Darkness of 8.4 (1) vpn L2L filter ASA when you specify the Protocol and port

Hi all - I've spent many hours trying to diagnose this and have read several discussions and the Cisco docs unsuccessfully...

Situation: two sites running Cisco ASA 5520 on 8.4 (1) with L2L IPsec on the public internet between each of them. The configuration of IPsec and associated routing works as it should and we are able to pass traffic between networks private behind each device as expected. The problem occurs when you try to block sessions using a vpn-filter group policy configuration.

Each site has 3 private subnets that are able to communicate correctly without the vpn-filter configuration. We want to restrict access to specific protocols, hosts, and ports between each network.

SITE A: 10.10.0.0/18, 10.10.64.0/18, 10.10.128.0/18

SITE B: 10.20.0.0/18, 10.20.64.0/18, 10.20.128.0/18

When we apply a filter-vpn configuration which restricted access only two guests, as follows...

SITE A: vpn_acl_x_x_x_x list extended access permit ip host 10.20.0.1 host 10.10.0.1

SITE b: the ip host 10.10.0.1 allowed extended access list vpn_acl_x_x_x_x host 10.20.0.1

... the configuration works correctly. However, when we try to lock the configuration more far and specify the protocols and ports, as follows...

SITE A: vpn_acl_x_x_x_x list extended access permit tcp host 10.20.0.1 host 10.10.0.1 eq 22

SITE b: vpn_acl_x_x_x_x to the list of access permit tcp host 10.10.0.1 host 10.20.0.1 eq 22

... and then try to establish a SSH connection between 10.10.0.1 and 10.20.0.1 or vice versa, the package is stopped on the side of the SOURCE. ..

Mar 22 11:58:01 x.x.x.x 22 March 2011 14:34:56: % ASA-4-106103: vpn_acl_x_x_x_x of the access list refused tcp to the user "" inside-data/10.10.0.1(59112)-> outside-iptrans/10.20.0.1(22) hit - cnt 1 first success [0xd8d1c1b4, 0 x 0]

I would really appreciate it if someone could shed some light on what is wrong with this Setup.

SOLUTION

The ACE must be implemented on the source and the end of the tunnel destination to facilitate this configuration.

EXAMPLE 1: allow SSH two-way communication between hosts on each network (SITE A can connect to SITE B, SITE B can connect to SITE A)...

SITE A:

access-list vpn_acl_x_x_x_x extended permit tcp host 10.20.0.1 host 10.10.0.1 eq 22

access-list vpn_acl_x_x_x_x extended permit tcp host 10.20.0.1 eq 22 host 10.10.0.1

SITE B:

access-list vpn_acl_x_x_x_x extended permit tcp host 10.10.0.1 host 10.20.0.1 eq 22

access-list vpn_acl_x_x_x_x extended permit tcp host 10.10.0.1 eq 22 host 10.20.0.1

EXAMPLE 2: allow communication one-way SSH between hosts on each network (SITE A can connect to SITE B, SITE B is unable to connect to SITE A)...

SITE A:

access-list vpn_acl_x_x_x_x extended permit tcp host 10.20.0.1 eq 22 host 10.10.0.1

SITE B:

access-list vpn_acl_x_x_x_x extended permit tcp host 10.10.0.1 host 10.20.0.1 eq 22

Very good and thank you for this post. Please kindly marks the message as answered while others may learn from your post. I think that you have started a very good discussion on vpn-filter for tunnel L2L.

Tags: Cisco Security

Similar Questions

  • ODA IP ASA when you browse the web via remote access vpn

    Hi all

    I was wondering if it is possible to configure an ASA5510 in a way to allow users remote access VPN use external IP of the ASA when browsing the web. So what I'm looking for is a solution to hide my IP address and use the IP address of the ASA, when browsing.

    The firmware version of the ASA is 9.1 (6)

    Thanks in advance

    Hello

    What you want to achieve is calles u-turn.

    You must enable the feature allowed same-security-traffic intra-interface

    For the configuration of the asa, here's the Cisco documentation (I don't copy paste on the post):

    http://www.Cisco.com/c/en/us/support/docs/security/ASA-5500-x-series-NEX...

