Cisco VPN Site to Site with a static and dynamic does not

Hello

I have ASA 5510 in Headquarters with static, IP and ASA 5505 in the remote site behind ADSL router trying to establish VPN, but its failure in phase 1

Config of the headquarters

interface Ethernet0/0

Description link to router LeaseLine

nameif outside

security-level 0

IP x.x.x.x 255.255.255.248

!

interface Ethernet0/1

Description link to LAN internal

nameif inside

security-level 100

IP 172.17.1.15 255.255.255.0

access extensive list ip 172.17.1.0 inside_nat0_outbound_1 allow 255.255.255.0 172.20.1.0 255.255.255.0

access extensive list ip 172.17.1.0 inside_nat0_outbound_1 allow 255.255.255.0 172.19.1.0 255.255.255.0

access extensive list ip 172.17.1.0 vpn_to_remote allow 255.255.255.0 172.19.1.0 255.255.255.0

extended VPN ip 172.17.1.0 access list allow 255.255.255.0 172.20.1.0 255.255.255.0

Global 1 interface (outside)

NAT (inside) 0-list of access inside_nat0_outbound_1

NAT (inside) 1 0.0.0.0 0.0.0.0

Route outside 0.0.0.0 0.0.0.0 x.x.x.x 1

Crypto ipsec transform-set esp-aes-256-md5 esp-aes-256 esp-md5-hmac

Crypto ipsec transform-set ESP-AES-256-SHA 256 - aes - esp esp-sha-hmac

correspondence address 1 crypto dynamic-map cisco VPN

Crypto dynamic-map cisco 1 set of transformation-ESP-AES-256-SHA

card crypto outside_map 10 correspondence address vpn_to_remote

card crypto outside_map 10 set pfs

card crypto outside_map 10 peers set y.y.y.y

card crypto outside_map 10 transform-set esp-aes-256-md5

outside_map crypto 10 card value reverse-road

dynamic outside_map 30-isakmp ipsec crypto map Cisco

outside_map interface card crypto outside

crypto isakmp identity address

crypto ISAKMP allow outside

crypto ISAKMP policy 10

preshared authentication

aes-256 encryption

md5 hash

Group 5

life 86400

crypto ISAKMP policy 20

preshared authentication

aes encryption

md5 hash

Group 2

life 86400

crypto ISAKMP policy 30

preshared authentication

aes-256 encryption

sha hash

Group 2

life 86400

Crypto isakmp nat-traversal 20

tunnel-group y.y.y.y type ipsec-l2l

tunnel-group ipsec-attributes y.y.y.y

pre-shared-key *.

tunnel-group parkplace type ipsec-l2l

tunnel-group ipsec-attributes parkplace

pre-shared-key *.

The Remote Site configuration

interface Vlan1

nameif inside

security-level 100

address 172.20.1.1 IP 255.255.255.0

!

interface Vlan2

nameif outside

security-level 0

IP 192.168.1.2 255.255.255.0

!

interface Ethernet0/0

switchport access vlan 2

!

interface Ethernet0/1

ICMP list extended access permit icmp any one

access-list SHEEP extended ip 172.20.1.0 allow 255.255.255.0 172.17.1.0 255.255.255.0

extended VPN 172.20.1.0 ip access list allow 255.255.255.0 172.17.1.0 255.255.255.0

Global 1 interface (outside)

NAT (inside) 0 access-list SHEEP

NAT (inside) 1 0.0.0.0 0.0.0.0 outdoors

Access-group ICMP in interface outside

Route outside 0.0.0.0 0.0.0.0 192.168.1.1 1

Crypto ipsec transform-set ESP-AES-256-SHA 256 - aes - esp esp-sha-hmac

crypto map outside_map 1 is the VPN address

peer set card crypto outside_map 1 83.111.252.242

card crypto outside_map 1 set of transformation-ESP-AES-256-SHA

outside_map interface card crypto outside

crypto ISAKMP allow outside

crypto ISAKMP policy 10

preshared authentication

aes-256 encryption

sha hash

Group 2

life 86400

Crypto isakmp nat-traversal 20

tunnel-group fairmount type ipsec-l2l

tunnel-group fairmount ipsec-attributes

pre-shared-key *.

Best regards / Asfar

Hello

Have you tried to replace the names of 'tunnel-group' entry with Ip address on both ends... ?

