Cannot reach the destination of an IPSec tunnel through another IPSec tunnel

Hi all

I have a PIX 515E version 8.0 (2).

I have two remote sites connected to this PIX via IPSec tunnels.

Each remote site can reach local networks behind the PIX, but I can't reach remoteSiteB remoteSiteA.

Thus,.

SiteA <----- ipsec="" -----="">PIX1 SiteX <---------------->10.0.8.1 10.30.8.254

SiteB <----- ipsec="" -----="">PIX1 SiteX <---------------->10.0.8.1 10.138.34.21

SiteA can ping SiteX

SiteB can ping SiteX

SiteA cannot ping SiteB

SiteB cannot ping SiteA

If I do not show crypto isakmp ipsec his I see appropriate subnets:

Tag crypto map: CRYPTO-MAP, seq num: 4, local addr: 203.166.1.1

permit access-list ACLVPN-TO_SITEA ip 10.138.34.16 255.255.255.240 host 10.30.8.254

local ident (addr, mask, prot, port): (10.138.34.16/255.255.255.240/0/0)

Remote ident (addr, mask, prot, port): (10.30.8.254/255.255.255.255/0/0)

current_peer: 104.86.2.4

Tag crypto map: CRYPTO-MAP, seq num: 5, local addr: 203.166.1.1

access-list ACLVPN-TO_SITEB allowed host ip 10.30.8.254 10.138.34.16 255.255.255.240

local ident (addr, mask, prot, port): (10.30.8.254/255.255.255.255/0/0)

Remote ident (addr, mask, prot, port): (10.138.34.16/255.255.255.240/0/0)

current_peer: 216.178.200.200

Journal messages that seem to point to the problem...

April 18, 2013 13:27:35: % PIX-4-402116: IPSEC: received a package of ESP (SPI = 0xD51BB13A, sequence number = 0x21A) 104.86.2.4 (user = 104.86.2.4) at 203.166.1.1.  Inside the package décapsulés does not match policy negotiated in the SA.  The package indicates its destination as 10.138.34.21, its source as 10.30.8.254 and its Protocol 6.  SA specifies its local proxy like 10.0.8.0/255.255.255.0/0/0 and his remote_proxy as 10.30.8.254/255.255.255.255/0/0

My question is really what I have to do something funky to allow traffic to pass between the two tunnels?

Hello

This could be much easier if we have seen the real configurations.

But here are some things to be confirmed in the configurations (some of them you mentioned above, but I still quote once again)

  • Make sure that each firewall, you set the appropriate VPN L2L ACL
  • Make sure that you have configured NAT0 on the central PIX "outside" interface for the Site A and Site B
  • Make sure the Central PIX has "same-security-traffic permit intra-interface" configured. This will allow the Site traffic to enter the Central PIX 'outside' interface and head back on the same interface to Site B. And vice versa.

To view some actual configurations that may be required provided everything else is ok. (I assume that all devices are Cisco)

Central PIX

permit same-security-traffic intra-interface

A connection to the site

SITE-A-CRYPTOMAP of the 10.0.8.0 ip access list allow 255.255.255.0 host 10.30.8.254

SITE-A-CRYPTOMAP of the 10.138.34.16 ip access list allow 255.255.255.240 host 10.30.8.254

Site B connection

SITE-B-CRYPTOMAP of the 10.0.8.0 ip access list allow 255.255.255.0 10.138.34.16 255.255.255.240

SITE-B-CRYPTOMAP to the list of allowed access host ip 10.30.8.254 10.138.34.16 255.255.255.240

NAT0

access list for the INTERIOR-NAT0 allowed ip 10.0.8.0 255.255.255.0 host 10.30.8.254

access list for the INTERIOR-NAT0 allowed ip 10.0.8.0 255.255.255.0 10.138.34.16 255.255.255.240

NAT (inside) 0-list of access to the INTERIOR-NAT0

OUTSIDE-NAT0 allowed host ip 10.30.8.254 access list 10.138.34.16 255.255.255.240

OUTSIDE-NAT0 allowed ip 10.138.34.16 access list 255.255.255.240 host 10.30.8.254

NAT (outside) 0-list of access OUTSIDE-NAT0

Site has

CENTRAL-SITE-CRYPTOMAP to the list of allowed access host ip 10.30.8.254 10.0.8.0 255.255.255.0

