Cannot reach the destination of an IPSec tunnel through another IPSec tunnel
Hi all
I have a PIX 515E version 8.0 (2).
I have two remote sites connected to this PIX via IPSec tunnels.
Each remote site can reach local networks behind the PIX, but I can't reach remoteSiteB remoteSiteA.
Thus,.
SiteA <----- ipsec="" -----="">PIX1 SiteX <---------------->10.0.8.1 10.30.8.254
SiteB <----- ipsec="" -----="">PIX1 SiteX <---------------->10.0.8.1 10.138.34.21
SiteA can ping SiteX
SiteB can ping SiteX
SiteA cannot ping SiteB
SiteB cannot ping SiteA
If I do not show crypto isakmp ipsec his I see appropriate subnets:
Tag crypto map: CRYPTO-MAP, seq num: 4, local addr: 203.166.1.1
permit access-list ACLVPN-TO_SITEA ip 10.138.34.16 255.255.255.240 host 10.30.8.254
local ident (addr, mask, prot, port): (10.138.34.16/255.255.255.240/0/0)
Remote ident (addr, mask, prot, port): (10.30.8.254/255.255.255.255/0/0)
current_peer: 104.86.2.4
Tag crypto map: CRYPTO-MAP, seq num: 5, local addr: 203.166.1.1
access-list ACLVPN-TO_SITEB allowed host ip 10.30.8.254 10.138.34.16 255.255.255.240
local ident (addr, mask, prot, port): (10.30.8.254/255.255.255.255/0/0)
Remote ident (addr, mask, prot, port): (10.138.34.16/255.255.255.240/0/0)
current_peer: 216.178.200.200
Journal messages that seem to point to the problem...
April 18, 2013 13:27:35: % PIX-4-402116: IPSEC: received a package of ESP (SPI = 0xD51BB13A, sequence number = 0x21A) 104.86.2.4 (user = 104.86.2.4) at 203.166.1.1. Inside the package décapsulés does not match policy negotiated in the SA. The package indicates its destination as 10.138.34.21, its source as 10.30.8.254 and its Protocol 6. SA specifies its local proxy like 10.0.8.0/255.255.255.0/0/0 and his remote_proxy as 10.30.8.254/255.255.255.255/0/0
My question is really what I have to do something funky to allow traffic to pass between the two tunnels?
Hello
This could be much easier if we have seen the real configurations.
But here are some things to be confirmed in the configurations (some of them you mentioned above, but I still quote once again)
- Make sure that each firewall, you set the appropriate VPN L2L ACL
- Make sure that you have configured NAT0 on the central PIX "outside" interface for the Site A and Site B
- Make sure the Central PIX has "same-security-traffic permit intra-interface" configured. This will allow the Site traffic to enter the Central PIX 'outside' interface and head back on the same interface to Site B. And vice versa.
To view some actual configurations that may be required provided everything else is ok. (I assume that all devices are Cisco)
Central PIX
permit same-security-traffic intra-interface
A connection to the site
SITE-A-CRYPTOMAP of the 10.0.8.0 ip access list allow 255.255.255.0 host 10.30.8.254
SITE-A-CRYPTOMAP of the 10.138.34.16 ip access list allow 255.255.255.240 host 10.30.8.254
Site B connection
SITE-B-CRYPTOMAP of the 10.0.8.0 ip access list allow 255.255.255.0 10.138.34.16 255.255.255.240
SITE-B-CRYPTOMAP to the list of allowed access host ip 10.30.8.254 10.138.34.16 255.255.255.240
NAT0
access list for the INTERIOR-NAT0 allowed ip 10.0.8.0 255.255.255.0 host 10.30.8.254
access list for the INTERIOR-NAT0 allowed ip 10.0.8.0 255.255.255.0 10.138.34.16 255.255.255.240
NAT (inside) 0-list of access to the INTERIOR-NAT0
OUTSIDE-NAT0 allowed host ip 10.30.8.254 access list 10.138.34.16 255.255.255.240
OUTSIDE-NAT0 allowed ip 10.138.34.16 access list 255.255.255.240 host 10.30.8.254
NAT (outside) 0-list of access OUTSIDE-NAT0
Site has
CENTRAL-SITE-CRYPTOMAP to the list of allowed access host ip 10.30.8.254 10.0.8.0 255.255.255.0
CENTRAL-SITE-CRYPTOMAP to the list of allowed access host ip 10.30.8.254 10.138.34.16 255.255.255.240
the INTERIOR-NAT0 allowed host ip 10.30.8.254 access list 10.0.8.0 255.255.255.0
the INTERIOR-NAT0 allowed host ip 10.30.8.254 access list 10.138.34.16 255.255.255.240
NAT (inside) 0-list of access to the INTERIOR-NAT0
Site B---------------->----->---------------->----->
CENTRAL-SITE-CRYPTOMAP of the 10.138.34.16 ip access list allow 255.255.255.240 10.0.8.0 255.255.255.0
CENTRAL-SITE-CRYPTOMAP of the 10.138.34.16 ip access list allow 255.255.255.240 host 10.30.8.254
the INTERIOR-NAT0 allowed host ip 10.138.34.16 access list 255.255.255.240 10.0.8.0 255.255.255.0
the INTERIOR-NAT0 allowed host ip 10.138.34.16 access list 255.255.255.240 host 10.30.8.254
NAT (inside) 0-list of access to the INTERIOR-NAT0
Hope this helps
-Jouni
Tags: Cisco Security
Similar Questions
-
Continually, I get the error that cannot reach the server while trying to install SP1.
