thanks. We'll let you know when a new response is added.

The answer should be

PIX# access-list DMZ_outbound_nat0_acl extended permit ip host 192.168.2.6 172.20.1.5 255.255.252.0
access-list VPN extended permit ip host 192.168.4.101 10.91.84.0 255.255.252.0

Discuss This Question: 2  Replies

 
There was an error processing your information. Please try again later.
Thanks. We'll let you know when a new response is added.
Send me notifications when members answer or reply to this question.

REGISTER or login:

Forgot Password?
By submitting you agree to receive email from TechTarget and its partners. If you reside outside of the United States, you consent to having your personal data transferred to and processed in the United States. Privacy
  • Ekansh
    The steps you listed make completely sense and are easy to follow.
    0 pointsBadges:
    report
  • Ekansh
    Your momma did not raise any dummies! Great post!
    0 pointsBadges:
    report

Forgot Password

No problem! Submit your e-mail address below. We'll send you an e-mail containing your password.

Your password has been sent to:

To follow this tag...

There was an error processing your information. Please try again later.

REGISTER or login:

Forgot Password?
By submitting you agree to receive email from TechTarget and its partners. If you reside outside of the United States, you consent to having your personal data transferred to and processed in the United States. Privacy

Thanks! We'll email you when relevant content is added and updated.

Following