CENTRAL-SITE-CRYPTOMAP to the list of allowed access host ip 10.30.8.254 10.138.34.16 255.255.255.240

the INTERIOR-NAT0 allowed host ip 10.30.8.254 access list 10.0.8.0 255.255.255.0

the INTERIOR-NAT0 allowed host ip 10.30.8.254 access list 10.138.34.16 255.255.255.240

NAT (inside) 0-list of access to the INTERIOR-NAT0

Site B

CENTRAL-SITE-CRYPTOMAP of the 10.138.34.16 ip access list allow 255.255.255.240 10.0.8.0 255.255.255.0

CENTRAL-SITE-CRYPTOMAP of the 10.138.34.16 ip access list allow 255.255.255.240 host 10.30.8.254

the INTERIOR-NAT0 allowed host ip 10.138.34.16 access list 255.255.255.240 10.0.8.0 255.255.255.0

the INTERIOR-NAT0 allowed host ip 10.138.34.16 access list 255.255.255.240 host 10.30.8.254

NAT (inside) 0-list of access to the INTERIOR-NAT0

Hope this helps

-Jouni

Tags: Cisco Security

Similar Questions

  • Continually, I get the error that cannot reach the server while trying to install SP1.

    Win XP Pro reloading, get all updates

    I reinstalled Windows XP Pro and need to update to SP1 to 3 as well as all security updates.  (After download) installation, SP1, I continually get the error that cannot reach the server, visit Web of MS for a version that requires no web access if the problem persists. I can't find this version of SP1 that does not need to happen on the server from Ms.  In addition, isn't there an easier way to get all updates when you perform a new installation instead of going one by one with all the updates?

    If you have SP1A, then you can go straight to the installation of SP3.  If you have SP1, then you need to install SP1A or SP2 before going to SP3.  You can get the updates described in the following article:

    "How to obtain the latest Windows XP service pack"
      <>http://support.Microsoft.com/kb/322389/ >

    HTH,
    JW

  • internal hosts cannot access the internet w / L2L configured tunnel

    The internal hosts behind the ASA cannot access the internet with a configured tunnel to L2L. The L2L tunnel is mounted and passing traffic correctly. However, the internal host cannot access the internet through the ASA. I think I have my NAT watered somewhere. I can't even a host statically mapped to the internet. It might be because I'm used to having a WAN IP to the external interface which differs by the CIDR block assigned by the ISP. In this case, it's all together, with the ASA outside interface occupying the first available address.

    We have been assigned a CIDR range x.x.x.64/28. x.x.x.65 is my front door and my first usable est.68, by the PSI (I guess what they utilisent.66 et.67 for internal use). External interface of the ASA est.68 and I'm trying to get NAT others. I'm Polo all DHCP clients internal and have some static entries as well. Below is the relevant NAT config. Yet once, all traffic passes above the tunnel properly, but not from inside to outside. If more information is needed, please advise.

    interface outside

    IP address x.x.x.68 255.255.255.240

    NAT-control

    Global x.x.x.69 - x.x.x.77 2 (outdoor)

    Global 1 x.x.x.78 (outside)

    NAT (inside) 0 access-list sheep

    NAT (inside) 1 10.10.10.0 255.255.255.0

    public static x.x.x.69 (inside, outside) STATIC_NAT_EXAMPLE netmask 255.255.255.255

    internal access-group interface inside

    Route outside 0.0.0.0 0.0.0.0 x.x.x.65 1

    internal to the 10.10.10.0 ip access list allow 255.255.255.0 any

    ! Remote LAN is 192.168.10.0/24

    access-list sheep extended ip 10.10.10.0 allow 255.255.255.0 192.168.10.0 255.255.255.0

    Can you post a "show sysopt run?

    Try this command to enable proxy arp.

    No outside sysopt noproxyarp

  • Windows 7 Advisor - cannot reach the server

    I installed the Windows 7 advisor and both yesterday and today, he cannot reach the server updates - or before scanning - so it does not work for me.  Any ideas? The server is down? I can access many other things!

    It seems to run normally today.

  • Cannot create the destination file during the file extraction

    I am trying to install a program from a zip compressed file, but Windows will not let me. When I try to run the files directly from the zip, it tells me that 'the destination file cannot be created." Alternatively, when I try to extract the individual files in the zipped folder, I get "error code 0x80004005".

    I am running Windows 7 64 bit and I've never had this problem before. Any help would be appreciated!