Win XP Pro reloading, get all updates
I reinstalled Windows XP Pro and need to update to SP1 to 3 as well as all security updates. (After download) installation, SP1, I continually get the error that cannot reach the server, visit Web of MS for a version that requires no web access if the problem persists. I can't find this version of SP1 that does not need to happen on the server from Ms. In addition, isn't there an easier way to get all updates when you perform a new installation instead of going one by one with all the updates?
If you have SP1A, then you can go straight to the installation of SP3. If you have SP1, then you need to install SP1A or SP2 before going to SP3. You can get the updates described in the following article:
"How to obtain the latest Windows XP service pack"
<>http://support.Microsoft.com/kb/322389/ >HTH,
JW -
internal hosts cannot access the internet w / L2L configured tunnel
The internal hosts behind the ASA cannot access the internet with a configured tunnel to L2L. The L2L tunnel is mounted and passing traffic correctly. However, the internal host cannot access the internet through the ASA. I think I have my NAT watered somewhere. I can't even a host statically mapped to the internet. It might be because I'm used to having a WAN IP to the external interface which differs by the CIDR block assigned by the ISP. In this case, it's all together, with the ASA outside interface occupying the first available address.
We have been assigned a CIDR range x.x.x.64/28. x.x.x.65 is my front door and my first usable est.68, by the PSI (I guess what they utilisent.66 et.67 for internal use). External interface of the ASA est.68 and I'm trying to get NAT others. I'm Polo all DHCP clients internal and have some static entries as well. Below is the relevant NAT config. Yet once, all traffic passes above the tunnel properly, but not from inside to outside. If more information is needed, please advise.
interface outside
IP address x.x.x.68 255.255.255.240
NAT-control
Global x.x.x.69 - x.x.x.77 2 (outdoor)
Global 1 x.x.x.78 (outside)
NAT (inside) 0 access-list sheep
NAT (inside) 1 10.10.10.0 255.255.255.0
public static x.x.x.69 (inside, outside) STATIC_NAT_EXAMPLE netmask 255.255.255.255
internal access-group interface inside
Route outside 0.0.0.0 0.0.0.0 x.x.x.65 1
internal to the 10.10.10.0 ip access list allow 255.255.255.0 any
! Remote LAN is 192.168.10.0/24
access-list sheep extended ip 10.10.10.0 allow 255.255.255.0 192.168.10.0 255.255.255.0
Can you post a "show sysopt run?
Try this command to enable proxy arp.
No outside sysopt noproxyarp
-
Windows 7 Advisor - cannot reach the server
I installed the Windows 7 advisor and both yesterday and today, he cannot reach the server updates - or before scanning - so it does not work for me. Any ideas? The server is down? I can access many other things!
It seems to run normally today.
-
Cannot create the destination file during the file extraction
I am trying to install a program from a zip compressed file, but Windows will not let me. When I try to run the files directly from the zip, it tells me that 'the destination file cannot be created." Alternatively, when I try to extract the individual files in the zipped folder, I get "error code 0x80004005".
I am running Windows 7 64 bit and I've never had this problem before. Any help would be appreciated!
You can try to register the .dll file and see if that makes a difference.
From an elevated command prompt try regsvr32 zipfldr.dll
You can also create another user to see if they have the same problem.
