Second ASA connects to the router

I had another thread going, but when I passed my current blocking upward, I marked the thread as answered, so I didn't know if I should start a new one or continue on...

I tried to go through this troubleshooting doc, but I still can't understand it.

By turning on debugging for the 2811, I do see something.

See debugging

Encryption subsystem:
Crypto ISAKMP debug is on
Crypto ISAKMP debug error is on
Crypto IPSEC debugging is on
Crypto IPSEC error debugging is on

#show crypto session
Current state of the session crypto

Interface: FastEthernet0/1
The session state: UP-ACTIVE
Peer: port of 108.x.x.x 500
IKE SA: local 64.x.x.x/500 remote 108.x.x.x/500 Active
FLOW IPSEC: allowed ip 192.168.26.0/255.255.255.0 192.168.27.0/255.255.255.0
Active sAs: 0, origin: card crypto
FLOW IPSEC: allowed ip 10.130.15.0/255.255.255.0 192.168.27.0/255.255.255.0
Active sAs: 0, origin: card crypto
FLOW IPSEC: allowed ip 10.131.16.0/255.255.255.0 192.168.27.0/255.255.255.0
Active sAs: 2, origin: card crypto
FLOW IPSEC: allowed ip 172.20.15.0/255.255.255.0 192.168.27.0/255.255.255.0
Active sAs: 0, origin: card crypto
FLOW IPSEC: allowed ip 172.21.16.0/255.255.255.0 192.168.27.0/255.255.255.0
Active sAs: 0, origin: card crypto
FLOW IPSEC: allowed ip 10.21.0.0/255.255.255.0 192.168.27.0/255.255.255.0
Active sAs: 2, origin: card crypto
FLOW IPSEC: allowed ip 10.30.18.0/255.255.255.0 192.168.27.0/255.255.255.0
Active sAs: 2, origin: card crypto

Interface: FastEthernet0/1
The session state: UP-ACTIVE
Peer: port of 99.x.x.x 500
IKE SA: local 64.x.x.x/500 remote 99.x.x.x/500 Active
FLOW IPSEC: allowed ip 192.168.27.0/255.255.255.0 192.168.26.0/255.255.255.0
Active sAs: 0, origin: card crypto
FLOW IPSEC: allowed ip 10.130.15.0/255.255.255.0 192.168.26.0/255.255.255.0
Active sAs: 0, origin: card crypto
FLOW IPSEC: allowed ip 10.131.16.0/255.255.255.0 192.168.26.0/255.255.255.0
Active sAs: 2, origin: card crypto
FLOW IPSEC: allowed ip 172.20.15.0/255.255.255.0 192.168.26.0/255.255.255.0
Active sAs: 0, origin: card crypto
FLOW IPSEC: allowed ip 172.21.16.0/255.255.255.0 192.168.26.0/255.255.255.0
Active sAs: 0, origin: card crypto
FLOW IPSEC: allowed ip 10.21.0.0/255.255.255.0 192.168.26.0/255.255.255.0
Active sAs: 2, origin: card crypto
FLOW IPSEC: allowed ip 10.30.18.0/255.255.255.0 192.168.26.0/255.255.255.0
Active sAs: 2, origin: card crypto

Cryptography of show, for me, it seems that it works, but 192.168.27.x is not accessible.

The ASA original is still connected, I can post more details/config is necessary.

The original thread is below...

https://supportforums.Cisco.com/thread/2167470?TSTART=0

(1) your last ping test does not work when you ping from the ASA. You should test from an internal PC which is part of the definition of encryption.

(2) in the "crypto ipsec to show his ' you see that this ASA revenue traffic, but nothing deciphered. So most likely the other end of the tunnel does not send anything back.

How to get:

Show us the real Crypto - and routing-config of the IPSec peer.

--
Don't stop once you have upgraded your network! Improve the world by lending money to low-income workers:
http://www.Kiva.org/invitedBy/karsteni

Tags: Cisco Security

Similar Questions

  • iMac connects to the router of Linkysys WRT1900ac

    I am trying to help a friend get his iMac 12.1, that is running 10.11.4, to connect to a new Linksys WRT1900ac router.  The router is a novelty in this House, is in the same room of 10 x 12, as the computers listed below, and the installer was using the Linksys recommends the method, which is to let the Linksys to make adjustments.

