Hi everyone,
I’m facing a site-to-site issue that I couldn’t resolved yet.
IPSec show etablished, but I cannot ping / access device through the VPN.
*** External ip and secret has been changed for security ***
Fasttrack’s disable on both router.
Help would be great appreciated,
Thanks
Configs are below:
1st router
ipsec policy
1 A src-address=192.168.1.0/24 src-port=any dst-address=192.168.2.0/24 dst-port=any protocol=all action=encrypt level=require ipsec-protocols=esp tunnel=yes sa-src-address=111.111.111.111 sa-dst-address=222.222.222.222 proposal=default ph2-count=1
proposal
0 * name=“default” auth-algorithms=sha1 enc-algorithms=3des lifetime=30m pfs-group=modp1024
peer
0 address=222.222.222.222/32 auth-method=pre-shared-key secret=“********” generate-policy=no policy-template-group=default exchange-mode=main send-initial-contact=yes nat-traversal=yes proposal-check=obey hash-algorithm=sha1
enc-algorithm=aes-128,3des dh-group=modp1024 lifetime=1d dpd-interval=2m dpd-maximum-failures=5
2nd router
ipsec policy
1 A src-address=192.168.2.0/24 src-port=any dst-address=192.168.1.0/24 dst-port=any protocol=all action=encrypt level=require ipsec-protocols=esp tunnel=yes sa-src-address=222.222.222.222 sa-dst-address=111.111.111.111 proposal=default ph2-count=1
proposal
0 * name=“default” auth-algorithms=sha1 enc-algorithms=3des lifetime=30m pfs-group=modp1024
peer
0 address=111.111.111.111/32 auth-method=pre-shared-key secret=“********” generate-policy=no policy-template-group=default exchange-mode=main send-initial-contact=yes nat-traversal=yes proposal-check=obey hash-algorithm=sha1
enc-algorithm=aes-128,3des dh-group=modp1024 lifetime=1d dpd-interval=2m dpd-maximum-failures=5