-
Win LR 6.4 import/Add - cannot change the destination of the catalogue
Using LR 6.4 and has several hard drives installed on my desktop computer. LR (.lrcat) catalogs are on the G drive - and have always been on the G drive. LR and Photoshop are also installed on drive G. My photos are in the folders on the F drive. My two catalogues are given due recognition in the preferences as being on drive G.
When I use the import - Add command, LR allows me to choose the source, but immediately chooses the destination as "My catalog" C drive. Although there is a small box next to the C drive, it is unusable and I can't find a way to change the destination. If I use other commands such as copy, I am able to change the destination. But whenever I load photos from a disc, I have for them to make a folder on the F drive and copy them from the disk to the new folder. Then, I want to add these pictures to the catalog that is currently active. I want to add them without moving... l
I did a search for .lrcat and all the catalogs were on drive G, as they are supposed to be. However, there is an entry on the C drive that is marked as a MS Word file and it is called: Lightroom assessment.docx. A paragraph seemed more likely guilty, but I don't know if I should change it and if so, what to change:
The application folder: G:\Program Adobe Lightroom
Library path: G:\Lightroom Backups\June2015\June2015.lrcat
\Adobe\Lightroom
Settings folder: C:\Users\mg\AppData\Roaming
Thanks for any help or suggestions. Is to make the process even very frustrating catalog help
No matter that one of your hard drives, the catalog is on. If this catalog is one that is active, then it is one which will contain references to imported pictures. When you use the add in the import dialog box images are added to the catalogue of their current location. You cannot specify a different destination when you use this option. When you use the copy option, then you are able to specify a destination in the right column of the import dialog box. You must choose the appropriate drive and the main folder in the folder tree that appears. Then, specify the name of the subfolder in the highlighted area:
You talked about change the destination of the catalog. It was a poor choice of words or you don't understand how the catalog works. The catalogue is available in one place. Normally it does not move anywhere unless you choose to do it manually. You can control the destination of your imported images, and Lightroom will import to the destination on any hard drive. But they are managed using the catalogue that remains in one place.
-
Please help, my iphone cannot reach the cellular network
Please help me, my phone can not reach the cellular network since this morning (5 h). I have already contacted the network support and they said that there is nothing wrong with the network. the State on the screen 'search'... Please help me... I can't use my phone... Help, please
You can try to reset your device. It will not destroy your data.
Press and hold the sleep/wake button
Press and hold the Home button
Press and hold both buttons until the display turns off and on again with the Apple logo on the subject.
Another way is to go to settings - general - reset - Reset all settings
-
Outlook 2007 crashes. Problem report generates a message to install the office update, but I can't reach the Web site update as an automatic update in place. How can I find the necessary update?
Hello
Which is exactly the problem that you are facing with update?
I suggest you follow the link and check.
Install Windows updates
http://Windows.Microsoft.com/en-us/Windows-Vista/install-Windows-updates
I also suggest that you send your request from the link and check.
http://www.Microsoft.com/Office/Community/en-us/FlyoutOverview.mspx
-
Windows Installer cannot find the Destination component
After wash starts the Windows Installer window if poster once finished top of desktop. The process takes about a minute. Windows Installer message is, "Preparation for installation." Then, the Destination component appears with message "Please wait while Windows configures the destination component", and shows the progress bar. Then, the Destination component window appears with the message, "an installation package to the Destination of the product component is not found. Try the installation again using a valid copy of the installation package, "Destination. msi´."
This package is not in my computer. This happens everytime I turn on the computer. The whole process is very long. How can I fix it so that the message?
Thank you for your help.
Hi lmcrae,
Put your computer in a clean boot configuration to determine which product is responsible for this. Clean boot is a way convenient, safer to change the options for startup in the registry; You can turn individual items or disable freely to try various combinations up to that narrow you the problem. Once you find out, post details about the same so that we can take additional measures.
Please see this article for detailed information on how to do it.
How to troubleshoot a problem by performing a clean boot in Windows Vista or in Windows 7
Note: Ensure that you switch your computer to normal startup mode after completing the troubleshooting steps. Steps are available in the article above.
Kind regards
Shinmila H - Microsoft Support
Visit our Microsoft answers feedback Forum and let us know what you think.
-
AppAssure BMR cannot find the Destination disk.
I am preforming a bare metal restore material disimillar and Appassure cannot find the drive on the target computer.
Restore dell Poweredge R430 13g. The discs are in a controlled by a H330 PERC RAID 1.
Is there something I am missing, usually displays the disc without any problems?
Thanks for the support!