    Here are its configuration;

    The router is connected to a cable modem, ISP and the following devices are connected to the router and works well;

    Via ethernet

    Windows 10 PC

    AT & T cell phone extender

    Ooma VOIP

    Wireless

    iPhone

    iPad

    Notebook PC

    While troubleshooting my MacBook 5.1 also allows to connect without problems to the Linksys router.

    Note that her iMac connects without problem to the wifi network Netgear Guest unprotected from its neighbor.  I also installed in his room my 1st generation Airport Express, which has added a second wifi network but without access to the internet and his iMac connect without problems to this wifi.

    Here are the steps I took to try to solve this problem, and they were unsuccessful;

    ➔ Scanned for malware/adware with Malwarebytes and found nothing.

    ➔ Ransacked after the files in/Library/Preferences/SystemConfiguration and restarted

    com Apple.Airport.Preferences.plist
    NetworkInterfaces.plist
    Preferences.plist

    ➔ When the previous did not work I trashed all the files in the folder/Library/Preferences/SystemConfiguration except "com.apple.boot.plist', which would not remove and rebooted

    ➔ Created a second user account and still not able to connect to the Linksys router

    ➔ Repaired permissions

    ➔ Created a new location in System Preferences > network and added the OpenDNS addresses and in the material value MTU 1453

    ➔ restarted in safe mode and not still could not connect

    Firmware on the router Checked ➔, which is updated

    ➔ Reset SMC

    ➔ reinstalled El Capitan via the App Store

    That's all I could think about.  I'm puzzled.

    I checked the router and everything seems ok, but I'm no expert.  There may be something I'm not contagious.  I have seen that he has no MAC filtering set up in the router, so this isn't everything.

    Please tell me if there is something that I'm on.  Is there something in the router, that I need to change?  There are other files in the Mac, I need to delete?  Is there any other troubleshooting steps I can take to identify this problem.

    Any help would be appreciated as it is a total mystery to me.

    There are a lot of variables, but start with some basic info. So on her iMac, if you click the wifi at the top right, you can see his router listed?

  • M40X connects to the router Netgear DG834G wireless

    Message on the toolbar and warnings are; No limited connectivity or. Improved Intel Pro wireless 2200BG driver worm 9.0.4.8 without success.
    I have another laptop with a USB wireless network too and that works very well.
    I was able to connect to the router via the ethernet card.
    Been on Netgear, and the router works well.
    Any ideas, anyone please...

    Hello

    I guess that your laptop uses the map Intel 2200BG wireless.
    You will find a lot of questions and problems with this card intel.
    Mainly the graphics driver update will solve these issues.
    You can also check the power save mode settings in the properties of the wireless card. Go to the Device Manager, choose the wireless card and go to properties. In the second Advanced tab you should find the Power save mode option. Please switch off (off)

    I put t know where you download the driver, but you must use the latest version on the Intel site.

  • Unable to connect to the router

    -Please ignore this message: I did not wait enough to do the factory reset. It seems that launch a factory reset without waiting for 10 seconds only restarts the router.

    Hello

    Today I tried to connect to my router (I do not use it for a few years) and it didn't work at all.

    Initially, I plugged it in just 2 RJ45 cables: one for internet, one for the PC. The computer could not connect to the router (DHCP failed).

    I then restored the factory settings and tried again: same thing, the computer could not find the router via DHCP.

    I tried to force an IP address (IP: 192.168.1.5, mask: 255.255.255.0 Gateway: 192.168.1.1).

    By forcing the INVESTIGATION period, I was able to connect to the router, but when I tried connect to 192.168.1.1 with admin/password, it wouldn't let me (bad password - don't forget I restored it to factory settings, several times actually). The address http://routeurlogin.net/ is not found (404) and I was unable to go on websites (404). A curious thing is, using this connection, I was able to connect to Skype (and send/receive messages), although the sites Web could not be reached from a browser.

    I'm running out of ideas to solve the problem, but I suspect a hardware problem, so any help would be welcome.

    Yes he did.

    I couldn't find an option to delete my message, otherwise I would have done it.

