Problem with website Source NAT Site policy

Dear all,

IAM facing issue with source based nat in Site-toSite VPN configuration.

We want to access the remote site server 10.67.1.5 from my main server 192.168.210.224, my 192.168.210.224 server need nat with 10.66.102.178 to go to the outside of the remote site. We have done below the configuration and VPN pahse1 and phase 2 sets up very well, but we are not able to access the remote server 10.67.1.5. Phase 2 set up and only the packages are not wrapping decapsulating. Remote site is seen VPN ending the router and the phase 1 and phase 2 implements.

There is no configured nat exemption. Appreciate urgent help to identify the problem...

We have tunnels from site to site much operational f... but not the tunnels with policy NAT

config
--------
access list acl - OR line 1 permit extended ip 192.168.210.224 host 10.67.1.5 (hitcnt = 0)
allowed to access list acl - NOR line extended to 2 ip host 10.66.102.178 10.67.1.5 (hitcnt = 2)

NAT (inside) 2 192.168.210.224 255.255.255.255
Global 2 10.66.102.178 (outside)

Crypto ipsec transform-set OR esp-3des esp-sha-hmac

card crypto ENOCMAP 22 matches the acl address - OR
card crypto ENOCMAP 22 set counterpart x.x.x.x
card crypto ENOCMAP 22 set transform-set
card crypto ENOCMAP 22 defined security-association life seconds 3600
card crypto ENOCMAP 22 set reverse-road
ENOCMAP interface card crypto outside

tunnel-group x.x.x.x type ipsec-l2l
tunnel-group ipsec-attributes x.x.x.x
pre-shared key *.

======================================================================

12 peer IKE: x.x.x.x
Type: L2L role: initiator
Generate a new key: no State: MM_ACTIVE

ENOCDC-FW03 # sh crypto ipsec his counterpart x.x.x.x
peer address: x.x.x.x
Tag crypto map: ENOCMAP, seq num: 22, local addr: x.x.x.x

access list acl - OR extended permit ip host 10.66.102.178 10.67.1.5
local ident (addr, mask, prot, port): (10.66.102.178/255.255.255.255/0/0)
Remote ident (addr, mask, prot, port): (10.67.1.5/255.255.255.255/0/0)
current_peer: x.x.x.x

#pkts program: 2, #pkts encrypt: 2, #pkts digest: 2
#pkts decaps: 0, #pkts decrypt: 0, #pkts check: 0
compressed #pkts: 0, unzipped #pkts: 0
#pkts uncompressed: 2, comp #pkts failed: 0, #pkts Dang failed: 0
success #frag before: 0, failures before #frag: 0, #fragments created: 0
Sent #PMTUs: 0, #PMTUs rcvd: 0, reassembly: 20th century / of frgs #decapsulated: 0
#send errors: 0, #recv errors: 0

endpt local crypto. : x.x.x.x, remote Start crypto. : x.x.x.x

Path mtu 1500, fresh ipsec generals 58, media, mtu 1500
current outbound SPI: 89BAF49F
current inbound SPI: DB36C4B6

Hello

Please try this nat statement below:

policynat list extended access allowed host ip 192.168.210.224 10.67.1.5

public static 10.66.102.178 (inside, outside) - policynat access list

Here is some reference material for policy nat - http://www.cisco.com/en/US/docs/security/asa/asa82/configuration/guide/nat_overview.html#wp1088419

Thank you

Tarik Admani
* Please note the useful messages *.

Tags: Cisco Security

Similar Questions

  • Anyone know if there is a problem with the "Windows Update" site? Since May 11, 2010...

    Anyone know if there is a problem with the "Windows Update" site? As of May 11, 2010 I could not access it for 2 days now.  I get an error report indicating that he has a "problem with the site '... Not sure if it's my computer or the site itself. I just need to check updates and download them. I would be grateful for any feedback...  Thank you!
    ~ Jenifer

    It is without a doubt.  There were a few patches published today, and I was able to update all my machines successfully.  This looks more like a virus problem.  Have you run a virus scan recently?  Many times, if you are infected the virus will prevent you to access Windows Update.

    You can also use Microsoft Fix It to reset the Windows Update components: http://support.microsoft.com/kb/971058.  This could also be your problem.

