Cisco 5510 Getting Started Guide - Page 164

Configuring the Other Side of the VPN Connection

Page 164 highlights

Configuring the Other Side of the VPN Connection Chapter 12 Scenario: Site-to-Site VPN Configuration Configuring the Other Side of the VPN Connection You have just configured the local adaptive security appliance. Next, you need to configure the adaptive security appliance at the remote site. At the remote site, configure the second adaptive security appliance to serve as a VPN peer. Use the procedure you used to configure the local adaptive security appliance, starting with "Configuring the Security Appliance at the Local Site" section on page 12-3 and finishing with "Viewing VPN Attributes and Completing the Wizard" section on page 12-10. Note When configuring Security Appliance 2, use the same values for each of the options that you selected for Security Appliance 1, with the exception of local hosts and networks. Mismatches are a common cause of VPN configuration failures. For information about verifying or troubleshooting the configuration for the Site-to-Site VPN, see the section "Troubleshooting the Security Appliance" in the Cisco ASA 5500 Series Configuration Guide using the CLI. For specific troubleshooting issues, see the Troubleshooting Technotes at the following location: http://www.cisco.com/en/US/products/ps6120/prod_tech_notes_list.html For help troubleshooting configuration issues, see the Configuration Examples and TechNotes at the following location: http://www.cisco.com/en/US/products/ps6120/prod_configuration_examples_lis t.html In particular, see the technotes for Site to Site VPN (L2L) with ASA in the Troubleshooting Technotes. The troubleshooting technotes walk you through using commands like the following to troubleshoot the Site-to-site VPN configuration: • show run isakmp • show run ipsec • show run tunnel-group • show run crypto map 12-12 Cisco ASA 5500 Series Getting Started Guide 78-19186-01

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208

Chapter 12
Scenario: Site-to-Site VPN Configuration
Configuring the Other Side of the VPN Connection
12-12
Cisco ASA 5500 Series Getting Started Guide
78-19186-01
Configuring the Other Side of the VPN Connection
You have just configured the local adaptive security appliance. Next, you need to
configure the adaptive security appliance at the remote site.
At the remote site, configure the second adaptive security appliance to serve as a
VPN peer. Use the procedure you used to configure the local adaptive security
appliance, starting with
“Configuring the Security Appliance at the Local Site”
section on page 12-3
and finishing with
“Viewing VPN Attributes and
Completing the Wizard” section on page 12-10
.
Note
When configuring Security Appliance 2, use the same values for each of the
options that you selected for Security Appliance 1, with the exception of local
hosts and networks. Mismatches are a common cause of VPN configuration
failures.
For information about verifying or troubleshooting the configuration for the
Site-to-Site VPN, see the section “Troubleshooting the Security Appliance” in the
Cisco ASA 5500 Series Configuration Guide using the CLI
.
For specific troubleshooting issues, see the Troubleshooting Technotes at the
following location:
For help troubleshooting configuration issues, see the Configuration Examples
and TechNotes at the following location:
t.html
In particular, see the technotes for Site to Site VPN (L2L) with ASA in the
Troubleshooting Technotes. The troubleshooting technotes walk you through
using commands like the following to troubleshoot the Site-to-site VPN
configuration:
show run isakmp
show run ipsec
show run tunnel-group
show run crypto map