  • Connects to the router, but cannot send or receive data

    I have a WRT54G.  I can find the network and connect to the router, but I can't send or receive data.  I tried to connect directly to the router and I still not able to send or receive data. Both computers on the router has the same problem.  I did a reset the router back to the settings by default and still no luck.  Any thoughts?  Thanks in advance for the help.

    The first thing you can try is when you the Modem and the router is connected to the other, disconnect the power from the router and Modem, wait 30 seconds and then plug in the power to the Modem and once all the lights are solid, then connect the power supply to the Linksys router, now check if you are able to go online. If still no then...

    Who is your ISP. So I think you need to re - configure all settings of your router again.

    If your Internet Service is cable follow this link

    If your Internet Service is DSL follow this link

  • Unable to connect to the router (BEFSR41 V4.0)

    I have a Linksys BEFSR41 (Version 4.0) wired router and I am not able to connect to it. It has been in storage (the top of a closet shelf) for the past two years and when it when it was still used it worked like a pro.

    I used the downloaded from the site Web of Linksys router configuration utility to install it, and when it gets to the final stage, he says that it cannot connect to the router. Try to go to 192.168.1.1 translates into a (very long) network timeout.

    I have reset the router several times (retained in the for more than 10 seconds reset button) and have had no result. All the lights on the front of the router work normally.

    I already checked and I'm set up to get the IP addresses of network automatically rather than assigning a static.

    Any help appreciated,
    ~ Darxide

    Number set by putting the ADSL modem in bridged Ethernet mode.

  • Motherboard has 2 ethernet ports. both are connected to the router, only 1 is sending/receiving information.

    OK, my onderstanding I should be able to define a place for sending and one for receiving. How I do that... Both are connected to the router. If I unplug one, the other to rest and then work. But my? is how to work both for sending / and the reception. I have an ASUS Crosshair 590 MB, internet by cable that goes from router then to computer... the any 2 are connected to the router. SOMEONE HAS IT PLS! Can help to ya? THX, Nolan

    Hello

    Yes, this problem will cause a problem psychological too many users.

    Some vendors of motherboard put this second NETWORK card, because it cost them 30 cents to do this, and it seems not good for marketing.

    While users cannot let go of the poor port (30 cents) sitting there with nothing to do. (;_;)

    Jack, MVP-Networking. WWW.EZLAN.NET

  • Printer Hp6700: unable to connect to the router wireless D - Link DI-514 when SSID Broadcast is set to no.

    HP6700 printer: unable to connect to the router wireless D - Link DI-514 when the router Broadcast SSID is set to no. My MAC laptop and HP laptop both work with the set SSID on no. If I change the router Wireless SSID Broadcast is YES, then the printer HP6700 can connect to the wireless router. I set up the printer it saying that the SSID and password have been, the same as both of my laptops, but it connects ever, unless I have change the router to broadcast the SSID. Help!

    Have you tried to update the firmware on the DI-514?

    You can also try to set a static IP address on the printer, and then assign the printer to the list of DHCP static in the interface of the router.
    To give a static IP address to your printer:
    -Print a the front of the printer Network Setup Page. Note the IP address of the printer.
    -Enter the IP address in a browser to reveal the internal settings of the printer.
    -Choose the network tab, then wireless along the left side, then on the IPv4 tab.
    -On this screen, you want to set a manual IP address. You must assign an IP address outside the range that the router sets automatically (called the DHCP range). If you do not know the range, change the last set of numbers (those after the last '.') 250
    -Apply the subnet 255.255.255.0 (unless you know it's different, if so, use it)
    -Enter the IP of your router (on the Page of the Network Config) for the gateway.
    -Enter for the first DNS 8.8.8.8 and 8.8.4.4 for second DNS. It's Google DNS. You can choose a different external DNS if you wish.
    -Click 'apply '.
    Now, stop the router and printer, start the router, wait, and then start printing.

    After that you remove and re - add the printer to your Mac.

    Show support by clicking on the blue Kudos star in the post that solved your problem. Doing so will help the other members of the forum their solutions also.

