Problem with website Source NAT Site policy
Dear all,
IAM facing issue with source based nat in Site-toSite VPN configuration.
We want to access the remote site server 10.67.1.5 from my main server 192.168.210.224, my 192.168.210.224 server need nat with 10.66.102.178 to go to the outside of the remote site. We have done below the configuration and VPN pahse1 and phase 2 sets up very well, but we are not able to access the remote server 10.67.1.5. Phase 2 set up and only the packages are not wrapping decapsulating. Remote site is seen VPN ending the router and the phase 1 and phase 2 implements.
There is no configured nat exemption. Appreciate urgent help to identify the problem...
We have tunnels from site to site much operational f... but not the tunnels with policy NAT
config
--------
access list acl - OR line 1 permit extended ip 192.168.210.224 host 10.67.1.5 (hitcnt = 0)
allowed to access list acl - NOR line extended to 2 ip host 10.66.102.178 10.67.1.5 (hitcnt = 2)
NAT (inside) 2 192.168.210.224 255.255.255.255
Global 2 10.66.102.178 (outside)
Crypto ipsec transform-set OR esp-3des esp-sha-hmac
card crypto ENOCMAP 22 matches the acl address - OR
card crypto ENOCMAP 22 set counterpart x.x.x.x
card crypto ENOCMAP 22 set transform-set
card crypto ENOCMAP 22 defined security-association life seconds 3600
card crypto ENOCMAP 22 set reverse-road
ENOCMAP interface card crypto outside
tunnel-group x.x.x.x type ipsec-l2l
tunnel-group ipsec-attributes x.x.x.x
pre-shared key *.
======================================================================
12 peer IKE: x.x.x.x
Type: L2L role: initiator
Generate a new key: no State: MM_ACTIVE
ENOCDC-FW03 # sh crypto ipsec his counterpart x.x.x.x
peer address: x.x.x.x
Tag crypto map: ENOCMAP, seq num: 22, local addr: x.x.x.x
access list acl - OR extended permit ip host 10.66.102.178 10.67.1.5
local ident (addr, mask, prot, port): (10.66.102.178/255.255.255.255/0/0)
Remote ident (addr, mask, prot, port): (10.67.1.5/255.255.255.255/0/0)
current_peer: x.x.x.x
#pkts program: 2, #pkts encrypt: 2, #pkts digest: 2
#pkts decaps: 0, #pkts decrypt: 0, #pkts check: 0
compressed #pkts: 0, unzipped #pkts: 0
#pkts uncompressed: 2, comp #pkts failed: 0, #pkts Dang failed: 0
success #frag before: 0, failures before #frag: 0, #fragments created: 0
Sent #PMTUs: 0, #PMTUs rcvd: 0, reassembly: 20th century / of frgs #decapsulated: 0
#send errors: 0, #recv errors: 0
endpt local crypto. : x.x.x.x, remote Start crypto. : x.x.x.x
Path mtu 1500, fresh ipsec generals 58, media, mtu 1500
current outbound SPI: 89BAF49F
current inbound SPI: DB36C4B6
Hello
Please try this nat statement below:
policynat list extended access allowed host ip 192.168.210.224 10.67.1.5
public static 10.66.102.178 (inside, outside) - policynat access list
Here is some reference material for policy nat - http://www.cisco.com/en/US/docs/security/asa/asa82/configuration/guide/nat_overview.html#wp1088419
Thank you
Tarik Admani
* Please note the useful messages *.
Tags: Cisco Security
Similar Questions
-
Anyone know if there is a problem with the "Windows Update" site? As of May 11, 2010 I could not access it for 2 days now. I get an error report indicating that he has a "problem with the site '... Not sure if it's my computer or the site itself. I just need to check updates and download them. I would be grateful for any feedback... Thank you!
~ JeniferIt is without a doubt. There were a few patches published today, and I was able to update all my machines successfully. This looks more like a virus problem. Have you run a virus scan recently? Many times, if you are infected the virus will prevent you to access Windows Update.
You can also use Microsoft Fix It to reset the Windows Update components: http://support.microsoft.com/kb/971058. This could also be your problem.
Let me know how it goes,
Barbara
-
Original title: Internet issues
My mother's laptop has suddenly stopped to access Web sites. I tried to explore, Firefox and Chrome using both wireless and ethernet... connections we both century link and I tried the two houses... my works laptop on both networks. All three browsers connect to the internet, but not all pages opens. I ran the store and he told me that I should look online for more help... which is not the case, but it cannot determine the problem. Any ideas?