    Thank you

    PS: Please do not forget to rate and score as good response if this solves your problem

  • How to turn off inprivate filter? When I go to security and turn it off I'm ok until I quit internet Explorer

    Original title: filter inprivate

    How to turn off inprivate filter? When I go to security and turn it off I'm ok until I quit internet Explorer

    What you say has not added to the top...

    InPrivate Browsing must be turned on by you.

    At the time wherever you go out navigation, Inprivate browsing is also disabled.

    Read the last sentence of this screenshot...

    Maybe I misunderstood what you are saying?

  • I get 'no more virtual tiles can be allocated' when you try the filter Shake reduction... anyone know what causes this error?

    I get 'no more virtual tiles can be allocated' when you try the filter Shake reduction... anyone know what causes this error? I always get on each blurry picture, I am trying to do a little better.

    This may result from the way in which the scratch disk is set up. Yo have a separate drive for the scratch?

  • With the help of Photoshop CC on my MacBook Pro (bought a few months ago)... The question I have is that under the filter options, when you select made... There is no option use lighting effects... any suggestions

    With the help of Photoshop CC on my MacBook Pro (bought a few months ago)... The question I have is that under the filter options, when you select made... There is no option use lighting effects... any suggestions?

    Hello

    Please make sure that you work in 8 bits/channel and RGB mode. (Under Image > Mode > Select RGB and 8-bit per channel) lightning effects only works in this mode.

    Also in preferences > Performance > "Use Graphics Processor" must be checked.

    ~ Assani

  • Can't view the YouTube video because there is an active filter. It happens on the job and home networks and only on Firefox (15.0.1).

    After update 15.0.1 Firefox and Adobe Flash Player to 11.4, I was unable to view the media from YouTube. I was given a message: "this video is not available with the filter of education allowed.» To view this video, site network administrator will have to add to a playlist. I work for a school district and use my laptop at work so I thought that I got this message because YouTube is blocked on this network. But when I got home, I got the same message on my home network with YouTube videos. I have reset Firefox and he took care of the issue until I'm at work, and the problem happened again with the same message everywhere... I tried to post the same videos on another browser (Safari) and it works beautifully. I'm afraid that if I reset Firefox even once, I'm having the same problem.

    It is possible that YouTube set a cookie to filter which can still be seen when you connect at home. To clear cookies for youtube.com, you can use one of these:

    (1) 'dialog show Cookies' tab in Preferences/Privacy:

    Firefox > Preferences > privacy > 'view the Cookies '.

    Type yout in the search box at the top to filter the list and remove each cookie individually.

    (2) "view Cookies dialog box" in the Page Info/Security tab:

    While displaying a page on the site-

    Tools > Page Info > Security > 'view the Cookies '.

    -remove each cookie individually.

    Then, try to reload the page and see if Youtube behaves differently.

  • With WAN Miniport problem when you configure the VPN in Windows 7 server

    I tried to make my computer a VPN server by establishing a "new incoming connection" under connections in the network and sharing Center. Originally, she she started but showed no WAN Miniport connections. I could not connect to this VPN with my other computer.

    What I've done so far:

    • I have 'upgrade' all WAN Miniports in 'MAC Bridge miniport driver' Device Manager (since I couldn't uninstall them as they were) and then uninstall all WAN miniports. I restarted my computer and then I tried the device drivers to install automatically, but only a few installed successfully.
    • Then, I downloaded the latest WDK (8.1) and tried to reinstall all Miniports WAN via devcon.exe with the command "devcon.exe install c:\windows\inf\netrasa.inf MS_PptpMiniport. He says that the node has been created, but it could not install the drivers. I restarted my computer, but some of these minis ports appeared as 'Unknown' in Device Manager, while others appeared with their names but with numbers attached because I tried a few times, Ex: "Miniport network EXTENDED (IP) #3".»

    from my understanding, I need at least WAN Miniport pptp to work for VPN to work. I don't know what to do at this point. Any help is greatly appreciated. Thanks in advance.

