- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
04-23-2019 03:49 PM
I have IPSEc ikev1 tunnel with vendor.
Phase 1 and 2 are up and green.
From PA from my Lan interface when I ping remote lan subnet ping does not work.
I see no return traffic from vendor to PA.
IS this normal behaviour to have Phase 1 and 2 up but routing does nor work both way?
04-24-2019 03:15 AM - edited 04-24-2019 03:16 AM
phases 1 and 2 are simply the connection, routing is still needed on both ends before packets can pass through
have both sides set a static route to the remote network into the tunnel
does the remote end rely on ProxyIDs to properly route packets into the tunnel
have security policies been configured to allow both ends to communicate through the tunnel
04-24-2019 03:15 AM - edited 04-24-2019 03:16 AM
phases 1 and 2 are simply the connection, routing is still needed on both ends before packets can pass through
have both sides set a static route to the remote network into the tunnel
does the remote end rely on ProxyIDs to properly route packets into the tunnel
have security policies been configured to allow both ends to communicate through the tunnel
04-24-2019 12:05 PM
Vendor Device interface - ping was disabled
all good now.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!