cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1230
Views
0
Helpful
2
Replies

packet tracer type vpn subtype encrypt result DROP

clark white
Level 2
Level 2

Dears

i have a L2L vpn from branch to HQ and everthing works fine i am adding a new subnet in the vpn access-list exactly as per the cisco recommendation mirror access-list on both ends, But still the connection to the ISE server on port 1645 fails my branch switches are not able to reach the ISE server in HQ.

The strange part is the packet-tracer some time shows me results all ok and within a seconds if i run again it shows me vpn encrypt packet drop.

 

Please find the attached packet tracer output.

 

 

 

 

2 Replies 2

Hello,

 Should be nice if you put firewall config here. Only one question, does Firewall has route to the new subneteork?

i can paste the config but i  have routes pretty sure for that

Review Cisco Networking products for a $25 gift card