    You can try to register the .dll file and see if that makes a difference.

    From an elevated command prompt try regsvr32 zipfldr.dll

    You can also create another user to see if they have the same problem.

  • Win LR 6.4 import/Add - cannot change the destination of the catalogue

    Using LR 6.4 and has several hard drives installed on my desktop computer.  LR (.lrcat) catalogs are on the G drive - and have always been on the G drive.  LR and Photoshop are also installed on drive G.  My photos are in the folders on the F drive.  My two catalogues are given due recognition in the preferences as being on drive G.

    When I use the import - Add command, LR allows me to choose the source, but immediately chooses the destination as "My catalog" C drive.  Although there is a small box next to the C drive, it is unusable and I can't find a way to change the destination.  If I use other commands such as copy, I am able to change the destination.  But whenever I load photos from a disc, I have for them to make a folder on the F drive and copy them from the disk to the new folder.  Then, I want to add these pictures to the catalog that is currently active.  I want to add them without moving... l

    I did a search for .lrcat and all the catalogs were on drive G, as they are supposed to be.  However, there is an entry on the C drive that is marked as a MS Word file and it is called: Lightroom assessment.docx.  A paragraph seemed more likely guilty, but I don't know if I should change it and if so, what to change:

    The application folder: G:\Program Adobe Lightroom

    Library path: G:\Lightroom Backups\June2015\June2015.lrcat

    \Adobe\Lightroom

    Settings folder: C:\Users\mg\AppData\Roaming

    Thanks for any help or suggestions.  Is to make the process even very frustrating catalog help

    No matter that one of your hard drives, the catalog is on. If this catalog is one that is active, then it is one which will contain references to imported pictures. When you use the add in the import dialog box images are added to the catalogue of their current location. You cannot specify a different destination when you use this option. When you use the copy option, then you are able to specify a destination in the right column of the import dialog box. You must choose the appropriate drive and the main folder in the folder tree that appears. Then, specify the name of the subfolder in the highlighted area:

    You talked about change the destination of the catalog. It was a poor choice of words or you don't understand how the catalog works. The catalogue is available in one place. Normally it does not move anywhere unless you choose to do it manually. You can control the destination of your imported images, and Lightroom will import to the destination on any hard drive. But they are managed using the catalogue that remains in one place.

  • Please help, my iphone cannot reach the cellular network

    Please help me, my phone can not reach the cellular network since this morning (5 h). I have already contacted the network support and they said that there is nothing wrong with the network. the State on the screen 'search'... Please help me... I can't use my phone... Help, please

    You can try to reset your device. It will not destroy your data.

    Press and hold the sleep/wake button

    Press and hold the Home button

    Press and hold both buttons until the display turns off and on again with the Apple logo on the subject.

    Another way is to go to settings - general - reset - Reset all settings

  • Cannot reach the update page

    Outlook 2007 crashes.  Problem report generates a message to install the office update, but I can't reach the Web site update as an automatic update in place.  How can I find the necessary update?

    Hello

    Which is exactly the problem that you are facing with update?

    I suggest you follow the link and check.

    Install Windows updates

    http://Windows.Microsoft.com/en-us/Windows-Vista/install-Windows-updates

    I also suggest that you send your request from the link and check.

    http://www.Microsoft.com/Office/Community/en-us/FlyoutOverview.mspx

  • Windows Installer cannot find the Destination component

    After wash starts the Windows Installer window if poster once finished top of desktop. The process takes about a minute. Windows Installer message is, "Preparation for installation." Then, the Destination component appears with message "Please wait while Windows configures the destination component", and shows the progress bar. Then, the Destination component window appears with the message, "an installation package to the Destination of the product component is not found. Try the installation again using a valid copy of the installation package, "Destination. msi´."

    This package is not in my computer. This happens everytime I turn on the computer. The whole process is very long. How can I fix it so that the message?

    Thank you for your help.

    Hi lmcrae,

    Put your computer in a clean boot configuration to determine which product is responsible for this. Clean boot is a way convenient, safer to change the options for startup in the registry; You can turn individual items or disable freely to try various combinations up to that narrow you the problem. Once you find out, post details about the same so that we can take additional measures.

    Please see this article for detailed information on how to do it.

    How to troubleshoot a problem by performing a clean boot in Windows Vista or in Windows 7

    Note: Ensure that you switch your computer to normal startup mode after completing the troubleshooting steps. Steps are available in the article above.