Thank you

MS

Tags: Cisco Security

Similar Questions

  • I try to enter the serial number to register my software, but the label outside of the box, he's starting with the letters and it does not accept the letters... . Only numbers

    I try to enter the serial number to register my software, but the label outside of the box, he's starting with the letters and it does not accept the letters... . Only numbers

    Serial numbers contain no letters, so maybe it's your redemption code, for use on adobe.com to get your serial number.

    Here are a few links to look for more information

    https://helpx.Adobe.com/x-productkb/global/redemption-code-help.html#productboxorprepaidca rd

    Quickly find your serial number

  • I can't refine edge to work in 2014 of CC.  I select the mask, do the steps required to refine the mask and get a negative icon, a circle with a slash, and it does not work.  I used refine edge before and it has always worked.  This happened on fo

    I can't refine edge to work in 2014 of CC.  I select the mask, do the steps required to refine the mask and get a negative icon, a circle with a slash, and it does not work.  I used refine edge before and it has always worked.  This has happened for a while.  Very frustrating!

    Adobe Creative Cloud to edge CC>

  • Problem with Windows Fax and Scan does not connect to the Internal Modem

    Just got a new Acer Aspire 5542-5416 computer laptop with Windows 7 64 bit Home Premium, 4 GB of Ram and a 320 GB hard drive. It has a 56 k modem integrated fax of like the old days, but I can't make it work. The laptop did not come with the Windows CD.

    If I open the program Windows Fax and Scan, it is not able to connect to the modem. Basically, if I click on tools > fax accounts > Add..., I get a box with 2 choices: to connect to a fax modem or connect to a fax on my network server. When I want to connect a fax modem I get a message that says: an error has occurred. Please, try the operation again later or contact your administrator. It allows me to do this then just clock OK and them I'm right where I started.

    While in Windows Fax and Scan, if I click on tools > fax settings... nothing happens. No menu settings or anything ever appears. Quite simply, the program does nothing. If I try tools > Fax Status Monitor... I get a box that says entrance exam status, ready to receive a fax. It has a blue progress bar as something takes over, but it gets about 1/100 to and never goes further or ends. There is no box, but there are 3 buttons: view details, answer call or cancel. If I hit details, I get an empty list. If I click on answer call I get an error that says that the fax service is not available.

    If I try tools > Options, general tab has only a single option box is checked: play a sound when come it to new messages. If I try to print a Word or PDF file to a fax using Fax in the printer list, I get the same box with 2 choices: to connect to a fax modem or connect to a fax on my network server, but I get the same error message: an error has occurred. Please, try the operation again later or contact your administrator.

    I've searched the Internet high and low for a solution but no luck. There is a lot of discussion about this problem, but none of the solutions work for me. If I go to Device Manager, the modem is working properly and if I click on the Modem query on the Diagnostics tab, it seems to be able to communicate with the modem very well. I tried to roll back the driver and updated again and still no luck, same problem. If I go to HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fax\Accounts in the registry, there is no subkeys under the folder accounts I can delete.

    Has anyone else had a similar problem? Is there any solution for this? I did a Windows Update last night and has not yet solve it. Thank you.

    Sorry about that.

    Here is the link:

    http://social.msdn.Microsoft.com/forums/en-us/windowscompatibility/thread/c75ae899-D05B-411D-a7f2-00fdd33b8589/

  • F2 and entry does not on certain pages of the site, except if the field selected

    F2 and entry does not not to go backward or forward on certain pages of the site unless field selected. It is on an intranet site after reload PC with Windows XP, other old Windows XP PC work.

    Including the Firefox Firefox 10.0, or 11.0 9.0 upgrade fixed this problem with the program code of the intranet for keys F2 and Enter to forward and back a page in the application of the intranet site.

  • Touchpad and mouse does not scroll on AOL or Fox News site

    Original title: mouse and keyboard does not not on the first page of web sites.

    \When opening site Internet AOL or Fox News, my touchpad and mouse does not scroll.  In addition, the normal ads that appear on AOL and the Fox new sites do not appear.  Touchpad and mouse work fine on the facebook page.  I can't click and close AOL and Fox News.  I run a system check total notron and restore systems affecting a couple of days, when everything worked well.  Any ideas to solve the problem?

    Hello

    1. what web browser do you use?

    2. What is the brand and model of the computer?

    3. What is the brand and model of the mouse?

    4. you receive an error message?

    5. have you made changes on the computer before this problem?

    Step 1:

    If you use Internet Explorer, you can view the following link.