    Gateway DX4822-01 desktop PC

    Windows 7 64-bit, SP1

    Hello Jdrumr,

    Welcome to the Microsoft Community Forum.

    The question you posted would be better suited to the TechNet community.

    Please visit the link below to find a community that will support what ask you:

    Microsoft TechNet

    http://social.technet.Microsoft.com/forums/Windows/en-us/home?category=w7itpro

    Hope the helps of information. Let us know if you need help with Windows related issues. We will be happy to help you.

    Thank you

  • PSE close unexpectedly when you use the filter

    I use PSE 13 on a Mac under 10.10.3. When I try to use the filter > deformation, the program stops. What should I do to fix this?

    Before playing with the cleanup tool, delete all the prefs. (The button does that the plist).

    Go in your username > library > Preferences and delete:

    com.adobe.PhotoshopElements.plist

    Adobe Photoshop elements 13 paths

    Adobe Photoshop elements 13 parameters.

    This library is hidden in the latest versions of Mac OS X. To see it, click on the menu go to the Finder and hold down the Option key, then it appears in the small house for your user account.

    After you delete the files, repair permissions, and then try again.

  • Interactive report uncheck filter when you add the new filter

    Y at - it all possibliity to uncheck all filters that are already defined in an interactive report when you create a new filter?

    My first approach by adding a dynamic action that is bound to the search field:

    key_down = event
    jQuery Selector = #apexir_SEARCH
    scope = live event

    The Action contains:
    $('input:checkbox').attr ("checked", false);

    At present, there are 2 problems:
    1. when the user presses 'go' or 'enter' the check box is checked again when the result is displayed
    2. If a filter is defined when the search box is not used, it does not work

    Hi Oliver,.

    too many problems I think. You can try to hack any POST message, analyze it, and if it's p_widget_action = FILTER stop action and interfere with an AJAX to APEX_UTIL call. IR_FILTER or IR_RESET. After the AJAX request was returnd (synchronous), you can start again the original MESSAGE that defines the new filter.

    Hmm. sounds to me like you'd better ask the customer if he is willing to pay for this kind of convenience.

    Greetings from Germany from the North,
    Andreas

  • Reset the filter prompt when you navigate to the dashboard Page

    Hello world! Came across this bizarre situation when navigating from a source of report a target and then dashboard page topic to another page of dashboard. It seems that the prompt value filters are enabled on each succeeding because of this dashboard page.

    Scenario as follows:

    I have a report from the source

    Item ID * State * Contact
    12345 * open * SomePerson

    If I click on SomePerson (value Navigation Drill-Down), it takes me to a dashboard Page that has Contact = SomePerson applied filter, which works as expected.

    But now, when I go to all the other pages of the dashboard, both the status = open and Contact = SomePerson are applied to all views. Is there in such a way that by clicking on the dashboard Page tab would also default reset all filter values prompted since the guests?

    Thank you! I learn a lot here. Any help would be appreciated.

    Hello

    What is there in the other pages of your quick dashboard...
    According to my understanding of your question...
    you make the scope of the dashboard page guest

    OR

    You can turn off the guests before selecting anything...
    Follow this... http://obiee101.blogspot.com/2008/08/obiee-making-clear-button.html

    Thank you & best regards
    Kishore Guggilla

  • Client VPN does not start when you use RDP

    I have a few people that RDP in Windows 2000 Server. The console client VPN starts very well (4.7 4.6 & tried). When accessing remotely via RDP, you try to start the VPN client throws the error:

    "Error 56: the Service VPN from Cisco Systems Inc. has not been started." Please start this service and try again. »

    Helpful service is started and it works very well from the console.

    If this is the case, then I guess that this version may have a bug.

    personally, I always use the v4.0.3(a). I was testing v4.6, however, it kept crashing my machine so finally that I dropped.

  • VPN high availability: double 3 k in the hub and the PIX as rays

    Hi Experts.

    In my scenario, I need routing between the rays and, above all, high availability (HA).

    On the shelves, I have Pix 501/506E, OS ver 6.3. In the hub, I have a couple of redundant VPN3k.

