I must be overseeing something really obvious, but I can't get VPN's working on machines connected to the wireless part of a Cisco 887 :-( Does anyone have a "You idiot, you did ${stupid}" or a troubleshooting hint for me?
When I use a wired connection everything works fine. When I go wireless, GRE packets are coming out of my laptop, sent out to the Internet, reply packets arrive and I can see them as incoming traffic on the Gi0 of the wlan-ap. They just don't go out dotradio0.1. See the counting of the access-lists I put on gi0.1(accl 100) and dot0.1 (accl101):
ap#show ip access-lists 100 Extended IP access list 100 10 permit gre 192.168.173.0 0.0.0.255 any (40 matches) 20 permit gre any 192.168.173.0 0.0.0.255 (40 matches) 30 permit ip any any (45347 matches) ap#show ip access-lists 101 Extended IP access list 101 10 permit gre 192.168.173.0 0.0.0.255 any (10 matches) 20 permit gre any 192.168.173.0 0.0.0.255 30 permit ip any any (26955 matches)
A few relevant configs I hope: access-list 100 and 101 are just for troubleshooting.
dot11 ssid Spaider vlan 1 authentication open authentication key-management wpa guest-mode mbssid guest-mode
bridge irb
interface Dot11Radio0.1 encapsulation dot1Q 1 native ip access-group 101 in ip access-group 101 out no ip route-cache bridge-group 1 bridge-group 1 subscriber-loop-control bridge-group 1 block-unknown-source no bridge-group 1 source-learning no bridge-group 1 unicast-flooding bridge-group 1 spanning-disabled
interface GigabitEthernet0.1 encapsulation dot1Q 1 native ip access-group 100 in ip access-group 100 out no ip route-cache bridge-group 1 no bridge-group 1 source-learning bridge-group 1 spanning-disabled
interface BVI1 ip address 192.168.173.2 255.255.255.0 no ip route-cache
access-list 100 permit gre 192.168.173.0 0.0.0.255 any access-list 100 permit gre any 192.168.173.0 0.0.0.255 access-list 100 permit ip any any access-list 101 permit gre 192.168.173.0 0.0.0.255 any access-list 101 permit gre any 192.168.173.0 0.0.0.255 access-list 101 permit ip any any bridge 1 protocol ieee bridge 1 route ip
Greetings
Mark