    Why a few blank pages or incorrectly displayed in Internet Explorer?

    http://Windows.Microsoft.com/en-us/Windows7/webpages-look-incorrect-in-Internet-Explorer

    Step 2:

    You can see the following link.

    Mouse, touchpad and keyboard with Windows problems

    http://Windows.Microsoft.com/en-us/Windows/help/Mouse-touchpad-and-keyboard-problems-in-Windows?T1=tab04

    Please provide us with more information to help you further.

  • Adobe Muse Site in preview mode before but does not work when published

    Hello

    I have an Adobe Muse site that works perfectly when it is in preview with any browser mode, but does not at all appear when it is published on BusinessCatalyst.

    Someone has to meet this problem before?

    Here is my test link: http://wss001.businesscatalyst.com/

    Hey guys,.

    Adobe support helped me to find the problem.  Content tags we put on the block of text doesn't jive with catalyst for business.  Remove the content tags contributed to publish the site.

  • Silver payment plan "Photograph" has been removed from the account, but creative cloud changes were on the site for the products and also do not appear on the site as my payment was perfect (but money has been withdrawn) sorry for my English.

    Payment plan 'picture '.

    Money was withdrawn from the account, but creative cloud changes were products on the site and also does not appear on the site as my payment was perfect (but money was withdrawn)

    Sorry for my English.

    Hi Vladislav % 20parfyonov,

    I saw the Adobe ID (email address) you used to post here and can see that you have a plan of creative photography of cloud are recorded.

    Please make sure you use the same Adobe ID (email address) that you used to purchase the subscription to connect to the Web site.

    Adobe trial and purchased applications are the same, you can download the application once installed, creative cloud it invites you to connect, use the following link: Download Adobe Creative Cloud apps | Adobe Creative Cloud free trial

    Once logged in go to APP and tab install CC 2015 Photoshop and Lightroom CC 2015 from there.

    * NOTE: Please make sure that your firewall of your computer or security software firewall does not block Adobe, if you are not sure of it then just turn off the firewall for awhile disconnect you and you connect on the creative application of cloud and check.

    Let us know if that helps.

  • I am not able to adjust the height of a page on my site. I try to move the blue mark on the left side and it does not move. What should I do? Thank you

    I am not able to adjust the height of a page on my site. I try to move the blue mark on the left side and it does not move. What should I do? Thank you

    Hello

    could you please try to find an empty project as rectangle/text box, especially at the lower end of the page. Use Edit-> "Select All" to select all elements on the page, it will be easier to locate.

    Let me know if it works

  • Difference between static and dynamic encryption card

    Anyone tell me the difference between static and dynamic encryption card?

    Hi Rodrigo,

    Public static crypto map - identifies by the peers and traffic to encrypt explicitly. Generally used to host some tunnels with different profiles and characteristics (different partners, sites, location)

    So, when you have the information of the two peers than what policies we're going to use, what is the IP on both devices we normally use static VPN.

    Crypto dynamic map - is one of the ways to accommodate peer sharing the same characteristics (for example, several offices of branches share the same configuration) or peers with dynamic IP addressing (DHCP, etc.)

    For more information, please visit:

    https://supportforums.Cisco.com/document/12013476/crypto-map-based-IPSec...

    Kind regards

    Aditya

    Please evaluate the useful messages and mark the correct answers.

  • static and dynamic reports

    Hello

    I'm new to HFR. Can someone tell me what is static and dynamic statement and when we go to static and when we go for dynamic with scenarios in real time?

    Thanks in advance

    Static report is usually fixed, so that the reports do not change when the time and hierarchies are updated. For example, a static report can be useful for regulatory deposits etc. You do not want to change statutory reports according to the when they were run ;-)

    Dynamic reports has several levels:

    -Dynamics updated due to changes in current month/quarter/year;

    -Dynamic reports that automatically updated based on changes made to the hierarchy: contour moves, new members, etc.

    In an ideal world, you have to build relationships are dynamic as possible, that you do not have what to have to change them every month, quarter, year, based on the changes of the period.
    Or do you need to update when managers change their minds about what needs to be told (less maintenance and future audit)

    Building reports are dynamic as possible has some limitations, however, in this by establishing the report, it would be not as fast to run (you may have several rows/columns more) to make the reports 'dynamic '.

    HOEP this helps, Iain

  • Tiara dac combined with the NI PCIe-6259 does not send the data

    Hello

    I have a card OR PCIe-6259 & DIAdem 11.2.0 (version 2010) on a windows 7 PC.