Hello
Welcome to the Microsoft community.
I understand that you have a problem with access to Web sites. We apologize for the inconvenience caused to you and appreciates your efforts to try to resolve the problem.
I would like to know the details below to help you better
- Do you receive an error message/code when you access Web sites?
- Do you think that any symbol with exclamation on the icon of this internet access on the taskbar (right)?
I ask you to try the steps in the Microsoft Help article below and check if it helps.
Why can't I connect to the Internet?
http://Windows.Microsoft.com/en-us/Windows/cant-connect-Internet#1TC=Windows-7
Also I ask you to reset TCP/IP and check if it helps.
How to reset TCP/IP using the NetShell utility
http://support.Microsoft.com/kb/299357/en-usKeep us updated on the issue to help you better.
-
Problem began the week last with Verizon's Yahoo email. I can't access it. I get the message on the certificate. Said the security certificate presented by this website was issued for a different website address. can hnts in and out of yahoo, but can not get by e-mail. I have Windows vista 32-bit home. Have tried several things offered by yahoo... Delete history, cookies, defragment the drive hard, etc. Then they said need to ask Verizon. Community sitting there, no response. I had a help line, but what they had me try did not work. Could not do the download help remotely, I tried Java plugin download, has got an error 12031, and a Microsoft fix it but none of it worked. Could not load. Then they said it was having problems with Microsoft windows problems. Error files, corrupted files and certificate & register... I did a few other things too but do not know if someone can help me... Not even if I am in the right place. I really hope that someone can help you.
Hi Patsabo,
I suggest you to check if you are facing the same question in the new administrator account.
Create a new user account-
http://Windows.Microsoft.com/en-us/Windows-Vista/create-a-user-accountIf you are not faced with the same question in a new user account, you can view the link below and use the steps provided to fix a corrupted - user profile
http://Windows.Microsoft.com/en-us/Windows-Vista/fix-a-corrupted-user-profileLet us know the status of the issue. If you need help, please after return. We will be happy to help you.
-
Problem with the download Web site
I'm having a problem when I publish my site Builder at host gator. The following errors are happening, and I don't know if these are problems of vista or not
l\Temp\WER70C1.tmp.version.txt
\Temp\WERC789.tmp.AppCompat.txt
l\Temp\WERC7F7.tmp.mdmp
Thanks advance!Cat hubrich,
You will need to check with the Support of Ewisoft with this question. Mike - Engineer Support Microsoft Answers
Visit our Microsoft answers feedback Forum and let us know what you think. -
Problem with the BlackBerry Developer Site
We are currently experiencing a problem with the integration of BlackBerry ID with the BlackBerry Developer web site. This prevents the developers to create a new BlackBerry ID Token, connecting Issue Tracker and Developer area and potentially other areas that require authentication. Trying to access one of these pages gives the following error.
Sorry, there is a problem with the page you are trying to reach and it cannot be displayed. Please try again later.
Teams are trying to solve the problem. We apologize for the inconvenience.
The problem has been resolved. You should now be able to connect Issue Tracker and generate BlackBerry ID chips again.
-
Problems with the Eclipse Update site
Hello
I try to install the component pack v6.0.0. I'm just following the instructions here
http://NA.BlackBerry.com/eng/developers/javaappdev/javaupdate.jsp
and installation just hangs (or I get the Exception of transfer). I found many messages of forum on the problems with the update site but no solutions. Is this one? Or y at - it another way to install the component pack in eclipse?
Thank you
Sarah
Hi Mark,
Apologies that I was on vacation and never had to deal with that. I just tried to update the software development kits using the same procedure. It must have been a problem with the update site before that it worked well this time.
Thank you
Sarah
-
a problem with the alignment of site on the Tablet and phone version.
I have a problem with the alignment of my site on the Tablet and phone Version of my site.
If you open the Tariffuehrer.com site on the tablet or smartphone, you can see, the page is aligned to the left in the browser. I want the page to Center. I did find an option for it in the backend of muse.
I'd be happy if someone can help me.
Hi Michael,
I can't view your site as it showed error 403,
Can you please recheck the url of your site and repost it so that I can check on this subject.
Kind regards
_Ankush
-
Hello
I updated Firefox on my computer for 13.01. Now, he struggles to read about 2 sites - both are Joomla and based on the model of JA-purity. What happens is that it fails to load the CSS files to do with the side and the top of the Joomla site menus. The file comes up with this:
because its MIME type "text/html", is not "text/css".
