Backup peer on the SAA does not when peer 2

Execution of ASA 5505 with version 8.2 (2).

I configured a backup with this configuration encryption counterpart:

outside_1_cryptomap to access ip 192.168.1.0 scope list allow 255.255.255.0 10.
0.1.0 255.255.255.0

Crypto ipsec transform-set ESP-AES-128-SHA aes - esp esp-sha-hmac
Crypto ipsec transform-set esp-SHA-ESP-3DES-3des esp-sha-hmac
life crypto ipsec security association seconds 28800
Crypto ipsec kilobytes of life - safety 4608000 association
card crypto outside_map 1 match address outside_1_cryptomap
card crypto outside_map 1 set of peer X.X.X.X
card crypto outside_map 1 set of transformation-ESP-3DES-SHA
card crypto outside_map 2 match address outside_1_cryptomap
outside_map 2 peer Y.Y.Y.Y crypto card game
card crypto outside_map 2 game of transformation-ESP-3DES-SHA
outside_map interface card crypto outside
crypto ISAKMP allow inside
crypto ISAKMP allow outside
crypto ISAKMP policy 10
preshared authentication
3des encryption
sha hash
Group 1
life 86400

The tunnel work well when the peer 1, X.X.X.X (ping between host 192.168.1.2 and 10.0.1.3 on private networks).  When he switches to 2 counterpart, Y.Y.Y.Y tunnel comes up with Y.Y.Y.Y as breakpoint as being verified in ' show crypto ipsec his '.  However I cannont pass all traffic through at the peer 2 is in place.  Note that the peer on the other side is a multi-WAN device and X.X.X.X and Y.Y.Y.Y attached and failure is created by unplugging X.X.X.X by the device...

When I run a command packet-trace ASA using ICMP (entry packet-trace inside the 192.168.1.2 icmp 8 0 10.0.1.3 retail) stage 12 he ignores the package when it starts to encrypt the packet. It corresponds to crypto debugs on the crypto ACL early in Phases (Phase 3) so I know the package is headed toward the tunnel.  See failure below.  It is said that flow is denied by rule configured.

Phase: 12
Type: VPN
Subtype: encrypt
Result: DECLINE
Config:
Additional information:
Direct flow from returns search rule:
ID = 0xd8a5bc30, priority = 70, domain = encrypt, deny = false
hits = 420, user_data = 0 x 0, cs_id = 0xd8a5b548, reverse, flags = 0 x 0 = 0 protocol
SRC = 192.168.1.0 ip, mask is 255.255.255.0, port = 0
DST ip = 10.0.1.0, mask is 255.255.255.0, port = 0, dscp = 0 x 0

Result:
input interface: inside
entry status: to the top
entry-line-status: to the top
output interface: outside
the status of the output: to the top
output-line-status: to the top
Action: drop
Drop-reason: flow (acl-drop) is denied by the configured rule

I tried to debug the acl on the filter, but cannot get the higher level at 1.

Any ideas on what I need in the config or what else can I use to debug?

Have you tried to put both the peer set under the same outside the map statement:--

card crypto outside_map 1 set counterpart x.x.x.x

card crypto outside_map 1 set counterpart y.y.y.y

I need to do it on one of my firewall, but I got this information from cisco Tac (verbly - not implemented yet) it works fine.

It may be useful

Manish

Tags: Cisco Security

Similar Questions

  • After hiighlighting a Word and paste it into another document, the Clipboard does not; When I hit enter again and again blocks. How should I do?

    When I select a word or phrase and copy to the Clipboard, then paste it into another area of the Clipboard does not erase the expression. Therefore, every time that I type and press the Enter key it continues paste the sentence throughout my document. I have the latest download of Firefox are installed (16.0, win 7 and that's when it started.) How to stop this heinous behavior so I can type a sentence with normality?

    Louise

    Try Firefox Safe mode to see how it works there.

    A way of solving problems, which disables most of the modules.

    The problems of Firefox using Firefox SafeMode

    When in Safe Mode...

    • The State of plugins is not affected.
    • Custom preferences are not affected.
    • All extensions are disabled.
    • The default theme is used, without a character.
    • userChrome.css and userContent.css are ignored.
    • The layout of the default toolbar is used.
    • The JIT Javascript compiler is disabled.
    • Hardware acceleration is disabled.
    • You can open the mode without failure of Firefox 15.0 + by pressing the SHIFT key when you use the desktop Firefox or shortcut in the start menu.
    • Or use the Help menu option, click restart with the disabled... modules while Firefox is running.

    To exit safe mode of Firefox, simply close Firefox and wait a few seconds before using the shortcut of Firefox (without the Shift key) to open it again.

