Need help, VPN between 1841 router & PIX 501

Trying to setup a VPN between an 1841 router at HQ with static IP connecting to remote office with a PIX 501 and a persistent IP (not static, but Mediacom has mapped PIX MAC this IP so I always get same public IP even on equip reboot). I have configured both sides but tunnel will not come up, must be missing something.
See attached configs.
THANK YOU!

Sorry.
interface: outside
Crypto map tag: IPSEC, local addr. 12.206.137.5
local ident (addr/mask/prot/port): (10.5.5.0/255.255.255.0/0/0)
remote ident (addr/mask/prot/port): (10.2.1.0/255.255.255.0/0/0)
current_peer: 216.203.117.82:500
PERMIT, flags={origin_is_acl,}
#pkts encaps: 659, #pkts encrypt: 659, #pkts digest 659
#pkts decaps: 462, #pkts decrypt: 462, #pkts verify 462
#pkts compressed: 0, #pkts decompressed: 0
#pkts not compressed: 0, #pkts compr. failed: 0, #pkts decompress failed: 0
#send errors 124, #recv errors 0
local crypto endpt.: 12.206.137.5, remote crypto endpt.: 216.203.117.82
path mtu 1500, ipsec overhead 56, media mtu 1500
current outbound spi: 793ff99e
inbound esp sas:
spi: 0xcbd5b096(3419779222)
transform: esp-des esp-md5-hmac ,
in use settings ={Tunnel, }
slot: 0, conn id: 4, crypto map: IPSEC
IV size: 8 bytes
replay detection support: Y
inbound ah sas:
inbound pcp sas:
outbound esp sas:
spi: 0x793ff99e(2034235806)
transform: esp-des esp-md5-hmac ,
in use settings ={Tunnel, }
slot: 0, conn id: 3, crypto map: IPSEC
sa timing: remaining key lifetime (k/sec): (4607996/1929)
IV size: 8 bytes
replay detection support: Y
outbound ah sas:
local ident (addr/mask/prot/port): (10.5.5.0/255.255.255.0/0/0)
remote ident (addr/mask/prot/port): (216.203.117.85/255.255.255.255/0/0)
current_peer: 216.203.117.82:500
PERMIT, flags={origin_is_acl,}
#pkts encaps: 2691, #pkts encrypt: 2691, #pkts digest 2691
#pkts decaps: 2601, #pkts decrypt: 2601, #pkts verify 2601
#pkts compressed: 0, #pkts decompressed: 0
#pkts not compressed: 0, #pkts compr. failed: 0, #pkts decompress failed: 0
#send errors 0, #recv errors 0
local crypto endpt.: 12.206.137.5, remote crypto endpt.: 216.203.117.82
path mtu 1500, ipsec overhead 56, media mtu 1500
current outbound spi: c6d3ea5c
inbound esp sas:
spi: 0x55d659c5(1440111045)
transform: esp-des esp-md5-hmac ,
in use settings ={Tunnel, }
slot: 0, conn id: 1, crypto map: IPSEC
sa timing: remaining key lifetime (k/sec): (4607097/1917)
replay detection support: Y
inbound ah sas:
inbound pcp sas:
outbound esp sas:
spi: 0xc6d3ea5c(3335776860)
transform: esp-des esp-md5-hmac ,
in use settings ={Tunnel, }
slot: 0, conn id: 2, crypto map: IPSEC
sa timing: remaining key lifetime (k/sec): (4607743/1890)
IV size: 8 bytes
replay detection support: Y
outbound ah sas:
outbound pcp sas:

Similar Messages

  • Need help regarding Cisco 1841 Router

    hello everyone , i am need of help regarding configuring of   FE 0/1 port. our company have a cisco 1841 router. The serial 0/0/0 is connected with VSAT for internet. The FE 0/0 is connected to switch(LAN) through which net connectivity is provided to all users. Recently a new VSAT has been installed at our site,with different IP series. So every time we want to switch between the two net connectivity we need to change the entire IP configuration of all users, which in turn prohibits the users from accessing the printers,data servers etc which are been set to our existing IP series. So, my idea was to configure the FE 0/1, so that just by changing the DNS will help us providing internet along with all other devices without changing the entire IP series. The new VSAT modem has a lan cable which can be connected to FE 0/1. Can any one help out in solving the problem. Our existing IP series is 192.168.3.1..... and the new VSAT series is 10.205.74.1......

