Lost the VPN tunnel between 2 site when internal client using client vpn

We currently have VPN tunnel connected to the remote desktop using router VPN Hotbrick 2.

When 1 of the internal computer try to connect to another server VPN customer using Cisco VPN Client v4.8, she will appear in drop/disable/loss of the tunnel between us VPN and remote offices. The tunnel is still established but no traffice between site 2. (cannot all ping)

What are the causes of the problem? Hotbrik problem? Customer Cisco VPN setting or something else?

I don't know what causes the problem. Help, please. Thanks in advance.

Hello

The problem is that your NAT device will not translating properly, and when the 2nd customer triggers (ISAKMP packets-UDP 500) connections port isn't transalated, so for the SAA is as the first user tries to connect again, then it rejects the initial connection.

The trick is, as you have discovered, use global UDP.

The problem is that UDP 10000 is not a standard, so you need to check if multiple users can be connected at the same time behind the same NAT device.

If this is not the case, use the NAT transparency standard industry (UDP 4500). This should be configured only on the SAA.

Please rate if this helped.

Kind regards

Daniel

Tags: Cisco Security

Similar Questions

  • I can weight of the IPSec Tunnels between ASAs

    Hello

    Remote site: link internet NYC 150 MB/s

    Local site: link internet Baltimore 400 MB/s

    Backup site: link internet Washington 200 Mb/s

    My main site and my backup site are connected via a gigabit Ethernet circuit between the respective base site switches.  Each site has its own internet connection and my OSPF allows to switch their traffic to the backup site if the main website is down.  We are opening an office in New York with one ASA unique connected to 150 Mbps FIOS internet circuit.  We want to set up an IPSec tunnel on the main site and the backup on the remote site, but want the remote site to prefer the tunnel in Baltimore, except if it is down.

    Interesting traffic would be the same for the two tunnels

    I know that ASA cannot be a GRE endpoint.  How can I force the New York traffic through the tunnel in Baltimore as long as it works?  An IPSec tunnel can be weighted?

    Thank you

    It is not in itself weighting, but you can create up to 10 backup over LAN to LAN VPN IPsec peers.

    For each tunnel, the security apparatus tried to negotiate with the first peer in the list. If this peer does not respond, the security apparatus made his way to the bottom of the list until a peer responds, or there is no peer more in the list.

    Reference.

  • How to force validation after lost the VPN connection

    Hello

    I did a lot of loading via a VPN connection. That lasted a few hours. Unfortunately the VPN connection has been lost. When you reconnect the VPN connection and connect in the scheme, I don't see all the data. Perhaps the transaction pending and was waiting to be engaged.

    Is it possible to tell the schema, "commit all pending transactions?

    Thanks in advance for any help.

    If your connection to the database has been lost, your session would have been rolled once the database realized he didn't have the client process. There was therefore no transaction on hold to commit at this stage.

    I don't think that there is a parameter that would indicate Oracle to automatically post transactions when the client process is dead - if there were, it would be extremely dangerous, since there is no guarantee that the data is in a consistent state to the point that the customer fails.

    Why are you doing a batch load via a VPN connection, probably from your desktop? Would be unwise to copy the data that you are trying to load a server in the same local network as the database and run the load it? In addition to being much more efficient, it is much easier to leave a job for some time on a server that it should keep a connection from your laptop computer for several hours.

    Justin

  • Unable to access SSL Web site when company proxy use man-in-the-middle attack to scan SSL traffic

    Our company uses a proxy server that analyzes the SSL traffic on web sites. This is done via man-in-the-middle attack. The proxy generates a new certificate on the fly that it sends to the client, impersonate a secure server.
    After upgrading from Firefox 10.0, I always get error:
    Error HTTP Status: 400 Bad Request
    After the confirmation of a security exception.

    Maybe this is related to the difficulties of the attack of the BEAST bug (browser exploit against SSL/TLS)

    • bug 702111 - intolerant servers to record split of 1: n-1. "The connection was reset" (see also the comment 60)
  • Problem with the text block, put in place when it is used on the page number marker

    Hello!

    I would use the text block on the marker page number on the master page in Indesign. The text block should change width when increases the page number. It does not work. What happens is that when the number of page moves a two-digit figure, the numbers tightened itself (compressed on top of each other) and the block of text changes size unless I drag on it (which means I have to manually unlock the master page first).

    I'm doing something wrong, or is this a bug?

    Thank you!

    Altogether! So, you can use a rule of Pará to simply do it!

  • What the Protection of Session State and when it is used.

    Hello

    I just want to know what is the Protection of the State of Session and where it should be used.

    Thank you
    Deepak

    Deepak,

    Protection of the State of session in the Oracle apex is a built-in feature that allows you to prevent users / hackers to a URL handling in your application.

    http://download.Oracle.com/docs/CD/E14373_01/AppDev.32/e11838/sec.htm#CDDGIGJH

    A simple way to undersatnd, what would be your banking session. As soon as you connect, your URL would include a key and probably session information for the session that you log on. But if you copy this URL and log off and reuse the URL, you wouldn't be able to connect as that the session is over.

