Each second ping fails

Hi all

I have a little test lan with the installation of 2611xm for ipsec vpn.

On each fe port I have a laptop plugged directly inside, int is assigned by dhcp, and outside at this stage is static.

I use 3rd party ipsec client program shrewsoft customer vpn.

The tunnel rises and its is established with many packages of encryption and decryption.

As mentioned in the title, each second ping fails in both directions from client to client, router 100% inside the cell phone pings and fails to address assigned 192.168.1.10 to the client ipsec "remote".

Here is my config and below that, I think that highlights where might be the cause, the arp entry address assigned ipsec is incomplete.

An ipconfig/all on the "remote" client shows a mac address of the int as aaaa.aaaa.aa00 tunnel.

Kind regards

Mitchell

config:

Router #show run
Building configuration...

Current configuration: 2139 bytes
!
version 12.3
horodateurs service debug datetime msec
Log service timestamps datetime msec
no password encryption service
!
router host name
!
boot-start-marker
boot system flash: c2600-ik9s - mz.123 - 6f.bin
boot-end-marker
!
!
no location network-clock-participate 1
No network-clock-participate wic 0
No aaa new-model
IP subnet zero
IP cef
!
!
no ip domain search
IP domain name vpn.changeme.com
IP-server names 4.2.2.2
DHCP excluded-address IP 192.168.0.0 192.168.0.9
!
internal IP dhcp pool
network 192.168.0.0 255.255.255.0
default router 192.168.0.1
4.2.2.2 DNS server
domain vpn.changeme.com
!
!
!
!
!
!
!
!
!
!
!
!
!
!
!
Keyring cryptographic remote_user
pre-shared key address 0.0.0.0 0.0.0.0 key xxxx
!
crypto ISAKMP policy 1
BA aes 256
preshared authentication
Group 5
ISAKMP crypto nat keepalive 5
crypto ISAKMP client configuration address pool local ipsec
!
ISAKMP crypto client configuration group remote_user_group
key xxxx
outdoor pool
ISAKMP crypto profile remote_user
Keychain remote_user
remote_user_group group identity match
!
!
Crypto ipsec transform-set esp - aes 256 esp-sha-hmac DYN_TFS
!
crypto dynamic-map DYN_MAP 1
game of transformation-DYN_TFS
REMOTE_USER Set isakmp-profile
!
!
launch of the card client configuration address card crypto
card crypto card client configuration address respond
map 1-isakmp ipsec dynamic crypto map DYN_MAP discover
!
!
!
!
interface FastEthernet0/0
ETHERNET INTERNAL description
the IP 192.168.0.1 255.255.255.0
automatic duplex
automatic speed
!
interface Serial0/0
no ip address
Shutdown
no fair queue
!
interface FastEthernet0/1
WAN ETHERNET description
10.1.1.1 IP address 255.255.255.0
automatic duplex
automatic speed
No cdp enable
card crypto map
!
interface Serial0/1
no ip address
Shutdown
!
IPSec local pool 192.168.1.10 IP 192.168.1.100
IP http server
no ip http secure server
IP classless
Driving IP profile
IP route 192.168.1.0 255.255.255.0 FastEthernet0/1
!
!
access list 101 ip enable any 192.168.0.0 0.0.0.255
!
!
!
!
!
!
!
!
Line con 0
Synchronous recording
line to 0
line vty 0 4
privilege level 15
opening of session
transport telnet entry
!
!
!
end

ARP on the router #show
Protocol of age (min) address Addr Type Interface equipment
Internet 10.1.1.2 0 001b.d338.0bab ARPA FastEthernet0/1
Internet 10.1.1.1 - 0017.5993.a6c1 ARPA FastEthernet0/1
Internet 192.168.1.10 0 incomplete ARPA
Internet 192.168.0.1 - 0017.5993.a6c0 ARPA FastEthernet0/0
Internet 192.168.0.2 1 001b.d338.0b7c ARPA FastEthernet0/0

The "Internet 192.168.1.10 ARPA incomplete 0 " output does not seem right. "."

The router should not have even this particular ARP entry because there is no router with the 192.168.1.0/24 subnet interface, so there is no reason for the router to ARP for this subnet unless you connect a PC with the 192.168.1.10 ip address previously. I suggest that you turn off the router ARP entry "clear arp.

For the following path statement: ip route 192.168.1.0 255.255.255.0 FastEthernet0/1, I would like to change the next hop of the fa0/1 to the actual ip address of the next hop router (or your ip address of PC if you connect directly a PC to the router interface fa0/1), that is to say:

IP route 192.168.1.0 255.255.255.0 10.1.1.x

Hope that helps.