    Bao
    Do I understand correctly that you will have 20 remote users who will telnet to the 2511 and from the 2511 will use reverse telnet to access the console of router1, router2, router3, etc which have their console ports connected to async ports of the 2511? If that understanding is correct then the firewall only needs to open TCP port 23 for telnet. The other ports (2001, 2002, etc) are between the 2511 and router1, router2, etc and will not be seen by the firewall. If my understanding is not correct then please clarify.
    I do not believe that you will find an image for the 2500 that supports SSH.
    HTH
    Rick

  • I need help picking a wired router

    im tired of bringing my computers modem upstairs everytime i wanna go on xbox live because then when my sis or mom needs to use the internet i have to bring it back downstairs so i wanna have a really good wired router i can keep upstairs in my room so i need help picking one

    The reason gaming and wireless don't work is because wireless does not transfer large packets of information which is what gaming uses. The best thing to do if you want wireless is to get a gaming router they will send larger packets of information and they also have dual ban gaming routers which will allow you to set up to where you can connect on one signal and your mom or sister on another it will make it much better for all of you in the long run.
    Brandon
    Best Buy Associate | Geek Squad Agent
    Forum Guidelines | Terms & Conditions | Community Guidelines | Blogging Guidelines
    *Remember to mark your questions solved and click the star under the user's name to show your thanks!

  • Need a help to config 1841 router!

    Hi all,
    Could someone tell me,can I configure two ISP on one Fast Ethernet port. We have a client, bougth a 1841 Modular router without aditional WAN cards. So, the router hes only two interfases. In this moment, we use one interfase for internal LAN and other for ISP. But the client want to has second ISP.

    Mariya
    Whether you can do that depends on some details that you have not given us.
    It is possible to configure more than one IP address on a FastEthernet interface using secondary addresses. So you could configure the address used by one ISP as primary and configure the address used by the other ISP as secondary. For this to work both ISP would need to give the client an Ethernet handoff and you would need a small Ethernet switch to connect the router FastEthernet to both ISPs.
    HTH
    Rick

  • Need help setting up my router

    hi i am new to this forum and i need some help
    i just recently bought a linksys  model: WRT54G ROUTER and a NETWORK USB ADAPTER and it wont connect to the internet using a wired connection and a wireless connection. i have COMCAST internet and i tryed calling them to see if they could help me but they couldnt. i also went to BEST BUY  and asked the geek squad people and they said the lnksys setup disk doesnt work 9/10 times so can any one please help me so i dont have to spend 100+ dollars to get my internet setup through my router.
    also  my modem is directly connected to my comouter by a cat-5 cable(ethernet cable)
    thanks in advance

    Make sure you can access the Internet while directly connected to the modem then...
    Check this out:
    CLICK THIS
    "The war between heaven and hell depends on the choices we make, and those choices require sacrifice. That's the test"

  • Need Help in finding out Router, Switch, firewall n IDS 4 Datacentre

    Hii All,
    Greetings!!!
    Iam workin on project for Datacenter. I need ur help in finding me out the exact Router, Switch, Firewall & IDS series based on my attached complete technical specification.
    pls find attched tech info for router, switch, firewall & IDS. Ur prompt respnse will be appreciated..
    Thanku in advance 4 ur kind cooperation & help.
    Looking forward 4 ur prompt response.
    Brgds
    Arif....

    The write-up more sounds like it's an 7206VXR router, a 6500E with Sup720.
    FW/ASA/PIX is an ASA 5510
    Please don't forget to rate useful posts.  Thanks.

  • Need help on setting up router

    Hi, I have a WRT54G wireless G router. I have a problem connecting to the internet through the router. If I connect an internet cable directly from my modem to my laptop, the internet works fine. If I connect the modem to the router and the router to my laptop, the message on my computer says 'limited or no connectivity'. I have set to detect IP and DNS automatically on my laptop.
    Even when I use the linksys EasyLink, it says it does not support my router. In the router setup page, the setting is set to 'Automatic DHCP'. Why is the problem? Can anyone help me? Thanks!