    If it's good in Firefox Safe mode, your problem is probably caused by an extension, and you need to understand that one.

    http://support.Mozilla.com/en-us/KB/troubleshooting+extensions+and+themes

    When find you what is causing that, please let us know. It might help others who have this problem.

  • the icons on the desktop does not when you click on

    no desktop icons do not respond when clicked on

    no desktop icons do not respond when clicked on

    1 Rebuid icon Cache...
    http://www.SevenForums.com/tutorials/49819-icon-cache-rebuild.html

    2. If the icon Cache rebuild does not help...
    Press Ctrl + Alt + Delete all > click Task Manager > processes tab > right-click on explorer.exe > click on end process > Application tab > new task... > in the Open box, type explorer.exe > OK
    Check the icons on the desktop.

  • Adjust the width does not when you link directly to the page number

    I put my initial notice to adjust the width.  If I only log to the file, the document fits the width.  However, when I add a number of specific page for the link, the document opens to the top of the entire page.  It does not match the width.  Is there something else I need to put or is this how it is supposed to work?  When I add destinations, the width adjustment seems to work very well.

    Try adding view = fifth parameter as:

    http://example.org/doc.PDF#page=72&view=fitH, 100

    www.Adobe.com/devnet/Acrobat/PDFs/pdf_open_parameters.PDF

  • Failover of the SAA does not work

    I am trying to get 2 ASA to failover in the laboratory, but Im not having not successful:

    Sho kentasa1 # fail

    Failover on

    Unit of primary failover

    Failover LAN interface: GigabitEthernet0/3.1 failover (Failed - passage to the No.)

    Frequency of survey unit 1 seconds, 15 seconds holding time

    Survey frequency interface 5 seconds, 25 seconds hold time

    1 political interface

    Watched 3 Interfaces maximum 250

    failover replication http

    Version: Our 7.2 (1), mate unknown

    Last failover to: 10:21:00 GMT Sep 19 2006

    This host: primary: enabled

    Activity time: 1126090 (s)

    slot 0: ASA5520 hw/sw rev (status 1.1/7.2(1)) (upward (Sys)

    Management interface (10.0.10.10): Normal (pending)

    Interface inside (10.254.0.2): no link (pending)

    Interface to the outside (206.67.136.3): no link (pending)

    Dmz (192.168.1.3) interface: no connection (not guarded)

    Interface mtadmz (192.168.255.1): No. Link (unguarded)

    Slot 1: vacuum

    Another host: secondary - failed

    Activity time: 0 (s)

    slot 0: vacuum

    Management interface (0.0.0.0): unknown (pending)

    Interface inside (10.254.0.252): unknown (pending)

    Interface to the outside (206.67.136.253): unknown (pending)

    DMZ (192.168.1.253) of the interface: unknown (not guarded)

    Mtadmz (192.168.255.253) of the interface: unknown (not guarded)

    Slot 1: vacuum

    Failover stateful logical Update Statistics

    Link: failover GigabitEthernet0/3.1 (Failed)

    Stateful Obj xmit rcv rerr xerr

    General 0 0 0 0

    sys cmd 0 0 0 0

    time 0 0 0 0

    RPC services 0 0 0 0

    Conn TCP 0 0 0 0

    Conn UDP 0 0 0 0

    ARP tbl 0 0 0 0

    Xlate_Timeout 0 0 0 0

    VPN IKE upd 0 0 0 0

    VPN IPSEC upd 0 0 0 0

    VPN CTCP upd 0 0 0 0

    VPN SDI upd 0 0 0 0

    VPN DHCP upd 0 0 0 0

    Logical update queue information

    Heart Max Total

    Recv q: 0 0 0

    Q xmit: 0 0 0

    I went through the docs but I think Im doing everything right. Attached are the configs to see if I missed something. Thank you!

    Bob

    First of all, there is no failover Interface is in place. It should look like:

    Failover LAN interface: FAILOVER of GigabitEthernet0/3 (top)

    In addition, a sh int on your failover interface must show that it is to the top and to the top.

    -Jon

  • Why the script does not when I use the action "success: Show '?

    Hi all

    I have a group of objects, that are initially hidden from view. I also have a button on the slide, which is configured to display this group of objects by clicking on it.

    The timeline is put on pause after 3 seconds, allowing the user to press the button to display the hidden group - but when the button is clicked the timeline resumes, I don't want to happen.

    No idea how can I avoid this problem?

    Captivate 8.0.1

    By replacing the simple action by action standard oneliner. Take a look on:

    Why choose Standard Simple action? -Captivate Blog

    This blog also has a link to a YouTube video that shows the difference.