Inject you the Perc controller drivers in the boot cd when it was created? If this isn't the case, then this is probably the issue. He can't access the storage controller so he can't see the disks.
-
Cannot reach the controls on panels
I just started using 2 screens - Macbook Pro and Asus. I use PS CC and I moved back points between the two, but then now I am not able to move. When I tried to drag the panels to my other screen they moved higher up on the screen but no more switch to another view. In the meantime, the panels are pushed way to the top and I can't reach the top where controls are to resize or move. I tried to turn and then turn it on again but still the same. How can I get these? Thank you!
I am a Windows user and not familiar with how double Mac displays, but it sounds a bit like your system is not configured for the position of the poster. I can choose a screen and drag it to the position, so when I move the slider to the right, it moves the screen 2 on three screen. If my screens have been set up in this way, but the physical positions was different, then it would be confused because the cursor does not seem to obey the mouse.
So first of all, turn off your second screen so that you can see all your dashboards and reset your workspace.
Then turn on the second screen again after checking that the physical and operating system to reach his position.
Organize your panels, and then save it as a new workspace.
Don't forget that you can save custom keyboard shortcuts and personalized workspaces customized toolbar configurations. This is a very cool and useful feature.
I hope this has helped, but if I misunderstood your question, please tell a little more about the problem.
-
55XD8505 it recharges continuously--cannot reach the factory reset
Hello
My 55XD8505 2016 is having issues. When you enter the home menu is extremely slow and leave then it is only a matter of minutes before the device reboots. If I just start the TV and stay away from the home menu, I can watch TV.
Now, my intention is to restore the factory settings to try to get the system going again. Normally a reset of the Android system can be done either
(1) via the settings menu
or
(2) by switch on the unit with the volume on/off button + start button / stop key and use recovery menu.
I can't do 1) since any speed, I navigate the menu of settings, the TV restarts before I can fill a selection of factory settings.
I can't do 2) either - at least all the possible combinations of Sony, I found does not apply for my TV
I'm all of ideas - is it possible to factory reset via the USB port (perhaps using ADB)?
A nailed!
I discovered that you can use 'top' under adb shell. I did the following:
(1) connect adb
(2) adb shell
(3) top m 5 (this lists the first 5 cpu by using the applications)
After running high and enter the main menu, I saw the CPU use climbing, and the app in the foreground was always/system/bin/mtkbt, which I figured well be related to Bluetooth. So, after a few attempts of menu navigation speed, I managed to enter the bluetooth menu and disable bluetooth before it restarts.
Success! Now I can navigate the menu of home once again, I have the tried clear the data cache / anything related to bluetooth from the menu applications and then reactivate bluetooth, but alas the problem returns. So now I'm running the TV without bluetooth. I could try to factory reset the TV tomorrow to see if it helps - at least now I can actually reach the factory reset menu.
UPDATE:
Now after you turn off the bluetooth, I could navigate the menu to factory reset. After doing a reset complete, it seems that everything is back to normal - even with bluetooth enabled. Problem solved... Thanks adb.
-
Client cannot get the external IP of DHCP address through WiM
WISN 5.2.178.0
6509 12.2 (33) SXH2a
WISN is in place, 1231 & 1131 joined APs, radio stations upwards, the customer associated but not an IP address.
Virtual interface with vlan # & IP on the destination VLAN.
WLAN with same vlan # as above.
I tried Open, PSK, WPA. Client cannot obtain an IP address.
What did I miss?
You have the virtual address set to 1.1.1.1?
Also, you have set up the address of the DHCP server on your interfaces VLAN? This is important because the controller basically uses an ip helper address to properly forward DHCP requests.
If you have these configured, try to use the internal DHCP server to test. The web GUI, access controller-> the DHCP server in-house. Configure a DHCP scope and activate it (don't worry, it is only used for wireless clients. It does not meet the DHCP requests on your network).
Now, go back to the controller-> Interfaces and configure the DHCP server to the management interface of the controller. See if your customers are able to get the addresses of the internal scope.
-
Adobe Pro XI - use the operating system to Windows 7 Pro
When a PDF document is open in Windows Explorer, and pages are added, deleted, ratings, all types of changes, he cannot be saved until the Windows Explorer is completely closed. If you try to save the document, you receive the error message next - "the document could not be saved. The file may be read-only, or another user may have his opening. Please save the document under a different name or in a different folder. «I have confirmed the document is not read only, it is not open by another user, and this is not open many times.» Once completely, you close Windows Explorer and try to save the document, it saves without problem.
