[c-nsp] Site to Site VPN
Mohammad Khalil
eng_mssk at hotmail.com
Mon Aug 9 10:26:00 EDT 2010
hi all
thanks for your support
the problem seemed that the VPN was retested from a side and the SA association from the other end
> Date: Mon, 9 Aug 2010 15:16:04 +0200
> From: jmayer at loplof.de
> To: cisco-nsp at puck.nether.net
> Subject: Re: [c-nsp] Site to Site VPN
>
> On Mon, Aug 09, 2010 at 01:40:14PM +0300, Mohammad Khalil wrote:
> > thanks for the response
> > now man i have another issue is that the show crypto isakmp sa is showing that the tunnel is up QM_IDLE
> > but i cannot ping the other side and it was working normally
> > and i see in the log message that there is "it is temporarly disabled due to recursive routing"
>
> I've never seen this message in combination with IPSEC so far, but with
> GRE that meant the system was now trying to reach the tunnel endpoint
> by sending the traffic *into* the tunnel. Could be the same for this
> scenario?
>
> Ciao
> Joerg
> --
> Joerg Mayer <jmayer at loplof.de>
> We are stuck with technology when what we really want is just stuff that
> works. Some say that should read Microsoft instead of technology.
> _______________________________________________
> cisco-nsp mailing list cisco-nsp at puck.nether.net
> https://puck.nether.net/mailman/listinfo/cisco-nsp
> archive at http://puck.nether.net/pipermail/cisco-nsp/
More information about the cisco-nsp
mailing list