Tags: Cisco Security

Similar Questions

  • DLR ping fails

    I use 5.5 and nsx 6.1.4 esxi

    and 4 physical machines

    I have 192.168.10.0/24 and 2 sub net 192.168.0.0/24

    I use 2 physical switch each for 1 net sub but the switches are not connected

    a cluster

    OME controller

    all esxi are connected to the net with Teddy 2 sub 2

    1 VDS for the cluster

    virtual machines are simply windows.iso just to simulate network clients

    I have 4 virtual machines of windows

    VM1 and VMS 2 in esxi 3

    VM3 and vm4 in esxi 4

    VM1 and VMS 3 (10.1.0.0/24) network connected to logical switch 1

    VM2 in esxi 3 and vm in esxi 4 4 logged in LS2 (10.2.0.0/24)

    16GB in each machine

    I use windows server r2 2012 AD and DNS

    "I have congigured a DLR between LS1, LS" and transit LS

    but the ping fails between VMS in different subnet

    Anay idea?

    DNAT (Destination NAT) is required for http access to vm via a public IP address on the edge gateway ESG.

    This article on the DTA section explains the configuration steps. A Point to note is that for the feature NAT firewall must be enabled and a firewall rule for http public address must be entered.

    http://www.routetocloud.com/2014/12/NSX-v-edge-NAT/

  • Once a day, I lose all network connectivity on my Windows XP SP3 laptop. When I try to ping something I get this error: "PING failed, error 1450' code"

    Hello, those in about 3 days, I lose network connectivity on my laptop with Windows XP SP3. When I ping no matter what page of the console I get the following error message: show PING failed, error code 1450. I tried to use the option of repair in my area, but it did not help. Computer restart resolves the problem, but I'd like to avoid doing. What should I do to solve the problem?

    original title: loss of network connectivity

    Since this happen in two different ISP, try to reset your modem or router and also contact your ISP support. Some ISPS will set a rule and limitation of their user, but in your case, discuss it with your ISP, or contact technical support for your PC manufacturer.

  • Successful lease IP, but ping failed and comms

    I run a network of 2 PC's at home. The two PC is running XP. I had successfully this network running with ICS for about 1 year. Due to performance issues, I decided to format the PC host. No hardware changes were made, but I load the updated drivers for all devices (including NIC - Intel Pro 100) on the formatted PC. Since the charging I can't do a ping between 2 PCs. The loop back Ping works fine on both PCs. What is really disconcerting is the fact that by using the ipconfig/all command, I see that the client PC rents successfully a new IP address of the host, but still there is no communication and ping fails. I ran several times in the Configuration Wizard from the network on both machines using different computer names (and even change the name of working group) of force to renew the connection. Whenever I see that the customer is to successfully get a new host IP lease, but always communication and ping is not available. I use AVG free edition and Windows Firewall. I also disabled the Windows Firewall on both machines, but it made no difference. I tried to put the customer on a fixed IP (192.168.0.2), but that also doesn't solve the problem. I am out, please help.

    Thanks for the reply, but the problem was resolved last night. I uninstalled the Intel driver for the NETWORK card and reinstalled an old version that I had on the disk. This instantly solved the problem, so I can assume there is a problem with the latest Intel driver. Thanks again.

  • Update error... I tried to update for the month and each time it fails

    I tried to perform updates for the month and each time it fails.  I get the same error message... Code 646 WIndows has encountered an unknown error.  I did troubleshooting and you are unable to find assistance.  I don't know much about the workings of the computer, but I know that I should be able to perform these updates.  I think I need it too.  I have 9 at this stage that it cannot load.  Help, please!

    I tried to perform updates for the month and each time it fails.  I get the same error message... Code 646 WIndows has encountered an unknown error.  I did troubleshooting and you are unable to find assistance.  I don't know much about the workings of the computer, but I know that I should be able to perform these updates.  I think I need it too.  I have 9 at this stage that it cannot load.  Help, please!

    This link leads to a response from Bobby Mi, moderator.
    Date: July 6, 2010
    http://social.answers.Microsoft.com/forums/en-us/vistawu/thread/18449f60-C149-4EAF-B8E6-a2880cd7232b

    Bobby Mi response will lead to this tutorial from Microsoft Support:
    http://support.Microsoft.com/kb/2258121

    Hope this can help solve your problem.
    For the benefits of others looking for answers, please mark as answer suggestion if it solves your problem.

  • fqdn ping fails after recovery from sleep mode

    client system is win7 64 bit

    Server DSN is isc bind 9.7 works on win 7 64 bit

    local system of fqdn ping fails after recovery from sleep mode.