    Let me know how it goes,

    Barbara

  • Problems with access to Web sites in the laptop of my mother, both wireless and ethernet connections

    Original title: Internet issues

    My mother's laptop has suddenly stopped to access Web sites. I tried to explore, Firefox and Chrome using both wireless and ethernet... connections we both century link and I tried the two houses... my works laptop on both networks. All three browsers connect to the internet, but not all pages opens. I ran the store and he told me that I should look online for more help... which is not the case, but it cannot determine the problem. Any ideas?

    Hello

    Welcome to the Microsoft community.

    I understand that you have a problem with access to Web sites. We apologize for the inconvenience caused to you and appreciates your efforts to try to resolve the problem.

    I would like to know the details below to help you better

    1. Do you receive an error message/code when you access Web sites?
    2. Do you think that any symbol with exclamation on the icon of this internet access on the taskbar (right)?

    I ask you to try the steps in the Microsoft Help article below and check if it helps.

    Why can't I connect to the Internet?

    http://Windows.Microsoft.com/en-us/Windows/cant-connect-Internet#1TC=Windows-7

    Also I ask you to reset TCP/IP and check if it helps.

    How to reset TCP/IP using the NetShell utility
    http://support.Microsoft.com/kb/299357/en-us

    Keep us updated on the issue to help you better.

  • Problem with website security cerificates. Said the security certificate presented by this website was issued for a different website address.

    Problem began the week last with Verizon's Yahoo email. I can't access it. I get the message on the certificate.  Said the security certificate presented by this website was issued for a different website address.  can hnts in and out of yahoo, but can not get by e-mail. I have Windows vista 32-bit home. Have tried several things offered by yahoo... Delete history, cookies, defragment the drive hard, etc. Then they said need to ask Verizon. Community sitting there, no response. I had a help line, but what they had me try did not work. Could not do the download help remotely, I tried Java plugin download, has got an error 12031, and a Microsoft fix it but none of it worked. Could not load. Then they said it was having problems with Microsoft windows problems. Error files, corrupted files and certificate & register...  I did a few other things too but do not know if someone can help me... Not even if I am in the right place.  I really hope that someone can help you.

    Hi Patsabo,

    I suggest you to check if you are facing the same question in the new administrator account.

    Create a new user account-
    http://Windows.Microsoft.com/en-us/Windows-Vista/create-a-user-account

    If you are not faced with the same question in a new user account, you can view the link below and use the steps provided to fix a corrupted - user profile
    http://Windows.Microsoft.com/en-us/Windows-Vista/fix-a-corrupted-user-profile

    Let us know the status of the issue. If you need help, please after return. We will be happy to help you.

  • Problem with the download Web site

    I'm having a problem when I publish my site Builder at host gator.  The following errors are happening, and I don't know if these are problems of vista or not

    l\Temp\WER70C1.tmp.version.txt
    \Temp\WERC789.tmp.AppCompat.txt
    l\Temp\WERC7F7.tmp.mdmp
    Thanks advance!

    Cat hubrich,
    You will need to check with the Support of Ewisoft with this question.  Mike - Engineer Support Microsoft Answers
    Visit our Microsoft answers feedback Forum and let us know what you think.

  • Problem with the BlackBerry Developer Site

    We are currently experiencing a problem with the integration of BlackBerry ID with the BlackBerry Developer web site.  This prevents the developers to create a new BlackBerry ID Token, connecting Issue Tracker and Developer area and potentially other areas that require authentication.  Trying to access one of these pages gives the following error.

    Sorry, there is a problem with the page you are trying to reach and it cannot be displayed. Please try again later.
    

    Teams are trying to solve the problem.  We apologize for the inconvenience.

    The problem has been resolved.  You should now be able to connect Issue Tracker and generate BlackBerry ID chips again.

  • Problems with the Eclipse Update site

    Hello

    I try to install the component pack v6.0.0. I'm just following the instructions here

    http://NA.BlackBerry.com/eng/developers/javaappdev/javaupdate.jsp

    and installation just hangs (or I get the Exception of transfer). I found many messages of forum on the problems with the update site but no solutions. Is this one? Or y at - it another way to install the component pack in eclipse?

    Thank you

    Sarah

    Hi Mark,

    Apologies that I was on vacation and never had to deal with that. I just tried to update the software development kits using the same procedure. It must have been a problem with the update site before that it worked well this time.

    Thank you

    Sarah

  • a problem with the alignment of site on the Tablet and phone version.

    I have a problem with the alignment of my site on the Tablet and phone Version of my site.