    You just need to set one up and everyone uses that password to connect to your network.
    Read this article here
    Setting-Up WEP, WPA or WPA2 Wireless Security on a Linksys Wireless Router
    "Sometimes your knight in shining armor is just a retard in tin foil.."-ARCHANGEL_06

  • Need help reconnecting my BEFW11S4 router..please! :)

    I was wondering if anyone could help me with the problem that I'm having right now.
    I've had a Linksys BEFW11S4 Wireless Router for more than a year now and so far, nothing's been wrong with it. Just last night, my DSL wouldn't connect so I called my internet provider (Frontier) and we got it to work but only after I disconnected the router. The guy on the phone said that the router was part of the problem and that I would need to call Linksys and have them guide me through setting it back up. He also said I'd need to change some of the settings. When I called, the Linksys lady said that I would need to pay money for them to help me, but I could use their free internet resources. So I tried reconnecting the router but it didn't work. So I'm stumped. I haven't a clue what to do. Could someone please help? Thank you so much.
    Oh I have Windows XP in case you need to know.

    1)connect the computer to the router's port 1
    2)access the router ui using http://192.168.1.1 . the default login password is "admin"..
    3)on the set up page , select the internet connection type as "PPPoE" ..
    4)Enter the username and password provided by Frontier...the username should be like [email protected]
    5)save the settings
    6)connect the modem to the router's internet port
    7)do a power cycle
    8)on the router web ui , go to the "status" tab and check whether the login status is connected ..
    9)if yes, there should be a valid internet ip address and you should be online
    10)if not, then you need to bridge the modem ..

  • Need help deciding between two different Zen products [micro vs ... micr

    Hey all,
    Just bought a black zen micro last Wednesday and am loving it. Bought it from Best Buy and splurged on the extra protection plan. Unfortunatlly, after a trip to Fry's today, I'm questioning my impulse buy.
    At Fry's they have two different box sets of Zen Micros. One small one, like the one I got at Best Buy, with the player/battery, headphones, usb cable and smooth little pouch. But they also had a larger box with player/battery, headphones, usb cable, smooth little pouch AND an AC charger (and I'm not sure, but possibly a second battery?). I am assuming that this large box with more items (but still the same $99 price) is an older box. What I'm wondering is if there is any difference between the players in the two boxes. If there is not a difference, then I'm going back to Best Buy to get a refund and get one of the boxes at Fry's that has the charger with it (a much needed accessory for my uses). Of course, if the players do differ, I would have to find out in what way and weigh my option to keep what I have or return it and base a decision on that. That, of course, is what prompted this post.
    I know some players just can't help but be deffecti've, does this older box contain a series with a higher rate of returns? Does it look different (I really like the way the back lighting looks on mine)? Anyone have experience with one of the older boxed sets and one of the newer ones (bought one, then another for S.O.)?
    I'm already leaning towards return, but I just wanted to check with other creative users before I made my final decision.
    Thanks,
    -Jonathan

    There is no difference in the operation of the players. The very early Micros had the word "BACK" on the return button, the newer version just has a left pointing arrow. Supposedly, the newest units have a revision to the headphone jack, but there is no way of telling if you have the better or worse jack. The large box will also have the holder with the belt clip and stand. The Limited Edition has the extra battery, and is clearly marked with a sticker on the front of the box that says "Limited Edition FREE Extra Battery for 24 Hour Playtime. Some people say that the backlighting is different with the newer units, I dont know. The large box IS the older retail version. Hope this helps you.

  • Need help deciding between 2 slr cameras

    I would love some help in deciding between 2 cameras, canon digital rebel xt and nikon d50. Since both seem to be rated equally, I want to base my decision on which one is easier to work with in iphoto or at least adobe elements 2 or 3. I have heard that raw files are proprietary and I don't even know if either will work on my mac. (do not have usb2 only usb1).
    Especially since I do not have any experience with any digital camera, I would appreciate any suggestions.
    thank you

    Thank you all for responding. I have been away from my computer and again I am not receiving e-mails letting me know if someone has replied.
    To answer a few questions; I will mainly be doing iDVD and iMovie slideshows and a few good prints (hopefully). I will be mainly taking photos of family and especially a new baby. After some research I was told that slrs take faster pixs, therefore more suitable for a moving baby, especially if shooting in a continuous mode. I also do not want a long delay before I take another pix so I can capture that special baby expression. I also want sharp pictures with realistic colors and enough pixels to crop. Since I do edit, crop ... I thought RAW might be a better choice than jpgs, since I understand that jpgs lose a lot of quality when touched up.
    Since I did not know anyone answered me, I bought the Canon. I am somewhat disappointed. I do not know if it is my fault or the cameras. I went to about 7 stores and asked the salespeople their opinion and all varied. Quite a few told me I would get sharper photos with the Nikon and maybe they were right. My Canon shoots pretty good color (although a little on the orange side, especially skin colors), BUT THEY ARE ALL SOFT, as one saleman warned me about. I am very disappointed since a friend's Nikon coolpix 5200 has sharper images than my canon at a third of the price.
    I now have this dilemna in that I have till Sunday to exchange it for a Nikon, but I am afraid that I might be exchanging one problem for another, or that the softness is caused by me regardless which camera I use. In that case I prefer the canon because it is lighter.
    I also discovered that Minolta makes a camera with anti-shake that is in the same price range. Maybe that would solve my problem, however it is the heaviest of all 3, but I would be willing to buy it if the anti-shake gives a sharper photo. I want these photos to eventually look good on a HD television.

