I have built a IPSEC tunnel between PA and CP. When i initiate traffic from PC sitting behind CP, phase 1 comes up on both FW. But phase 2 fails, i tried every possible modification in phase 2 settings(same on both end), changed intresting traffic (subnet) coming to CP as well. But i couldn't succeed.
CA has10.168.1.0/24
PA has 200.1.1.0/24
Below logs i captured.
PHASE1:
PHASE1
PHASE2:
PHASE2 FAILED LOG
PA PHASE 1 shows UP
TCPDUMPtcpdump
I reset the tunnel and initiated traffic from PA and i am able to ping. If there was config mismatch i shouldn't be able to reach from PA as well.
Router#ping 10.168.1.1 rep 100
Type escape sequence to abort.
Sending 100, 100-byte ICMP Echos to 10.168.1.1, timeout is 2 seconds:
!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
Success rate is 100 percent (100/100), round-trip min/avg/max = 24/31/44 ms
Thanks