    If you open the Tariffuehrer.com site on the tablet or smartphone, you can see, the page is aligned to the left in the browser. I want the page to Center. I did find an option for it in the backend of muse.

    I'd be happy if someone can help me.

    Hi Michael,

    I can't view your site as it showed error 403,

    Can you please recheck the url of your site and repost it so that I can check on this subject.

    Kind regards

    _Ankush

  • On Firefox only, I get problems with a few Joomla sites using the JA_purity template. Error: has not been loaded because its MIME type "text/html", is not "text /".

    Hello

    I updated Firefox on my computer for 13.01. Now, he struggles to read about 2 sites - both are Joomla and based on the model of JA-purity. What happens is that it fails to load the CSS files to do with the side and the top of the Joomla site menus. The file comes up with this:

    because its MIME type "text/html", is not "text/css".
    Source file: http://extensions.joomla.org/
    Line: 0

    This error does not appear with other browsers and it displays perfectly in fact in all other browsers.

    I'm new on this but I read the following article and think it could be my problem

    https://developer.Mozilla.org/en/Incorrect_MIME_Type_for_CSS_Files

    Where Im stuck, it's that I did not fully understand what to make of this article, if I could get a step by step guide to fix this problem that would be greatly appreciated.

    I apologize in advance if the answer lies somewhere here - I have had a look and couldn't get out.

    Thank you
    Alex

    I don't see that the error and all style sheets seem to load.

    Reload Web pages, and ignore the cache.

    • Hold SHIFT and click reload.
    • Press 'Ctrl + F5' or 'Ctrl + Shift + R' (Windows, Linux)
    • Press 'Cmd + Shift + R' (MAC)

    Clear the cache and cookies from sites that cause problems.

    "Clear the Cache":

    • Tools > Options > advanced > network > storage (Cache) offline: 'clear now '.

    'Delete Cookies' sites causing problems:

    • Tools > Options > privacy > Cookies: "show the Cookies".
  • problem with update of Windows 'site has encountered a problem and cannot display the page you are trying to view.

    Hi all, I recently rebooted my dell xps m140 older and I would get all the updates from microsoft. When I go to this webiste - http://www.update.microsoft.com/windowsupdate/v6/default.aspx?ln=en-us...i click on purpose and he says:-"the website has encountered a problem and cannot display the page you are trying to view. The options provided below may help you solve the problem. "no work around for this?

    You must be at Service Pack 3 level before you can use Windows updates.

    How to obtain the latest Windows XP service pack
    http://support.Microsoft.com/kb/322389

    You have not provided us with sufficient detail as to what level you are at

    If you haven't already done so, you will need to install the SP2 and SP3 (SP1 note no longer exists).

    To determine which service pack is currently installed on your computer, follow these steps:

    1. Click Startand then click run.
    2. Copy and paste, or type the following command, and then click OK:
      winver

      A dialog box displays the version of Windows and the service pack that is currently installed on your computer.

    Installation of SP2 - http://support.microsoft.com/gp/xpsp2getinstall

    Steps to take before you install Windows XP Service Pack 3
    http://support.Microsoft.com/kb/950717

  • Having a problem with access to several sites. PLEASE HELP QUICKLY!

    OK so I still really still did nothing with my laptop, but I tried to enter in google, download Itunes and I can not even access the E-system, all my sites search engine don't "work" ive been all day, ive tried already check if Windows 7 is the blocking of sites, my internet itself to have this problem but I can't seem to find out what's wrong , ive used IE9 and Chrome, but the two do not work even if I charge it appears always like it or at least someone to look how to do everything and send me the link...

    Try to run a full system scan with:

    http://www.Microsoft.com/security/scanner/en-us/default.aspx

  • Problems with 'Connection to the Site target' where is the log file?

    Hi all!

    I am VSphere replication deployment to 2 VCenter servers with 1 Center Server in a lab environment. I successfully deployed and saved VRM devices to both VCenter servers. I also installed the SRM agent on the same VCenters servers as well. Both plugins are appearing in both VCenter servers. When I try to connect to the site target either VCenter, I get the following error below after I click 'OK '. What log file should I look at to determine my problem?

    vrm1.pngvrm2.png

    I solved this problem today.

    I had the two configuration of VCenter servers for both use TCP 8080 for HTTP traffic, I have uninstalled/reinstalled VCenter at both ends. I accepted the default 80 TCP HTTP this time and I was able to connect to my remote / targeted VCenter in the connections section.