  • Need help choosing between AJA Kona LHe v. BM Multibridge Pro

    Hi gang,
    I'm purchasing a MacPro 3GHz and need to put in one of these cards to bring in component and SDI signals. Big differences seem to be:
    * Multibridge has HDMI output for monitoring, AJA does not although AJA has two SDI outs (which requires SDI->HDMI converter for monitoring at extra $$).
    * AJA has DVCProHD and Dynamic RT effects hardware acceleration but the Multibridge does not.
    Question: is the hardware acceleration on the AJA worth the price difference? Or is this a bunch of hogwash and the Multibridge performs just fine with FCP Studio with DVCProHD and RT effect?
    Any other comparison experiences between these two cards will be most helpful!
    Thanks.
    MacPro 3GHz   Mac OS X (10.4.8)  

    i bought a multibridge extreme a couple months ago, and returned it for a few reasons:
    1)- cheap, unbalanced fan made a **** of a racket...
    2)- the box kept interfering with my monitors (they would start cycling on and off when the box was hooked to the computer.
    I was super disappointed in the service i received from BM (after Kaspar Ko told me to contact him, he never answered any of my emails). I have heard BM support pales in comparison to Aja, but Aja is more expensive.
    the multibridge needs some help, and i am sure will eventually be an awesome tool (right now i am hounding the boys who make scopebox to upgrade to multi input capture to work with the multibridge's 2 sdi inputs for mutlicam capture on a single macpro), but for now they have to spend a little more time on R&D.
    Used the Kona2 at a studio last summer that i was working for and found it pretty flawless...

  • I need Help Setting Up Wireless Router WRT54G on NTL

    Hi, I've managed to setup a few home wireless networks in my time but I'm having problems with this. My gf's ISP is NTL and it is connected via a cable modem (rather than the set top). I registered my laptop using the installation software and the internet connection is working fine. I attempted to setup the router and I could connect to it, however I could not connect to the internet through the router. Previously with other routers I found an option where you could input the user/pass so that the router was automatically connected to the service, but I could not find this option. Does anyone who has setup this wireless router with an NTL setup / or anyone at all have any idea how I go about setting it all up?
    Thanks in advance

    I also found this thread which helps by showing when to clone the MAC address.
    Using run cmd from XP's start menu and typing ipconfig /all will show the MAC address of your machine's NIC card, if you need it.  
    http://linksys.custhelp.com/cgi-bin/linksys.cfg/php/enduser/std_adp.php?p_faqid=1040&p_created=10869...

  • Need Help setting up wireless router

    Hi, ive spent the week on the phone trying to reach all the various technical support people to help me, and getting no where, i wait forever and then get dropped.
    I just got time warner cable in NYC (queens) and the modem and internet surfing works fine if I use a USB cable from the modem to my computer, the problem is the ethernet doesnt work, and I dont have drivers for ethernet, but im more interested in setting up wireless from the modem, to the wireless router to my computer with the wireless card.
    I accidently installed some kind of microsoft tcp/ip thingy when surfing around my computer trying to fix this and now I cant use the wireless router and card.
    I dont want to spend hours on the phone in a tech support message maze, so please help me thru PM.
    Mark
    please PM me
    (Edited for guideline compliance. Thanks!)
    Message Edited by JOHNDOE_06 on 07-15-2007 12:16 PM

    Hi Mark, first off let me know are you able to go online directly with the modem, if computer is connected directly to the ethernet port of modem? if not, i think ethernet port of the modem is not working or may be it's defective or drivers for ethernet adapter is not installed , as you've mentioned you can able to go online with the USB cable, once computer is connnected directly to the USB port of modem...unless and untill ethernet port on the modem is not working you won't be able to configure the wireless router... router doesn't have USB port on it... anyways connect modem to the ethernet port of the  router >> computer (wireless), reset the router back to factory default settings by pressing reset button on the back panel of the router... release the reset button after 30 seconds, power cycle the network by unplugging power cable of the modem and router... wait for couple of minutes and power up the modem first and wait for few seconds once modem is rebooted, after that power up the router, check the light status power, WLAN and internet light on the router should be on... try connecting to "linksys" wireless n/w from wireless pc...check whether it works or not and let me know...