Are there settings in Adobe Pro XI or Windows that allows you to save documents without closing Windows Explorer first?
Thanks for any help you can provide. This error is a frustration because I open all my documents via Windows Explorer.
Turn off the preview in Windows Explorer.
-
Cannot reach the remote device.
Hello I am a strange problem and would be grateful to have any insight as to why this is happening.
The ASA is set up for two remote devices as follows
object obj-SV4(1:1) network
Home 172.16.2.24object obj-SV5(1:1) network
Home 172.16.2.25object obj-SV4(1:1) network
NAT static xxx.xxx.xxx.183 (indoor, outdoor)object obj-SV5(1:1) network
NAT static xxx.xxx.xxx.184 (indoor, outdoor)ASA # ping 172.16.2.24
Type to abort escape sequence.
Send 5, echoes ICMP 100 bytes to 172.16.2.24, wait time is 2 seconds:
!!!!!
Success rate is 100 per cent (5/5), round-trip min/avg/max = 18/10/20 ms
ASA # ping 172.16.2.25
Type to abort escape sequence.
Send 5, echoes ICMP 100 bytes to 172.16.2.25, wait time is 2 seconds:
?????
Success rate is 0% (0/5)When I trace the two devices to:
trace 172.16.2.25
Type to abort escape sequence.
The route to 172.16.2.251 172.28.213.202 0 ms 0 ms 0 ms
2 172.28.209.109 20 ms 20 ms 10 ms
3 * * *
4 * * *trace 172.16.2.24
Type to abort escape sequence.
The route to 172.16.2.241 172.28.213.202 0 ms 0 ms 0 ms
2 172.28.209.109 10 ms 20 ms 20 ms
3 172.28.209.110 20 ms 10 ms, 20 ms
4 172.16.2.24 20 ms 20 ms 10 msWhen I'm on the peripherique.109 he has the road to the entire subnet and I can reach le.24 et.25 both of him.
RTR #sh ip short int | Inclure.109
172.28.209.109 GigabitEthernet0/1.131 YES manual up upPing the server Samba 172.16.2.24
Type to abort escape sequence.
Send 5, echoes ICMP 100 bytes to 172.16.2.24, wait time is 2 seconds:
!!!!!
Success rate is 100 per cent (5/5), round-trip min/avg/max = 1/1/4 ms
Ping the server Samba 172.16.2.25Type to abort escape sequence.
Send 5, echoes ICMP 100 bytes to 172.16.2.25, wait time is 2 seconds:
!!!!!
Success rate is 100 per cent (5/5), round-trip min/avg/max = 1/1/4 msthe road is
Server IP route vrf 172.16.2.0 255.255.255.0 NAMESERVERS 172.28.209.110
Any advise will be appreciated.
Hello
What is the device that owns the IP 172.28.209.110? She or one of the other devices on the way to the ASA there any type of ACL or anything else that might block traffic?
You see no link on the SAA (or all newspapers gathered the SAA) host 172.16.2.25?
Is there some ports TCP is listening on the server that should respond to connection attempts? You could try TCP Ping of the SAA for ports
TCP ping 172.16.2.25
You can also give a "source" address in the command above, if you need. When you run the Software ASA below 8.4 (1) then the custom above 'ping tcp' to be supported.
-Jouni
Maybe you are looking for
-
Whenever I type a keyword in the search box on Firefox immediately opens a new tab for a search engine called abuchack and next to the search box, it says it's a google program.
-
If DIADEM will bother to follow the cursor on all pages in a journal, I think that there is a NON-SCRIPT way to view the values of Y for all. My graphics are aligned to the x-axis (couple), 4 - poster (1 for each rpm, HP, power and efficiency), and 2
-
Best way to reduce a large table 2D
Looking for best practices LabView on it. I have a 5000 x 5000 U16s 2D table and I would like to remove/delete lines even and then all of the same columns. I enclose a drawing of what I currently use but looks about 15 seconds to accomplish. Any bett
-
Keep getting the pop up that WebKit2WebProcess.exe has stopped working
I just tried to email urgent and important 8 times and he always tells me that this stupid and previously unknown program has stopped working! I followed the advice of aid, but there is no option to get rid of it or turn it off! I'm going to stop you
-
Print the addresses of group e-mail in Windows Mail
How can I print the e-mail addresses for a contact group in Windows Mail. I selected the group name of list of contacts and right-click for the print command, but only get names in a list. Can't see how to get their addresses to print also. Thank you