Source file: http://extensions.joomla.org/
Line: 0This error does not appear with other browsers and it displays perfectly in fact in all other browsers.
I'm new on this but I read the following article and think it could be my problem
https://developer.Mozilla.org/en/Incorrect_MIME_Type_for_CSS_Files
Where Im stuck, it's that I did not fully understand what to make of this article, if I could get a step by step guide to fix this problem that would be greatly appreciated.
I apologize in advance if the answer lies somewhere here - I have had a look and couldn't get out.
Thank you
AlexI don't see that the error and all style sheets seem to load.
Reload Web pages, and ignore the cache.
- Hold SHIFT and click reload.
- Press 'Ctrl + F5' or 'Ctrl + Shift + R' (Windows, Linux)
- Press 'Cmd + Shift + R' (MAC)
Clear the cache and cookies from sites that cause problems.
"Clear the Cache":
- Tools > Options > advanced > network > storage (Cache) offline: 'clear now '.
'Delete Cookies' sites causing problems:
- Tools > Options > privacy > Cookies: "show the Cookies".
-
Hi all, I recently rebooted my dell xps m140 older and I would get all the updates from microsoft. When I go to this webiste - http://www.update.microsoft.com/windowsupdate/v6/default.aspx?ln=en-us...i click on purpose and he says:-"the website has encountered a problem and cannot display the page you are trying to view. The options provided below may help you solve the problem. "no work around for this?
You must be at Service Pack 3 level before you can use Windows updates.
How to obtain the latest Windows XP service pack
http://support.Microsoft.com/kb/322389You have not provided us with sufficient detail as to what level you are at
If you haven't already done so, you will need to install the SP2 and SP3 (SP1 note no longer exists).
To determine which service pack is currently installed on your computer, follow these steps:
- Click Startand then click run.
- Copy and paste, or type the following command, and then click OK:winver
A dialog box displays the version of Windows and the service pack that is currently installed on your computer.
Installation of SP2 - http://support.microsoft.com/gp/xpsp2getinstall
Steps to take before you install Windows XP Service Pack 3
http://support.Microsoft.com/kb/950717 -
Having a problem with access to several sites. PLEASE HELP QUICKLY!
OK so I still really still did nothing with my laptop, but I tried to enter in google, download Itunes and I can not even access the E-system, all my sites search engine don't "work" ive been all day, ive tried already check if Windows 7 is the blocking of sites, my internet itself to have this problem but I can't seem to find out what's wrong , ive used IE9 and Chrome, but the two do not work even if I charge it appears always like it or at least someone to look how to do everything and send me the link...
Try to run a full system scan with:
http://www.Microsoft.com/security/scanner/en-us/default.aspx
-
Problems with 'Connection to the Site target' where is the log file?
Hi all!
I am VSphere replication deployment to 2 VCenter servers with 1 Center Server in a lab environment. I successfully deployed and saved VRM devices to both VCenter servers. I also installed the SRM agent on the same VCenters servers as well. Both plugins are appearing in both VCenter servers. When I try to connect to the site target either VCenter, I get the following error below after I click 'OK '. What log file should I look at to determine my problem?
I solved this problem today.
I had the two configuration of VCenter servers for both use TCP 8080 for HTTP traffic, I have uninstalled/reinstalled VCenter at both ends. I accepted the default 80 TCP HTTP this time and I was able to connect to my remote / targeted VCenter in the connections section.
What is strange, is that the VRM devices said they used TCP 8080 to save the VRM instance/database on the Service Platform controller (VCenter) and recorded everything very well. I was able to perform very well with configured TCP 8080 local replication.
My company has sometimes display TCP 80 a vulnerability and try to use other ports where possible.
-
Problem with download of change site with Muse CC
Hello
When downloading from my site, everything is out of place on the home page and a product page. I get the following message: "MuseJSAssert: error calling the function switch: TypeError: $(...)." toBrowserWidth is not a function"on these two pages, others are fine.
I downloaded it initially through Muse. When it did not work, I tried to download with Dreamweaver, Filezilla and Cyberduck, nothing helps... I get the same result every time.
I checked all my belongings have been correct and that they are.
It works perfectly when I publish in British Colombia.
I'm at a loss to know what to do. Can anyone help?
Thank you!
Hi again,
The site is now in ".com" and for this I changed my host.