    Or once you connect and navigate to a page, you would have the information information session and the page in your browser to the URL (say it's balance transfer page). However, this page would not directly accessible using the URL with someone else. A similar security feature can be activated by using "URL access" in the access page for Apex session state protection.

    Hope this helps,
    Rajesh.

  • Redirect a part of the vrf traffic between 2 sites over a redundant link

    Hey guys,.

    We have one customer (in the vrf) with 2 sites in different States and the execution of our soul of mpls... Our main link in our heart is affected by the degradation of service and want to route the client on our redundant link while retaining all other clients going on our primary link - is it possible?

    The customer in question has its own vrf (L3VPN) on both sites and running on mpls between sites. We would like to re - route this particular customer to take our backup path, while keeping everyone between sites through the primary. We do not use, rather LDP to build the SPLM.

    I don't think it's possible to only re - route a customer, but I thought I would ask the question.

    We cannot failover to secondary link for everyone between sites because the link doesn't have the capability.

    Thanks in advance.

    Hello

    Using MPLS YOU would certainly be an option. You must configure MPLS TE LS during the backup. You must also set up a separate look-back on each PE interface and use this address of the loopback interface as the next hop for the specific VRF

    IP vrf X

    BGP jump next loopback 999

    Route IP 255.255.255.255 Tu1

    In this way make you sure that only the traffic for this specific VRF would be above the tunnel of TE.

    Concerning

  • How do the firefox stop, a loading site when a new address is registered or a new link/bookmark is clicked?

    When you enter an address in the address bar that represents a place of slow loading (or even a site that does not exist) and then immediately after hitting enter change address link to a site that loads faster you will reach the last registration site. But after a while firefox will return to you at the address you entered first of all, on the site it represents or a page that contains a message that the site cannot be loaded.

    This problem often occurs when you type the wrong address and quickly corrected it.

    Reproduce the error with the following example:
    1: enter "awaawefawefsdfj.com" (or another site existing none) in the address bar and press ENTER.
    2: after quickly replace the address with "google.com" (or another fast loading site) and press ENTER.

    It displays first page of google and shortly after viewing a page with the error message.

    So my question is: this problem can be fixed with the settings?

    You can provide this feedback to developers here-
    https://input.Mozilla.org/en-us/feedback

  • Why Firefox has changed to show the U.S. on search sites when I am based in the United Kingdom?

    Since the installation of her "forget the historical navigation button" Firefox automatically displays the American Web sites instead of the previous UK those.

    The forget button is build in Firefox, but in order to ensure that there has been no change, have you you initially download the American or British Firefox build? I do not think that the two are linked, but you can change the search location in some search preferences. This can also be triggered by you IP address.

  • Firefox displays a cursor blinking 'Edit' in the body of all Web sites when I click.

    By clicking a button on a page Web puts the text flashing in the body of the site, like cursor editing a Word document. It is not cause other problems in addition to being really annoying and distracting, but it started today. I tried to restart Firefox with disabled modules, as well as to reinstall clean Firefox.

    Besides the above:

    This is probably because passing on the keyboard navigation and you can switch power switch keyboard navigation by pressing F7 (Mac: fn + F7).

    Note that this is a function of Firefox Accessibility.

    • Tools > Options > advanced > general > accessibility: [] "always use the cursor keys to navigate through the pages."
  • How to set the time difference between each data when using keithley 2400 scanning

    Hello friends,

    I use scanning Keithley vi the extent of SCANNING and acquire vi. I want to measure the voltage for each step and a pause between each two data, so I need a delay between each I step.

    I'm a starter to use Labview, thank you very much for your answers.

    Perry

    As Dennis says, if you use the built-in scan function, you will need to consult the manual. See Section 10-16 (this is page 10 of article 16, only paragraphs not but 10, 16) for the manual Keithley 2400.

    The Keithley 24xx series has a speed of measurement in units called PLC (Power Line Cycles). The default speed is 1PLC, which means a measure is taken with each cycle of line 1 power supply or 1/60th of a second (16.67ms). 24XX can range from 0.01 PLC (all 0.16ms) 10 PLC (all 166.6ms). The faster you measure, the less accuracy you get.

    To programmatically set this value, the command is

    ENSe:CURRent:NPLCycles

    ENSe:VOLTage:NPLCycles

    Depending on what you are sensing and where is the number of controllers from 0.01 to 10.

    Another factor that will determine the time between data points is the cycle SDM. These are more complicated, look at your Keithley manual for more information. Look at article 6 and article 11 for more information.

    Note:

    PLC times are based on a cycle of 60 Hz US.

  • NAT in the IPSec tunnel between 2 routers x IOS (877)

    Hi all

    We have a customer with 2 x 877 routers connected to the internet. These routers are configured with an IPSec tunnel (which works fine). The question is the inbound static NAT translation problems with the tunnel - port 25 is mapped to the address inside the mail server. The existing configuration works very well for incoming mail, but prevents users from access to the direct mail server (using the private IP address) on port 25.