  • Some keys on the keyboard does not when the phone is vertical

    Hello

    A week ago, some of my (H & B) buttons do not work. When I press the letters that surround them developed. It's the same thing when I'm doing my alarms (17 hundred hours). Any ideas as to why please?

    Settings > about phone > diagnostics > test > test the touch screen.

  • "Update of the server does not" when you try to update Acrobat 9 Pro

    I just installed Acrobat 9 Pro on my desktop and on my laptop. I was able to download and install the latest updates for the copy on my desktop computer (so that it is now version 9.3.0), use help > check updates.

    When I try the same command on my laptop, I get and error message "update server is unresponsive, which means that it may be offline at the moment, or the Internet settings or firlewall may be incorrect. Please try again later. "I tried several times yesterday and today with the same error. The message appears immediately; apparently not yet actually try to connect.

    I disabled my firewall and antivirus and always get the same result. I uninstalled then reinstalled Acrobat and still get the same result.

    I looked online on Adobe.com to see on the download and installation of updates manually, but it is difficult for me to say what updates, I need. Some are for other languages and some are 64-bit, but I have Windows 7 32 bit.

    A call to technical support was no help. The agent seemed to think because I installed the 9.0 version I needed only one English updated appearing on the page of download under 9.0, not updates later... And he said that Adobe recommends manually installation of updates of the site Adobe.com rather than use the control for the control of updates (?).

    In any case, anyone know what might cause this problem with the adobe update? Maybe I need to reinstall the update (where is it?).

    OR

    Can someone tell me who the updates listed on the page to dowload Acrobat should I install manually to bring my camera to date?

    [Running Windows 7 32-bit on both machines]

    Thank you.

    With all the respect that is due to the Bill, which is completely not the point of the question... you SHOULD be able to use the automatic update to easily update your Adobe products.  I have this talk frankly because I knew the incredible frustration of trying in vain to update my Adobe Creative Suite on my laptop.  I am assuming that you are trying to update Acrobat on a laptop and not on a desktop computer (not didn't have the same problems with my desktop PC).  The Merry is actually quite simple, just follow these steps:

    1. open the network and sharing Center
    2. click on change adapter settings
    3. right click on the map to Microsoft Virtual WiFi Miniport, and then click on disable.
    4. open Adobe Reader and help > check for updates

    And voila, updates to the Adobe Updater.  Enjoy!

  • I have a problem connecting on ebay if you use firefox, I get a message saying that the page does not not despite having cleared my cache and cookies.

    I have a problem connecting on ebay when you use firefox, it has been fine for years, but since a few days, I get a message saying that the page does not when I try to log in. I tried to clear my cookies and cache, but it makes no difference. This does not occur in google chrome and I can log on fine there so what's the problem with firefox?

    Do you also have this problem if you temporarily switch to private browsing mode?

    • Tools > Options > privacy, choose the setting Firefox will: use the custom settings for the story of
    • Select: [X] 'always use private browsing mode '.

    Start Firefox in Firefox to solve the issues in Safe Mode to check if one of the extensions or if hardware acceleration is the cause of the problem (switch to the DEFAULT theme: Firefox/tools > Modules > appearance/themes).

    See also:

  • Firefox seems to have recently developed seemingly random usually do not remember bookmarks, particularly when the pc does not stop correctly. Thank you

    Firefox seems to have recently developed seemingly random usually do not remember bookmarks, particularly when the pc does not stop correctly. Thank you

    If Firefox detects that the places.sqlite database is corrupted then Firefox can create a new database file and import bookmarks from a JSON backup that does not contain the most recent bookmarks (a new JSON backup is created when you run Firefox for the first time on a day), then you may lose the bookmarks in such a case.

    You can check for problems with the database places.sqlite file in the Firefox profile folder.

  • having an iphone 6.  The ringtone does not make a noise.   I tested the ringtone and it sounds however when I receive a call or text or email, the Bell is silent

    I have an iphone 6.  The ringtone does not make a noise.   I tested the ringtone and it sounds however when I receive a call or text or email, the Bell is silent

    Hello Jimmy10 66,

    Thank you for reaching out to the Community Support from Apple. I know how it is important to follow your alerts, and I want to help you get your work again.

    Before we get too far, it's always a good idea to check that your 'secret' button just above your volume controls is not engaged. If you see that the yellow indicator go ahead and switch to the other position to turn it off.

    Alternatively, you can drag up from the bottom of the screen and make sure that the control of "do not disturb" is disabled.