    Kind regards

    Shinmila H - Microsoft Support

    Visit our Microsoft answers feedback Forum and let us know what you think.

  • AppAssure BMR cannot find the Destination disk.

    I am preforming a bare metal restore material disimillar and Appassure cannot find the drive on the target computer.

    Restore dell Poweredge R430 13g. The discs are in a controlled by a H330 PERC RAID 1.

    Is there something I am missing, usually displays the disc without any problems?

    Thanks for the support!

    Inject you the Perc controller drivers in the boot cd when it was created? If this isn't the case, then this is probably the issue.  He can't access the storage controller so he can't see the disks.

  • Cannot reach the controls on panels

    I just started using 2 screens - Macbook Pro and Asus.  I use PS CC and I moved back points between the two, but then now I am not able to move.  When I tried to drag the panels to my other screen they moved higher up on the screen but no more switch to another view.  In the meantime, the panels are pushed way to the top and I can't reach the top where controls are to resize or move.  I tried to turn and then turn it on again but still the same.  How can I get these?  Thank you!

    I am a Windows user and not familiar with how double Mac displays, but it sounds a bit like your system is not configured for the position of the poster.  I can choose a screen and drag it to the position, so when I move the slider to the right, it moves the screen 2 on three screen.  If my screens have been set up in this way, but the physical positions was different, then it would be confused because the cursor does not seem to obey the mouse.

    So first of all, turn off your second screen so that you can see all your dashboards and reset your workspace.

    Then turn on the second screen again after checking that the physical and operating system to reach his position.

    Organize your panels, and then save it as a new workspace.

    Don't forget that you can save custom keyboard shortcuts and personalized workspaces customized toolbar configurations.  This is a very cool and useful feature.

    I hope this has helped, but if I misunderstood your question, please tell a little more about the problem.

  • 55XD8505 it recharges continuously--cannot reach the factory reset

    Hello

    My 55XD8505 2016 is having issues. When you enter the home menu is extremely slow and leave then it is only a matter of minutes before the device reboots. If I just start the TV and stay away from the home menu, I can watch TV.

    Now, my intention is to restore the factory settings to try to get the system going again. Normally a reset of the Android system can be done either

    (1) via the settings menu

    or

    (2) by switch on the unit with the volume on/off button + start button / stop key and use recovery menu.

    I can't do 1) since any speed, I navigate the menu of settings, the TV restarts before I can fill a selection of factory settings.

    I can't do 2) either - at least all the possible combinations of Sony, I found does not apply for my TV

    I'm all of ideas - is it possible to factory reset via the USB port (perhaps using ADB)?

    A nailed!

    I discovered that you can use 'top' under adb shell. I did the following:

    (1) connect adb

    (2) adb shell

    (3) top m 5 (this lists the first 5 cpu by using the applications)

    After running high and enter the main menu, I saw the CPU use climbing, and the app in the foreground was always/system/bin/mtkbt, which I figured well be related to Bluetooth. So, after a few attempts of menu navigation speed, I managed to enter the bluetooth menu and disable bluetooth before it restarts.

    Success! Now I can navigate the menu of home once again, I have the tried clear the data cache / anything related to bluetooth from the menu applications and then reactivate bluetooth, but alas the problem returns. So now I'm running the TV without bluetooth. I could try to factory reset the TV tomorrow to see if it helps - at least now I can actually reach the factory reset menu.

    UPDATE:

    Now after you turn off the bluetooth, I could navigate the menu to factory reset. After doing a reset complete, it seems that everything is back to normal - even with bluetooth enabled. Problem solved... Thanks adb.

  • Client cannot get the external IP of DHCP address through WiM

    WISN 5.2.178.0

    6509 12.2 (33) SXH2a

    WISN is in place, 1231 & 1131 joined APs, radio stations upwards, the customer associated but not an IP address.

    Virtual interface with vlan # & IP on the destination VLAN.

    WLAN with same vlan # as above.

    I tried Open, PSK, WPA. Client cannot obtain an IP address.

    What did I miss?

    You have the virtual address set to 1.1.1.1?

    Also, you have set up the address of the DHCP server on your interfaces VLAN? This is important because the controller basically uses an ip helper address to properly forward DHCP requests.

    If you have these configured, try to use the internal DHCP server to test. The web GUI, access controller-> the DHCP server in-house. Configure a DHCP scope and activate it (don't worry, it is only used for wireless clients. It does not meet the DHCP requests on your network).