    I do not think that the ping never hits the network.

    Nslookup of full domain name or name of the system only exists.

    the system name ping only succeeds.

    then after ipconfig/release, ipconfig / renew, successor to ping the domain name full local system.

    someone at - it thoughts or ideas?

    Hello

    From the description of the problem, it seems that your computer is on a domain. I suggest you post the same question on the link below. The link given below is link TechNet Support for Windows 7. The question facing you is best for TechNet forums.

    https://social.technet.Microsoft.com/forums/Windows/en-us/home?Forum=w7itpronetworking

    Feel free to write us if you have any other issues related to Windows.

  • Guest to guest Ping down (second Ping)

    Environment: ESXi Cluster DMZ closes

    2 R720 PowerEdge servers

    5.5 vCenter

    ESXi 5.5 ENT more

    6 - 1 GB NETWORK interface card

    -2 NIC - ESXi management

    -NIC 4 - VDS trunks

    VDS trunks connect to 3750 x with uplinks to the ASA5525x

    2 k 8 R2 invited on both hosts.

    All the guests drop periodically second ping to another client on cluster. (two guests).

    Sometimes more than one ping fall occurs.

    Any help to solve this issue is greatly appreciated.

    Topology

    VM on DMZ > tandem switch > Firewall

    What we found:

    The firewall strives to respond to ARP requests for the demilitarized zone.

    Applied controls:

    We have added search non-proxy-arp and route orders to the NAT configuration of the firewall part.

    The second ping drops stopped.

  • nslookup works, but ping fails by hostname (works of intellectual property). IE cannot display this webpage. Help, please!

    Cannot access Internet on my laptop with Windows XP SP2 installed; uninstalled firewall; Microsoft Security Essentials (AV) installed

    ipconfig/all shows a 192.168.x.x ip address to my ethernet card.

    TCP/IP properties are set to "Obtain an IP address automatically" and "Obtain DNS server address automatically."

    I am able to search names and ping by ip address but cannot ping by hostname. When I try to navigate through a Web site, it displays the message "Waiting for http://xxx.xxx.xxx ' in the status bar, but fails to load the Web page.

    I tried a few sites by their IP with the browser, for example 212.58.244.143, and IE was able to load the Web page (without any objects of course requiring name resolution).

    Able to ping loopback (127.0.0.1) as well as the computer by its name (which resolves to the ip address is assigned to the).

    ARP - a shows the entrance to the default gateway. Able to ping.

    I did ipconfig/flushdns and / registerdns without effect.

    Even with net stop dnscache and net start dnscache.

    Manually reset TCP/IP too by following the instructions here.

    Also used "netsh winsock reset catalog" according to the guideline here.

    Running out of ideas here... could someone please advise what to do? Or what additional information it would take to solve this problem?

    I met the same problem on win7. I also tried each solusion what you tried.

    In the end, I reinstalled the tcp/ip stack and solved this problem. Try the following steps:

    1 remove

    HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Winsock
    HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Winsock2

    2 reset

    3. right click on the network connection and then click Properties. Reinstall the protocols of the disc. The location is 'C:\Windows\inf '. Choose the «ipv4...» "and"ipv6 ".

    4 reboot

    Everything is ok.

    Good luck!

  • DNS Broke - nslookup successful but Ping fails

    Hello

    I'm working on an old client computer that is running Windows XP SP2.

    The computer is unable to connect because of a sort of DNS issue, so it appears.

    See, very strange:

    C:\Documents and c > nslookup digg.com

    Server: quarter - pri.sys.gtei .net

    Address: 4.2.2.1

    Non-authoritative answer:

    Name: digg.com

    Address: 64.191.203.30

    C:\Documents and c > ping 64.191.203.30

    Ping 64.191.203.30 with 32 bytes of data:

    Reply from 64.191.203.30: bytes = 32 time = 83ms TTL = 242

    Reply from 64.191.203.30: bytes = 32 time = 81ms TTL = 242

    Reply from 64.191.203.30: bytes = 32 time = 82ms TTL = 242

    Reply from 64.191.203.30: bytes = 32 time = 86ms TTL = 242

    Ping statistics for 64.191.203.30:

    Packets: Sent = 4, received = 4, lost = 0 (0% loss),

    Time approximate round trip in milli-seconds:

    Minimum = 81ms, Maximum = 86ms, average = 83ms

    C:\Documents and c > ping digg.com

    Ping request could not find host digg.com. Please check the name and try again.