    What is strange, is that the VRM devices said they used TCP 8080 to save the VRM instance/database on the Service Platform controller (VCenter) and recorded everything very well. I was able to perform very well with configured TCP 8080 local replication.

    My company has sometimes display TCP 80 a vulnerability and try to use other ports where possible.

  • Problem with download of change site with Muse CC

    Hello

    When downloading from my site, everything is out of place on the home page and a product page. I get the following message: "MuseJSAssert: error calling the function switch: TypeError: $(...)." toBrowserWidth is not a function"on these two pages, others are fine.

    I downloaded it initially through Muse. When it did not work, I tried to download with Dreamweaver, Filezilla and Cyberduck, nothing helps... I get the same result every time.

    I checked all my belongings have been correct and that they are.

    It works perfectly when I publish in British Colombia.

    I'm at a loss to know what to do. Can anyone help?

    Thank you!

    Hi again,

    The site is now in ".com" and for this I changed my host.

    I downloaded Muse, empty the cache of my browsers (Safari and Firefox), and it works now!

    The problem must come from my previous host I guess.

    Aish thank you want to study the issue, don't need her now.

    Kind regards

    Pascale

  • successful registration with one of the problems with other sources

    Hello world

    I have two icecube_cur_ownr and icecube_his_ownrpatterns.
    I can access these two SQL schemas, Toad. The TNS entries are as follows



    icecube_cur_ownr =
    (DESCRIPTION =
    (ADDRESS = (PROTOCOL = TCP)(HOST = xxx.xx.xx.xx) (PORT = 1521))
    (CONNECT_DATA =
    (SID = PRIMARY)
    )
    )



    icecube_his_ownr =
    (DESCRIPTION =
    (ADDRESS = (PROTOCOL = TCP)(HOST = xx.x.xx.xxx) (PORT = 1521))
    (CONNECT_DATA =
    (SID = CADS)
    )
    )


    Also I'm able to save icecube_cur_ownr as a source and successfully import the tables in OWB via design center

    problem is with icecube_his_ownr. During the registration process, when I try to test the connection it pops me an error in the results of the tests

    ORA-12170: TNS:connection timeout exceeded

    Ignoring the error, I went to import the tables and the error message popped up is as follows

    SQL exception
    Exception error: SQL Reporsitory
    Class name: cacheMediator
    Method name: getDDentry starting from DB
    Repository error message: ORA-12170: TNS:connection timeout exceeded

    You wonder why the connection is successful for a source, otherwise the other that I followed the same procedure for both cases.


    Could you please guide me to solve this problem.

    Thank you very much
    Sridh

    Hello

    It is different because you connect to diffferent PRIMARY = instances.icecube_cur_ownr, icecube_his_ownr = CADS.

    Have you used the same TNS-entry to connect with the CADS by sqlplus? If you have several oracle_homes you are not really sure what the owb tnsnames.ora uses.

    Then search for other files tnsnames.ora on this machine and check the entry for icecube_his_ownr. May differentiate them.

    Or use the host/port/Service method to create the source location to icecube_his_ownr, not the option of tns.

    Kind regards
    Detlef

  • Need help, a problem with IPSec and NAT - T

    We had a successful between a Cisco remote access client and the ASA connection.   The connection is more data transfer, but the Phase I and Phase II complete successfully.   There are several sections between separate networks for the remote user to the ASA, including hotlines of Verizon and Verizon's ISP.

    Troubleshooting Cisco guides strongly suggests, it is a problem of NAT - T, but when I turn on debugging 254 isakmp and debug ipsec 254, I get only a modest messages on NAT - T, which is "Recieved NAT-Traversal version 02 VID.   This message and connections, are when I disabled it on the ASA of NAT - T.

    If I enable NAT - T on the SAA, the remote client cannot establish Phase I or II; I was not able to gather debugs on this scenerio yet.

    The customer has a second laptop, both of them experience the same problem.  We have ensured that the Tunneling, UPD 4500 is activated.

    I suspect that an intermediary device or Verizon, changed something.

    What should be my next troubleshooting (unfortunately, I can't post the configs)?

    Kind regards

    j

    From my very limited experience, both sides must have the NAT - T enabled, otherwise the side who did not need NAT - t won't be able to read the part of the IP header because it is encrypted.

    Good luck!

    Pedro

Maybe you are looking for