    What mechanism is the best:

    1 - hub and spoke topology with remote EzVPN in rays - to HA, I can take advantage of the "load balancing" feature of the VPN3k?

    2 - hub and spoke topology with remote EzVPN in rays - to HA, I can take advantage of the "backup server" feature of the VPN3k?

    3 any-to-any topology (an IPSEC tunnel between any pair of sites) - for HA, I can take advantage of the 'LAN-to-LAN backup' feature of the VPN3k?

    Thank you

    Michele

    I'd go with NLB on the backup server. With load balancing your connections will be spread over the two hubs. If a hub dies, then at least it will only affect half of your connections, rather than each of them in case of death of your primary and backup servers using.

    If a hub dies, your PIX connections will be de-energized for a short period, but they will be able to reconnect back automatically without making you no change.

  • I have a VPN connection on my old computer to the network and the location of the former employer. How can I remove this. ?

    I unplugged, but it still appears on my computer under network and I can not remove it...

    Course's former employer can access my computer?

    I have another remote connection that accesses my new work computer, and I fear that my former employer may be able to access.

    I have confidential information on the new remote connection.

    Thank you

    Hello KathleenK86,

    The question you posted would be better suited in the TechNet Forums. I would recommend posting your query in the TechNet Forums. You can follow the link to your question:

    http://social.technet.Microsoft.com/forums/en-us/w7itpronetworking/threads

    Hope this information helps.

  • Why my machine does not freeze when you apply the paint to the oil filter in Ps CS6?

    HAF 932

    Motherboard ASUS P9X79 Deluxe Intel X 79

    Processor Intel Core i7 - 3930K

    RAM 32 GB (4-8)

    Universal CPU cooler Thermaltake CLP0564 Frio double 120mm

    Master cool 1200W Power Supply

    PNY VCGGTX570XPB - CG GeForce GTX 570 video card

    Crucial CT256M4SSD2 M4 SSD 2.5 "

    4 Hitachi 1 TB HD

    Card reader internal Ultra Aluminus U12 - 40529 3.5 "

    Lite-On iHES112-04 12 X internal Blu-Ray/DVDRW combo driv

    Windows 7-64 bitOil+Paint+Filter+FREEZING.jpg

    Maribeth R wrote:

    GeForce GTX 570 video card

    You are running version 301.42 available from nVidia.com display drivers?

    -Christmas

  • No preview image when using the filter flow therefore cannot see the changes I make up by clicking on the window of fluidity.  No way of knowing what is happening to the image while it is happening.

    Re: the fluidity in the last update PS CC filter.  When you use the filters of flow, how can I see the changes that I do while I'm using the filter tools, as I've always been able to do before?  Now, if I use the tool dilation or contraction tool, etc., I can't see the effect of what I did until I click on the window of fluidity and make to the main screen of PS.  This makes the tools unnecessary fluidity.

    Also check if see the background is checked.

Maybe you are looking for

  • Cannot change the Raw of Canon 80 d photo images

    Import raw images from Canon 80 Photos D modify them as opinion says Photos does not recognize these files

  • Satellite A300 - starts, but I don't know why

    I recently bought a Toshiba Satellite A300 and the following events occur: I turn off the phone properly, I close the lid, and sometimes with the valve closed the laptop starts normally, both the battery and without. I went through all the power opti

  • Aspire backup dafault V5 - 473G

    Hello If I ticked the option "copy the partition recovery from the PC to the recovery disc" my 16 GB flash drive were not detected by recovery management. But I can make the default backup without the option turned on.

  • M6-n012dx processor upgrade

    Hi I was wondering if I could upgrade my cpu to m6-n012dx HP ENVY. The vehicle currently has a 4200 m i5, also what is the model of this laptop motherboard and what are the processors compatible with her if she has any. I hope to upgrade to an i7 470

  • battery problem on sony vaio z3 after update of windows 8

    I had to disable the utilitiy ISB in the Task Manager, because the system wanted to put the computer into hibernation because of a battery problem.  I had the same problem after updating the driver control of battery.  How should I proceed?