Hello all,
I was successful configured S-S VPN between 2400 and 3400 AOS 5 using this configuration, but for AOS 6 between 620 and 3400 controllers, the tunnel could not establish. I knew 4500 UPD is working, because RAPs are working and using the same tunnel. Here are my configurations:
At master:
(BTCWC03) #show datapath session table 66.37.244.77
Datapath Session Table Entries
------------------------------
Flags: F - fast age, S - src NAT, N - dest NAT
D - deny, R - redirect, Y - no syn
H - high prio, P - set prio, T - set ToS
C - client, M - mirror, V - VOIP
Q - Real-Time Quality analysis
I - Deep inspect, U - Locally destined
E - Media Deep Inspect, G - media signal
Source IP Destination IP Prot SPort DPort Cntr Prio ToS Age Destination TAge Flags
-------------- -------------- ---- ----- ----- ---- ---- --- --- ----------- ---- -----
66.37.244.77 172.18.254.96 17 4500 4500 0/0 0 0 4 local 41 FY
172.18.254.96 66.37.244.77 17 4500 4500 0/0 0 0 0 local 41 FC
#show crypto-local ipsec-map MASTER2SITE
Crypto Map Template"MASTER2SITE" 100
IKE Version: 1
lifetime: [300 - 86400] seconds, no volume limit
PFS (Y/N): N
Transform sets={ *DEFAULT-TRANSFORM* }
Peer gateway: 66.37.244.77
Interface: VLAN 1
Source network: 172.18.0.0/255.255.0.0
Destination network: 172.16.18.0/255.255.255.0
Pre-Connect (Y/N): Y
Tunnel Trusted (Y/N): Y
Forced NAT-T (Y/N): N (tried with both Y and N)
At site:
#show crypto-local ipsec-map
Crypto Map Template"SITE2MASTER" 100
IKE Version: 1
lifetime: [300 - 86400] seconds, no volume limit
PFS (Y/N): N
Transform sets={ *DEFAULT-TRANSFORM* }
Peer gateway: 192.188.142.132 (this address NAT to master IP address)
Interface: VLAN 10
Source network: 172.16.18.0/255.255.255.0
Destination network: 172.18.0.0/255.255.0.0
Pre-Connect (Y/N): Y
Tunnel Trusted (Y/N): Y
Forced NAT-T (Y/N): N (tried with both Y and N)
Thank you for your help!
Trinh Nguyen
#3400