I downloaded Muse, empty the cache of my browsers (Safari and Firefox), and it works now!
The problem must come from my previous host I guess.
Aish thank you want to study the issue, don't need her now.
Kind regards
Pascale
-
successful registration with one of the problems with other sources
Hello world
I have two icecube_cur_ownr and icecube_his_ownrpatterns.
I can access these two SQL schemas, Toad. The TNS entries are as follows
icecube_cur_ownr =
(DESCRIPTION =
(ADDRESS = (PROTOCOL = TCP)(HOST = xxx.xx.xx.xx) (PORT = 1521))
(CONNECT_DATA =
(SID = PRIMARY)
)
)
icecube_his_ownr =
(DESCRIPTION =
(ADDRESS = (PROTOCOL = TCP)(HOST = xx.x.xx.xxx) (PORT = 1521))
(CONNECT_DATA =
(SID = CADS)
)
)
Also I'm able to save icecube_cur_ownr as a source and successfully import the tables in OWB via design center
problem is with icecube_his_ownr. During the registration process, when I try to test the connection it pops me an error in the results of the tests
ORA-12170: TNS:connection timeout exceeded
Ignoring the error, I went to import the tables and the error message popped up is as follows
SQL exception
Exception error: SQL Reporsitory
Class name: cacheMediator
Method name: getDDentry starting from DB
Repository error message: ORA-12170: TNS:connection timeout exceeded
You wonder why the connection is successful for a source, otherwise the other that I followed the same procedure for both cases.
Could you please guide me to solve this problem.
Thank you very much
SridhHello
It is different because you connect to diffferent PRIMARY = instances.icecube_cur_ownr, icecube_his_ownr = CADS.
Have you used the same TNS-entry to connect with the CADS by sqlplus? If you have several oracle_homes you are not really sure what the owb tnsnames.ora uses.
Then search for other files tnsnames.ora on this machine and check the entry for icecube_his_ownr. May differentiate them.
Or use the host/port/Service method to create the source location to icecube_his_ownr, not the option of tns.
Kind regards
Detlef -
Need help, a problem with IPSec and NAT - T
We had a successful between a Cisco remote access client and the ASA connection. The connection is more data transfer, but the Phase I and Phase II complete successfully. There are several sections between separate networks for the remote user to the ASA, including hotlines of Verizon and Verizon's ISP.
Troubleshooting Cisco guides strongly suggests, it is a problem of NAT - T, but when I turn on debugging 254 isakmp and debug ipsec 254, I get only a modest messages on NAT - T, which is "Recieved NAT-Traversal version 02 VID. This message and connections, are when I disabled it on the ASA of NAT - T.
If I enable NAT - T on the SAA, the remote client cannot establish Phase I or II; I was not able to gather debugs on this scenerio yet.
The customer has a second laptop, both of them experience the same problem. We have ensured that the Tunneling, UPD 4500 is activated.
I suspect that an intermediary device or Verizon, changed something.
What should be my next troubleshooting (unfortunately, I can't post the configs)?
Kind regards
j
From my very limited experience, both sides must have the NAT - T enabled, otherwise the side who did not need NAT - t won't be able to read the part of the IP header because it is encrypted.
Good luck!
Pedro
Maybe you are looking for
-
Pavilion g6: HP laptop, will start the first time, starts randomly
Hello I have a laptop HP Pavilion g6, running Windows 8.1. He often don't dΘmarre when I press the power button. He goes to the HP laoding screen with points going around, but there nothing happens. I try again and the same thing happens. Eventually
-
system to address 0x3bc processes have just crashed, disabling required key
system to address 0x3bc processes have just crashed, disabling required key pls send key deactivation
-
Hello community, I just got a new Latitude 10 ST2, and I really appreciated the help until after that I updated for Windows 8.1 and played some Diablo 2. For some reason, my brightness is now always very low, regardless of whether the Adaptive bright
-
WinHelp does not work on Windows 7, even after enforcement KB917607
I have installed Windows 7 Prof. I need to read .hlp files. I installed KB917607 on my 64-bit computer. I then applied the registry fix and now get the error message. "Cannot find or load RoboEx32.dll file. This file must be copied to C:/Windows/S
-
The C - Series (TC5) ditch company directory SSH list content
Hi, how can I list the contents of a corporate directory on the c-series ssh device hollow? xcommand directory search PhonebookType: Corporate (shows only the files) xcommand search phone book (only the local show 'my contacts' directory). I have a c