За совет по оптимизации всего этого дела и приведению в божеский вид - огромное спасибо!
Все же очень интерсно, почему при идентичных конфигах цисок, одна пингуется с длинком, а другая нет.статистика с проблемной циски:
sh ip int brie:
Interface IP-Address OK? Method Status Protocol
ATM0 unassigned YES NVRAM up up
Dialer0 111.*.*.* YES IPCP up up
NVI0 unassigned YES unset administratively down down
Tunnel0 192.168.254.1 YES NVRAM up up
Virtual-Access1 unassigned YES unset up up
Vlan1 192.168.1.1 YES NVRAM up up
sh cryp sess det:
Interface: Virtual-Access1
Session status: DOWN
Peer: 222.*.*.* port 500 fvrf: (none) ivrf: (none)
Desc: (none)
Phase1_id: (none)
IPSEC FLOW: permit 47 host 111.*.*.* host 222.*.*.*
Active SAs: 0, origin: crypto map
Inbound: #pkts dec'ed 0 drop 0 life (KB/Sec) 0/0
Outbound: #pkts enc'ed 0 drop 0 life (KB/Sec) 0/0
IPSEC FLOW: permit ip 192.168.1.0/255.255.255.0 192.168.2.0/255.255.255.0
Active SAs: 0, origin: crypto map
Inbound: #pkts dec'ed 0 drop 0 life (KB/Sec) 0/0
Outbound: #pkts enc'ed 0 drop 0 life (KB/Sec) 0/0
Interface: Virtual-Access1
Session status: DOWN
Peer: 333.*.*.* port 500 fvrf: (none) ivrf: (none)
Desc: (none)
Phase1_id: (none)
IPSEC FLOW: permit ip 192.168.1.0/255.255.255.0 192.168.3.0/255.255.255.0
Active SAs: 0, origin: crypto map
Inbound: #pkts dec'ed 0 drop 0 life (KB/Sec) 0/0
Outbound: #pkts enc'ed 0 drop 0 life (KB/Sec) 0/0
Interface: Dialer0
Session status: UP-IDLE
Peer: 222.*.*.* port 500 fvrf: (none) ivrf: (none)
Phase1_id: 222.*.*.*
Desc: (none)
IKE SA: local 111.*.*.*/500 remote 222.*.*.*/500 Active
Capabilities:(none) connid:2008 lifetime:09:38:15
IPSEC FLOW: permit 47 host 111.*.*.* host 222.*.*.*
Active SAs: 0, origin: crypto map
Inbound: #pkts dec'ed 27669 drop 0 life (KB/Sec) 0/0
Outbound: #pkts enc'ed 26505 drop 0 life (KB/Sec) 0/0
IPSEC FLOW: permit ip 192.168.1.0/255.255.255.0 192.168.2.0/255.255.255.0
Active SAs: 0, origin: crypto map
Inbound: #pkts dec'ed 0 drop 0 life (KB/Sec) 0/0
Outbound: #pkts enc'ed 0 drop 0 life (KB/Sec) 0/0
Interface: Dialer0
Uptime: 01:52:26
Session status: UP-ACTIVE
Peer: 333.*.*.* port 500 fvrf: (none) ivrf: (none)
Phase1_id: 333.*.*.*
Desc: (none)
IKE SA: local 111.*.*.*/500 remote 333.*.*.*/500 Active
Capabilities:(none) connid:2009 lifetime:03:02:02
IPSEC FLOW: permit ip 192.168.1.0/255.255.255.0 192.168.3.0/255.255.255.0
Active SAs: 2, origin: crypto map
Inbound: #pkts dec'ed 0 drop 0 life (KB/Sec) 4504577/22053
Outbound: #pkts enc'ed 0 drop 0 life (KB/Sec) 4504577/22053
sh ip route:
Gateway of last resort is 0.0.0.0 to network 0.0.0.0
111.*.*.0/32 is subnetted, 1 subnets
C 111.*.*.* is directly connected, Dialer0
213.228.116.0/32 is subnetted, 1 subnets
C 213.228.116.99 is directly connected, Dialer0
192.168.254.0/30 is subnetted, 1 subnets
C 192.168.254.0 is directly connected, Tunnel0
C 192.168.1.0/24 is directly connected, Vlan1
S 192.168.2.0/24 is directly connected, Tunnel0
S 192.168.3.0/24 [1/0] via 333.*.*.*
S* 0.0.0.0/0 is directly connected, Dialer0