    If those who are for the time off, go ahead and restart your phone and retest alerts. If the behaviour continues or if you encounter any problems, please reach out again and let the community know what other steps you have tried. The entire community is here to help.

    Best regards

  • When a link to open another application and firefox is closed, Firefox opens but the link does not work

    I use Firefox on Mac OS 10.9.2, 29, this problem has occurred on the OS 10.8 ~ and various other versions of FF. I use 29 simply because I like it!

    The problem: Firefox is configured as the default browser in all directions it is possible to set as the default value. However, when I click on a URL from any application and Firefox is closed, Firefox opens opens, my last session of navigation tabs start, but the link does not open. I must return to the application and click the link again. This only happens on Firefox. I can put any other default browser and it will open the link in a closed state.

    This is happening to me, same, on Mac OS X 10.6.8 but only since I've upgraded to the latest version of Firefox, 32.0.1. I can click on a HTTP link in another application and Firefox becomes the active application, but it will not load a new tab for the link, as expected. Instead, it just sits there. I have to go back to the other application and click on the link a second time, during which point Firefox correctly open a new tab and load the destination URL.

  • no service to customer without having to pay when the product does not work?

    no service to customer without having to pay when the product does not work?

    You will need to tell us more of the history for anyone to be able to give advice. The WHOLE story would be great!

  • Key on the keyboard does not work in firefox box when you type in the web site, but it works everywhere else?

    Key on the keyboard does not work in firefox box when you type in the web site, but it works everywhere else?

    Try Firefox SafeMode to see how it works there.

    A way of solving problems, which disables most of the modules.

    (If you use it, switch to the default theme).

    • You can open the mode without failure of Firefox 4.0 + by pressing the SHIFT key when you use the desktop Firefox or shortcut in the start menu.
    • Or use the Help menu option, click restart with the disabled... modules while Firefox is running.

    Do not choose anything at the moment, just use 'continue in safe mode.

    To exit safe mode of Firefox, simply close Firefox and wait a few seconds before using the shortcut of Firefox (without the Shift key) to open it again.

    If it's good in Firefox Safe mode, your problem is probably caused by an extension, and you need to understand that one.

    http://support.Mozilla.com/en-us/KB/troubleshooting+extensions+and+themes

    Can be caused by an add-on to the AVG.

    When find you what is causing that, please let us know. It might help others who have this problem.

  • Mail does not when you try to delete the message attach a file on new message

    I bought my wife a new MacBook, retina 12 "early 2015, 1.3 GHz Intel Core M, 8 GB 1600 MHz DDR3, running OS X El Capitan 10.11.3 with his old Mac, she would frequently get the ball from spinning to death when she tried to delete an e-mail message, and also when she creates a new message and tried to attach a file.  I was hoping that the new computer would solve this problem.  However, he still does sometimes, but not as often and does not have as much time to finally react.  Activity monitor says that the Mail does not respond when the small wheel is happening.  Looks like there is a corrupted somewhere file that got transferred to the new computer.  Any suggestions on how to solve it?  Previous posts suggested to remove the tray to sand, but the method, that said, does not have the folder that I had to remove.

    Please launch the Console application in one of the following ways:

    ☞ Enter the first letters of his name in a Spotlight search. Select from the results (it should be at the top).

    ☞ In the Finder, select go utilities ▹ of menu bar or press the combination of keys shift-command-U. The application is in the folder that opens.

    ☞ Open LaunchPad and start typing the name.

    The title of the Console window should be all Messages. If it isn't, select

    SYSTEM LOG QUERIES ▹ all Messages

    in the list of logs on the left. If you don't see this list, select

    List of newspapers seen ▹ display

    in the menu at the top of the screen bar.

    Click on the clear view icon in the toolbar. Then take an action that does not work the way you expect. Select all of the lines that appear in the Console window. Copy to the Clipboard by pressing Control-C key combination. Paste into a reply to this message by pressing command + V.

    The journal contains a large amount of information, almost everything that is not relevant to solve a particular problem. When you post a journal excerpt, be selective. A few dozen lines are almost always more than enough.

    Please don't dump blindly thousands of lines in the journal in this discussion.

    Please do not post screenshots of log messages - text poster.

    Some private information, such as your name or e-mail address, can appear in the log. Anonymize before posting.

    When you post the journal excerpt, an error message may appear on the web page: "you include content in your post that is not allowed", or "the message contains invalid characters." It's a bug in the forum software. Thanks for posting the text on Pastebin, then post here a link to the page you created.

    If you have an account on Pastebin, please do not select private in exposure menu to paste on the page, because no one else that you will be able to see it.

Maybe you are looking for