    C:\Documents and c >

    C:\Documents and c > nslookup digg.com

    Server: quarter - pri.sys.gtei .net

    Address: 4.2.2.1


    Non-authoritative answer:

    Name: digg.com

    Address: 64.191.203.30



    C:\Documents and c > ping 64.191.203.30


    Ping 64.191.203.30 with 32 bytes of data:


    Reply from 64.191.203.30: bytes = 32 time = 83ms TTL = 242

    Reply from 64.191.203.30: bytes = 32 time = 81ms TTL = 242

    Reply from 64.191.203.30: bytes = 32 time = 82ms TTL = 242

    Reply from 64.191.203.30: bytes = 32 time = 86ms TTL = 242


    Ping statistics for 64.191.203.30:

    Packets: Sent = 4, received = 4, lost = 0 (0% loss),

    Time approximate round trip in milli-seconds:

    Minimum = 81ms, Maximum = 86ms, average = 83ms


    C:\Documents and c > ping digg.com

    Ping request could not find host digg.com. Please check the name and try again.


    C:\Documents and c >

    So, as you can see the GET from the computer to the correct IP address for any domain using nslookup, but trying to ping or access any domain name instantly fails. :(

    Tried to run winsockxpfix, but that made no difference.

    Also, I tried using the service DNS, open dns but same problem.

    The computer is connected to my knowledge as work network. 7 other computers and two xbox 360 s on the network even get very well correct dns data. So it's fair to this computer.

    Even tried to install BIND 9 on the PC and the same problem. :(

    Thanks for the help,

    Will be

    God Bless America

    I fixed it by managing to install SP3. Just so install SP3 for XP fixed the problem. : D

    And Yes Ben, I tried that too. At a rating of 1. Thank you for trying to help though.

    God Bless America

  • 14/01/2016 of each update has failed me

    Original title: update 01/14/2016 of each update failed me , I do not know what's going on , but I'm really weird.
    
    01/14/2016 of each update failed me , I do not know what's going on , but I'm really weird.
    

    You receive errors related to updates?

    1. Open Windows Update by clicking the Start button, all programs and then click Windows Update.
    2. In the left pane, click view update history.
      http://Windows.Microsoft.com/en-AU/Windows/which-Windows-updates-installed#1TC=Windows-7
    3. Find an update for Windows that has failed to install, and then double-click the update to view more information.
      Updates that have failed to install will display failed under status, next to the name of update.
    4. In the Windows Update dialog box, next to the details of the error, review the error code for the update has failed.
    5. Follow the links in the Windows Update dialog box under more information or help and Support to resolve the problem, then try to reinstall updates by using Windows Update in Control Panel or by mail with the error code and maybe someone may be able to help others.

    How to ask a question:
    http://support.Microsoft.com/kb/555375

  • Test the IP (Ping failed)

    I want to develop an application from server to client on the Playbook.

    First thing, I'm getting is ping the Playbook of my office and vice versa.

    The Playbook seems to be able to ping from the desktop.  When I try to ping my Playbook of my desktop (Win7), it fails.

    I use the IP address found on the Playbook under Wifi settings.

    We know what I am doing wrong?  I have looked around and you haven't seen anything on this Board or Google which addresses this problem.

    Thank you.

    Thanks for responding, Mark.

    I meant with my progress so far yesterday.

    In my router settings was a checkbox for the isolation that allows anyone to see the devices on wifi.  Unchecking it now allows me to ping devices.

    I don't know what Mark refers to since I can now ping the Playbook as well as my laptop and iPod touch.

    Catch face!

  • REGEXP_REPLACE problem/bug - replaces only each second occurrence

    Hi all


    I use

    Oracle Database 10 g Express Edition Release 10.2.0.1.0 - product
    PL/SQL Release 10.2.0.1.0 - Production
    CORE 10.2.0.1.0 Production
    AMT for 32-bit Windows: Version 10.2.0.1.0 - Production
    NLSRTL Version 10.2.0.1.0 - Production

    I need a regular expression to rename a variable in a mathematical formula, when testing my code that I discovered that if the variable was repeated after himself that a single occurrence has been replaced. I need to replace only whole words as some variables can be a subset of a variable name longer, and variable names can have underscores in them.
    Here is an example of what happens.

    Is someone can you please tell me why this happens? Example code is:

    SELECT REGEXP_REPLACE (' ab ab ab + ab + ab + ab + ab + abc + abc + ab ", '(\W|^)ab(\W|$)', '\1xy\2',1,0,'i') from DUAL;

    The regular expression matches all the "ab" with a start line or a non alphabetical character before and not alpha or end of line at the end.