  • Need help choosing a new router (business use)

    Here is what I have: Windows XP Pro Workstation (Wired) Server running Windows 2000 Server (Wired) Server running Linux (Wired) Windows XP Pro Laptop (Wireless) Playstation 3 (Wireless) I plan on creating a VPN connection to my network using Microsoft's VPN (Routing and Remote Access component to be specific); however, I currently have a 3 year-old Linksys Wireless-G Router w/Speedbooster (WRT54GS) that does not allow incoming VPN Connections. I have confirmed all the settings are correct on my end and the router will not cooperate. I would like to get a new router that will allow incoming VPN Connections and provide wireless to my wireless equipment. I DO NOT want to use 3rd party VPN software. Your recommendations are much appreciated.

    It is unclear to me what kind of VPN connection you want to make exactly. Do you want to have a VPN connection from a computer in the internet using Microsoft's VPN client (i.e. PPTP or L2TP) to a server inside your LAN which is running the VPN server? What protocol do you want to use?
    This should work through the WRT you have already. What hardware version do you have? Check the label underneath the router. Check for firmware upgrades for your router on the linksys technical support pages.
    What port forwardings did you configure for the VPN tunnel?
    Some people reported that the pass-through settings in the router were reversed: not setting the pass-through option actually allow traffic.
    I don't think that a new router will necessarily solve your problems.
    If you still want to upgrade, I would not necessarily look for a full replacement of the WRT. The WRTs (older and newer) bundle many functions inside a single box which make it versatile to use but on the other hand also has it downsides when one function influences some other for instance.
    You can easily turn your old WRT into an access point for your LAN. If you want to buy a new router I would rather look into a wired router maybe even considering one with a VPN server built-in. Then you can establish the tunnel to the VPN router instead of a server inside your LAN. But you have to check the VPN routers carefully if they really support the client you want to use for the connection. Some are limited.

  • I need help with my WRT54GS router.

    My WRT54GS linksys router is acting up pretty bad. For example, i am just surfing the web and i have a program Ventrilo going talking to some friends, then all of a sudden i get disconnected from it and my internet just suddenly halts and then reconnects in a mere second or two. it also does this in the middle of me playing my online games. I have done every solution that i thought would remedy this problem, getting an ethernet cable, reinstalling Linksys, restarting my modem and router, changing my internet's security, reinstalling vista on my computer, EVERYTHING. I am not alone in this, my brother, plays the PS3 online, and my other brother plays a computer game on his computer. Anyway, while we are all doing our things on our own computers, we all get disconnected from the internet at the same time and it happens pretty frequently about once every 10-12 mins or so. Is anyone having the same problem, or does anyone have any ideas/solutions to this problem?
    Message Edited by Vaun1992 on 02-23-2009 03:02 PM

    You need to reset and re-configure your router to see if that makes any difference...Press and hold the reset button for 30 seconds...Release the reset button...Unplug the power cable from your router, wait for 30 seconds and re-connect the power cable...Now re-configure your router...
    If you still face the same problem you should try to upgrade your router's firmware...
    Download the Firmware from here ,
    Follow these steps to upgrade the firmware on the device: -
    Open an Internet Explorer browser page.In the address bar type - 192.168.1.1
    Leave the username blank & in password use admin in lower case...
    Click on the 'Administration' tab- Then click on the 'Firmware Upgrade' sub tab- Here click on 'Browse' and browse the .bin firmware file and click on "Upgrade"...
    Wait for few seconds until it shows that "Upgrade is successful"  After the firmware upgrade, click on "Reboot" and you will be returned back to the same page OR it will say "Page cannot be displayed".
    Press and hold the reset button for 30 seconds...Release the reset button...Unplug the power cable from your router, wait for 30 seconds and re-connect the power cable...Now re-configure your router...
    If you still face the same problem you should connect one computer straight to the modem and check if you have stable internet connection or the same problem re-occurs...

Maybe you are looking for