Re: VPN site-to-site not working with PIX 501s



Hello John,

When a tunnel drops suddenly both the device will have mismatched
states of the crypto SA and SPD.
The best way is to clear the garbage SA in both the PIX and ping.

The command to clear isa sa would be
clear crypto isakmp sa (cle cry isa sa)
and for ipsec
clear crypto ipsec sa (cle cry ipse sa)

Hope this will help
Vikas

John wrote:
I have two PIX 501s and they were connected via a vpn. All of a sudden
the circuit dropped and after rebooting both devices, I ahve not been
able to reestablish the VPN. I changed the PRE-SHARE key on both and
changed the transform sets, but no change. Once someone gave me a
command to reset the crypto key. I am not sure if this is what I need
to do. Does anyone know the process to do that or can you offer some
troubleshooting advice?

Thanks,

John

.



Relevant Pages

  • debugging failed vpn
    ... debug crypto isakmp ... Result of firewall command: "sh crypto ipsec sa" ... current outbound spi: 0 ... inbound esp sas: ...
    (comp.dcom.sys.cisco)
  • Re: IPSEC problem
    ... i made clear crypto isakmp sa clear crypto ipsec sa ... > i have my head blowing up sorry i'm 12 hours behind a screen and i have my ...
    (comp.dcom.sys.cisco)
  • Re: IPSEC problem
    ... >> clear crypto isakmp sa ... >> clear crypto ipsec sa ... i have my head blowing up sorry i'm 12 hours behind a screen and i have my ...
    (comp.dcom.sys.cisco)