    I have then replace the "ab" by "xy" and keep the original alpha not on each side. What happens is that only every second occurrence is replaced.
    If I put a space after each '+', and then it replaces all occurrences. (Of course, this is a domain user in a table of mathematical formulas so I can not wait to the user to worry about this problem.)

    I think that this may be due to the fact the pointer in conclusion any occurrence is moved correctly and it does not find the game immediately after.

    Can someone please explain this? Or did I miss something in my example.

    Thank you
    Dudley

    I don't think it's a bug, at least comparable re in python produces the same result:

    import re
    s="ab+ab+ab+ab+ab+ab+ab+abc+abc+ab"
    print re.sub(r"(\W|^)ab(\W|$)",r"\1xy\2",s)
    xy+ab+xy+ab+xy+ab+xy+abc+abc+xy
    

    If you have a match in your regular expression, the next probe will be launched after the game, it's how the regular expression works (at least IMHO).
    In your example the corresponding characters are "+ ab + (except the beginning of the line, end of line), that's why next occurency"ab"is not equal to."
    If you want to replace all"in Alberta, you could make the model as

    SELECT REGEXP_REPLACE('ab+ab+ab+ab+ab+ab+ab+abc+abc+ab', '(\W|^)?ab(\W|$)' , '\1xy\2',1,0,'i') from DUAL;
    

    Best regards

    Maxim

    Published by: Maxim Demenko, 14 July 2009 14:09
    fixed formatting

  • Internet IP Ping failed

    Hi, I received a windows update, but since it is installed I don't have an internet connection. I ran a diagnosis and the internet IP Ping couldn't whatever that means and how to fix? I tried many suggestions on the forum but nothing helps. The problem is not with the router I can get a connection with another computer someone at - it suggestions please.

    Hello

    Perform the steps in the article, and check whether the problem is resolved or not.

    "Internet Explorer cannot display the webpage" error when you view a Web site in Internet Explorer

    Hope that helps.

  • Ping fails intermittently but nslookup is fine

    Hello

    I enabled DNS and AD Windows 2008 r2 roles. I have Windows 7 and Windows 8 machines in the LAN and two of them having intermittent outages to resolve hosts using domain FULL, LAN hosts can be reached using the IP address and NSLOOKUP works fine too... It's just PING using a FULL domain name is not resolved. Appreciate any help with this issue.
    Here "ipconfig/all" watch for an Ethernet connection... (I disabled IPv6 on the local PC under control-> networks-> Ethernet properties panel)
    DHCP active...: Yes
    Autoconfiguration enabled...: Yes
    IPv4 address...: 10.0.10.199 (Preferred)
    ... Subnet mask: 255.255.255.0.
    Lease obtained...: 15 January 2013 14:56:57
    End of the lease...: February 3, 2013 17:26:18
    ... Default gateway. : 10.0.10.1.
    DHCP server...: 10.0.10.1.
    DNS servers...: 10.0.10.50
    10.0.10.1
    NetBIOS over TCP/IP...: enabled
    BTW, using workaround so far is, run ipconfig / renew twice and ping with FQDN works very well yet.
    Thank you
    Kishore

    Hello

    The Microsoft Answers community focuses on the context of use. Please reach out to the business community of COMPUTING in the TechNet forum below:

    http://TechNet.Microsoft.com/en-us/WindowsServer/bb310558.aspx

  • Ping failed with more than 76 bytes on Codian 4510

    Hi all

    Some troubleshooting problem I stumbled across what seems to be a strange behavior with the Codian 4510. In two separate environments, I realized that ping the device with a packet size of more than 76 bytes of data results in delays as shown below. Anyone know why this happens?

    localhost: ~ jason$ ping s 76 10.2.0.208

    PING 10.2.0.208 (10.2.0.208): 76 data bytes

    84 bytes from 10.2.0.208: icmp_seq = 0 ttl = 254 times = 3,642 ms

    84 bytes from 10.2.0.208: icmp_seq = 1 ttl = 254 = ms 3,579 times

    ^ C

    -10.2.0.208 - ping statistics

    2 packets transmitted, 2 packets received, 0.0% packet loss

    round-trip min/avg/max/stddev = 3.579/3.611/3.642/0.031 ms

    localhost: ~ jason$ ping s 77 10.2.0.208

    PING 10.2.0.208 (10.2.0.208): 77 data bytes

    Request timeout for icmp_seq 0

    Timeout for icmp_seq request 1

    ^ C

    -10.2.0.208 - ping statistics

    3 packets transmitted, 0 packets received, loss of packets of 100.0%

    This is normal, to avoid problems due to the too large ICMP packets.

Maybe you are looking for