Il problema,mi pare ovvio,è che l'interfaccia interna del router non riesce ad instradare corretamente i pacchetti verso la VPN.
Questo mi causa un sacco di problemi e devo assolutamente risolverlo...
Dal poco che so le VPN lan 2 lan vengono instradate tramite ACL le mie sono del tipo :
SEDE CENTRO STELLA
Codice: Seleziona tutto
crypto map VPN 3 ipsec-isakmp
description Tunnel to SEDE03
set peer xx.xx.xx.xx
set transform-set VPN
match address 153
!
access-list 100 remark *******************
access-list 100 remark *** ACL RM-NAT0 ***
access-list 100 remark *******************
access-list 100 remark --vpn sedi remote--
access-list 100 deny ip 192.168.0.0 0.0.0.255 192.168.1.0 0.0.0.255
access-list 100 deny ip 192.168.0.0 0.0.0.255 192.168.2.0 0.0.0.255
access-list 100 deny ip 192.168.0.0 0.0.0.255 192.168.3.0 0.0.0.255
access-list 100 remark --to translate--
access-list 100 permit ip 192.168.0.0 0.0.0.255 any
!
access-list 153 remark --VPN-TO-SEDE03--
access-list 153 permit ip 192.168.0.0 0.0.0.255 192.168.3.0 0.0.0.255
!
Codice: Seleziona tutto
crypto map VPN 1 ipsec-isakmp
description Tunnel to CENTRO-STELLA
set peer xx.xx.xx.xx
set transform-set VPN
match address 151
!
access-list 100 remark *******************
access-list 100 remark *** ACL RM-NAT0 ***
access-list 100 remark *******************
access-list 100 remark --vpn centro stella--
access-list 100 deny ip 192.168.3.0 0.0.0.255 192.168.0.0 0.0.0.255
access-list 100 remark --to translate--
access-list 100 permit ip 192.168.3.0 0.0.0.255 any
!
access-list 151 remark ************************
access-list 151 remark *** ACL TRAFFICO VPN ***
access-list 151 remark ************************
access-list 151 remark --VPN-TO-CENTRO-STELLA--
access-list 151 permit ip 192.168.3.0 0.0.0.255 192.168.0.0 0.0.0.255
!
Codice: Seleziona tutto
sede03#ping 192.168.0.1
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 192.168.0.1, timeout is 2 seconds:
U.U.U
Success rate is 0 percent (0/5)
sede03#ssh 192.168.0.1
% Destination unreachable; gateway or host down
sede03#traceroute 192.168.0.1
Type escape sequence to abort.
Tracing the route to 192.168.0.1
1 [i]ip punto punto telecom[/i] !A * !A
sede03#