    Now, go back to the controller-> Interfaces and configure the DHCP server to the management interface of the controller. See if your customers are able to get the addresses of the internal scope.

  • Cannot save the document - read-only or opened by another user error occurs when the PDF is opened in Windows Explorer

    Adobe Pro XI - use the operating system to Windows 7 Pro

    When a PDF document is open in Windows Explorer, and pages are added, deleted, ratings, all types of changes, he cannot be saved until the Windows Explorer is completely closed.  If you try to save the document, you receive the error message next - "the document could not be saved.  The file may be read-only, or another user may have his opening.  Please save the document under a different name or in a different folder. «I have confirmed the document is not read only, it is not open by another user, and this is not open many times.»  Once completely, you close Windows Explorer and try to save the document, it saves without problem.

    Are there settings in Adobe Pro XI or Windows that allows you to save documents without closing Windows Explorer first?

    Thanks for any help you can provide.  This error is a frustration because I open all my documents via Windows Explorer.

    Turn off the preview in Windows Explorer.

  • Cannot reach the remote device.

    Hello I am a strange problem and would be grateful to have any insight as to why this is happening.

    The ASA is set up for two remote devices as follows

    object obj-SV4(1:1) network
    Home 172.16.2.24

    object obj-SV5(1:1) network
    Home 172.16.2.25

    object obj-SV4(1:1) network
    NAT static xxx.xxx.xxx.183 (indoor, outdoor)

    object obj-SV5(1:1) network
    NAT static xxx.xxx.xxx.184 (indoor, outdoor)

    ASA # ping 172.16.2.24
    Type to abort escape sequence.
    Send 5, echoes ICMP 100 bytes to 172.16.2.24, wait time is 2 seconds:
    !!!!!
    Success rate is 100 per cent (5/5), round-trip min/avg/max = 18/10/20 ms
    ASA # ping 172.16.2.25
    Type to abort escape sequence.
    Send 5, echoes ICMP 100 bytes to 172.16.2.25, wait time is 2 seconds:
    ?????
    Success rate is 0% (0/5)

    When I trace the two devices to:

    trace 172.16.2.25

    Type to abort escape sequence.
    The route to 172.16.2.25

    1 172.28.213.202 0 ms 0 ms 0 ms
    2 172.28.209.109 20 ms 20 ms 10 ms
    3   *  *  *
    4   *  *  *

    trace 172.16.2.24

    Type to abort escape sequence.
    The route to 172.16.2.24

    1 172.28.213.202 0 ms 0 ms 0 ms
    2 172.28.209.109 10 ms 20 ms 20 ms
    3 172.28.209.110 20 ms 10 ms, 20 ms
    4 172.16.2.24 20 ms 20 ms 10 ms

    When I'm on the peripherique.109 he has the road to the entire subnet and I can reach le.24 et.25 both of him.

    RTR #sh ip short int | Inclure.109
    172.28.209.109 GigabitEthernet0/1.131 YES manual up up

    Ping the server Samba 172.16.2.24

    Type to abort escape sequence.
    Send 5, echoes ICMP 100 bytes to 172.16.2.24, wait time is 2 seconds:
    !!!!!
    Success rate is 100 per cent (5/5), round-trip min/avg/max = 1/1/4 ms
    Ping the server Samba 172.16.2.25

    Type to abort escape sequence.
    Send 5, echoes ICMP 100 bytes to 172.16.2.25, wait time is 2 seconds:
    !!!!!
    Success rate is 100 per cent (5/5), round-trip min/avg/max = 1/1/4 ms

    the road is

    Server IP route vrf 172.16.2.0 255.255.255.0 NAMESERVERS 172.28.209.110

    Any advise will be appreciated.

    Hello

    What is the device that owns the IP 172.28.209.110? She or one of the other devices on the way to the ASA there any type of ACL or anything else that might block traffic?

    You see no link on the SAA (or all newspapers gathered the SAA) host 172.16.2.25?

    Is there some ports TCP is listening on the server that should respond to connection attempts? You could try TCP Ping of the SAA for ports

    TCP ping 172.16.2.25

    You can also give a "source" address in the command above, if you need. When you run the Software ASA below 8.4 (1) then the custom above 'ping tcp' to be supported.

    -Jouni

Maybe you are looking for