    Inputs outputs & analog analog + digital are configured in MAX 9.8.0f0. (Global virtual channels)

    When I run a dac, entered analog works perfectly.

    Outputs analog and digital does not work. Only one of the four analog outputs give the value that has been send.

    In the past, I had the same problems with this version of DIAdem in combination with a third party USB card, but this has been resolved by the new firmware & software drivers.

    Someone who has had similar problems?

    Thank you.

    After trying many things, I finally found the solution.

    In the output ==> pilot ==> options pilot "weighting the digital bus" must be verified.

  • On Vista x 64 German language pack fails with code 2 - proposed patch does not install

    Hello!

    I tried to install on Vista Ultimate x 64 German language pack, but it failed with error code 2. The KB942903 hotfix for x 64 (also tried x 86) does not install with the message "this update does not apply to your system.

    I rebooted several times and tried to erase the directory SoftwareDistribution\downloads, no change.

    The log file is not really favourable, weird things only I see is:

    [...]
    KB94290303:04:16:578: CBS: language pack had error 800f081e. It has been deleted!
    [...]
    03:05:17:152: EC: CbsClient::Error(error=80092004,message="")
    [...]
    03:05:17:167: CBS: language pack had error 80092004. It has been deleted!

    Can someone help me out here?

    Thank you in advance!

    Stef.

    Hi StSz,

    1. What is the service pack installed on the computer?

    This problem occurs if a previous Windows Update process did not cause the computer to be in a corrupted state. This prevents the installation of any language pack.

    I suggest that you reset the Windows Update components and you try to install the pack of language, to check if it works.

    How to reset the Windows Update components?

    http://support.Microsoft.com/kb/971058

    See also the Microsoft article and try the steps mentioned below.

    Full Windows Vista Edition language pack version information
    http://support.Microsoft.com/kb/925471

    I hope this helps!

    Halima S - Microsoft technical support.

    Visit our Microsoft answers feedback Forum and let us know what you think.

  • I have a Dell Inspiron with windows XP and I can not start. I have the windows disc but do not know how to clean and reinstall. Please help me

    I have a Dell Inspiron with windows XP and I can not start.  I have the windows disc but do not know how to clean and reinstall.   Please help me

    You can repair XP or try the following:
    http://support.Microsoft.com/kb/917964
    http://support.Microsoft.com/kb/307545

    TO

    Re - install http://support.microsoft.com/kb/978788

  • Microsoft Flight Simulator 2004 installation with the 4th vista disc does not work. What should I do?

    Microsoft Flight Simulator 2004 installation with the 4th vista disc does not work.  What should I do?

    Hello

    You get no matter what error code or error message?

    There seems to be a problem with the file missing in the rear disc system. I suggest you to refer to the following Microsoft article and check if it helps.

    Flight Simulator 2004: known video issues: http://support.microsoft.com/kb/823628

    If the steps in the Microsoft article mentioned above do not help, then it would be best to ask your question in the Microsoft Game support forum.

    Microsoft Flight Simulator Games Forum: http://www.fsinsider.com/

    Or contact support for Microsoft Flight Simulator game: http://www.microsoft.com/Products/Games/FSInsider/tips/Pages/default.aspx

    Hope the information is useful.

Maybe you are looking for

  • Questions of BootCamp

    Hello! I have a mid-2012 MBA running the latest OS. I'm trying BootCamp a x 64 Windows 7 .iso that I picked up on an old hard drive. I copied it on my MBA and whenever I try to get BootCamp running, it installs the .iso image file, with a beautiful r

  • Update has not installed while the computer shuts

    When shutting down my computer is trying to install an update, but seems to stop and the computer never stops. I waited eight hours before restart my computer. What should I do to install this update and resolve this situation?

  • string of imput was not in a correct format

    What does that mean? I tried to use Microsoft Fix it and he jumped upwards. Thank you

  • internal/external speakers, all the controls reveal all workers

    internal, external, mike, headphones do not work.  After all recommended controls, unistall causing w/restart install: same problem.  also used fix - it several times: same problem. Help! Joe

  • Manipulate a string with 'left', 'mid' or 'right' functions

    I'm struggling to apply the principle (from the Qstring reference on the dev site), in my QML using functions of middle and right to left, in order to manipulate a string... QString x = "Pineapple"; QString y = x.left(4); // y == "Pine" I have includ