    Here is the Config NAT:

    nat INET_POOL netmask 255.255.255.252 IP pool

    IP nat inside source map route INET_NAT pool INET_POOL overload

    IP nat inside source static tcp 10.10.0.8 25 25 expandable

    IP nat inside source static tcp 10.10.0.8 80 80 extensible

    IP nat inside source static tcp 10.10.0.8 443 443 extensible

    IP nat inside source static tcp 10.10.0.7 1433 1433 extensible

    IP nat inside source static tcp 10.10.0.7 extensible 3389 3389

    allowed INET_NAT 1 route map

    corresponds to the IP 101

    access-list 101 deny ip 10.10.0.0 0.0.0.255 192.168.1.0 0.0.0.255

    access-list 101 permit ip 10.10.0.0 0.0.0.255 any

    On the SAA, I would setup a NAT exemption, but how do I get the same thing in the IOS?

    See you soon,.

    Luke

    Take a look at this link:

    http://www.Cisco.com/en/us/docs/iOS/12_2t/12_2t4/feature/guide/ftnatrt.html

    Concerning

    Farrukh

  • Lost the disk for Installation of Windows Vista - can I use my friends with my product key?

    I am running Windows Vista on my computer at home, but I had this for a few years, and he began to have very slow, so I decided to completely erase the hard drive, now I know how to do this, but I need to re - install the OS when I'm done, but I've lost my Windows Vista installation CD , even though I still have my code/product key - it would be OK to use my drive of Windows Vista to friends with my product code?

    I tried this article: http://support.microsoft.com/default.aspx/kb/326246and he do not seem to answer my question - I'm trying to replace my copy, I just want to know if it is OK to use my friends?

    Yes.

    As long as it's a DVD from Microsoft and not a computer Manufacturer'e Recovery DVD.

    Read the information below.

    Vista recovery media obtain and/or use the Partition Recovery Vista on your computer to the factory settings .

    There is no Vista free download legal available.

    Contact your computer manufacturer and ask them to send a recovery disk/s Vista set.

    Normally, they do this for a cost of $ small.

    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

    In addition, ask them if you have a recovery Partition on your computer/laptop to restore it to factory settings.

    See if a manual provided with the computer or go to the manufacturer's website, email or you can call for information on how to make a recovery.

    Normally, you have to press F10 or F11 at startup to start the recovery process...

    Another way I've seen on some models is press F8 and go to a list of startup options, and launch a recovery of standards of plant with it, by selecting the repair option.

    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

    Also ask them if it is possible to do the recovery disk/s for the recovery Partition in case of a system Crash or hard drive failure.

    They will tell you how to do this.

    Every computer manufacturer has their own way of making recovery disk/s.

    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

    Or borrow a good Microsoft Vista DVD (not Dell, HP, etc).
    A good Vista DVD contains all versions of Vista.
    The product key determines which version of Vista is installed.

    There are 2 disks of Vista: one for 32-bit operating system, and one for 64-bit operating system.

    If install a cleaning is required with a good DVD of Vista (not HP, Dell recovery disks):

    Go to your Bios/Setup, or the Boot Menu at startup and change the Boot order to make the DVD/CD drive 1st in the boot order, then reboot with the disk in the drive.

    At the startup/power on you should see at the bottom of the screen either F2 or DELETE, go to Setup/Bios or F12 for the Boot Menu

    http://support.Microsoft.com/default.aspx/KB/918884

    MS advice on the conduct of clean install.

    http://www.theeldergeekvista.com/vista_clean_installation.htm

    A tutorial on the use of a clean install

    http://www.winsupersite.com/showcase/winvista_install_03.asp

    Super Guide Windows Vista Installation

    After installation > go to the website of the manufacturer of your computer/notebook > drivers and downloads Section > key in your model number > get latest Vista drivers for it > download/install them.

    Save all data, because it will be lost during a clean installation.

    See you soon.

    Mick Murphy - Microsoft partner

  • Why sometimes make the Chinese at the top of my screen symbols when I connect using Firefox? Actually more when I leave loging to be quite exact.

    I don't know if they're Chinese characters or another Eastern culture that uses similar to express thoughts in writing characters.

    You mark this thread as the Firefox OS thread, but I think you're talking about Firefox for desktop PC, right?

    So probably that you have mcafee site advisor extension installed in your browser, try starting Firefox with mcafee site Advisor disabled or try the safe mode

  • I suddenly lost the ability to create a wallpaper on my desktop using a one of my digital photos.

    I use MS XP Home edition - 2002 with Service Pack 3 installed.

    My DTC is a Dell Dimension 4700 with 3 GB of RAM

    I got a wallpaper from one of my old digital photos used for more than a year.  This past weekend, I tried to change it to a more recent photo.  He accepted the change initially, but the next time I logged in my system that the new image is gone, replaced by a dark blue background.  Then I did a restore of the system back to Friday October 23 and at the beginning the old returned photo.  Yet once, I could set the new photo as my desktop wallpaper, but it disappeared when I logged on later in the evening.

    The new photo was a .bmp file, but when I changed it to a .jpeg file it still doesn't load.

    Any help in resolving this problem.  It is very curious.

    CaptFBK

    Hello CaptFBK

    Try to copy your image to C:\Windows and see if it stays then.

Maybe you are looking for