  • 9.3.4 disabled wifi on an Ipad, but it connects to the router. Just don't download at all

    IPad was working fine, but I've updated to 9.3.4. Now Wireless does not work. Shows connected to the router, but nothing happens, but say unable to connect to the server, error trying to access the internet or by mail. Also turn continuous flashing VPN gray to green, then again, but we have never set up a virtual private network. Don't know if it is connected. Have you tried

    1 disconnection / reconnection to 2 routers that work very well for other devices

    2 reset wireless via settings > general > reset > reset network settings and then hang up again

    3 airplane mode on, wait a few minutes, then shut off again

    Overall, the router will connect to any time, we put the password, but there is no transfer of data. 3 other devices work fine with the router. Don't know where to go from here, or if it is possible to back out from the upgrade. Anyone else having this problem? A research increase the same problem.

    Thank you

    Anything that causes the problem is not specifically 9.3.4, which fixes just a security breach. Have you tried to restart routers?

  • Firefox prevents the connection from the router

    WRT120N router Linksys-Cisco, Firefox 22.0

    I discovered that my router rejects all attempts at connection (192.168.0.1, 401 authentication failure "browser can not perform authentication or authentication failed") when you browse to it from Firefox. It allows the connection when the attempt is made of Chrome.

    I remember having long ago something similar with Firefox, but resolved by disabling the option "say it me not to follow the sites", following what connections made; just looked and it is still not verified - if this isn't it.

    I looked a the packet capture and the password IS sent to the router, but it rejects the connection.

    Any ideas?

    "BUT IT WORKS CORRECTLY BOOTED IN SAFE MODE."
    Which prompted me to check the extensions.
    I called, guess what... TAKE STEPS TO TRACK ME.

    (Why is there such an extension if it is built in function?)

    Disabling, allowing the router to connect! I don't know why twice now, try to activate Do not not track eliminated the possibility to connect to the router... but this is the solution.

  • HP Envy 4500: Printer connected to the router, but will not print wireless Macbook

    I want my wireless printer to work on my macbook, but I can't. I tried setting up on the HP utility to connect with the router as the mac and printer on but it does not work! It indicates that the download was successful, but the device was not reachable. I don't really know where to go from here and any help would be really appreciated. Thank you.

    Hey @miriamnimmo,

    Welcome to the Forums of HP, I would be happy to help you! I understand that you have the printer set up on your network, but the software says that the device is not accessible. Sometimes the IPv6 may interfere with the connection, and I suggest we disable that before anything else. On the fornt of the printer Panel, scroll down to and then select Wireless. In the wireless Menu, select Advanced settings, then IPv6 and.

    Now we are going to let the router and unplug the power cable (NOTE: do not reset the router), then do the same with the printer and shut down the computer. After a minute, plug in the router, wait to fully turn on, then plug the printer back in and wait for the wireless light become solid. Once the router and the printer are on, go ahead and re - turn on the computer. This will refresh the network connection.

    Please let me know if this solves the problem by marking your post as solved (click on Accept as Solution button below). If the problem persists, let me know, I'll watch for your reply.

    See you soon!

  • 15 - r074TU: laptop does not connect to the router

    Day sum... .my laptop (model No. 15r074TU) with window 8.1 does not connect to the router that is D-link

    I uninstalled my driver reinstalled again, but it didn't work... even if I formatted my laptop, reconfigure the router and... done with all possible measures to overcome this problem, but have ultimately failed. Please suggest ways to tackle this problem as soon as possible...

    Follow the wizards in the following forum sticky and troubleshooting.

    http://h30434.www3.HP.com/T5/notebook-wireless-and-networking/common-fixes-for-wireless-connectivity-issues/m-p/4831601#M86871

  • Unable to connect to the router WLan - Satellite L300D

    Please help me so that I have still a few hairs left!

    I installed WLAN driver on my laptop Satellite L300D with Vista Home installed.

    I see my network in the available connections, but when I go to connect, it will not connect.

    My other two desktop computers can connect to the router without a problem.

    Any suggestions?

    Thank you
    Neil

    Hello

    I think that you didn t try updates. Right?
    Therefore, my first recommendation would be an update of the BIOS and driver WLan.

    Check the current version of the BIOS that is available on your laptop. If the latest version has been released then update the BIOS.
    In addition, to download the latest WLan driver from the Toshiba WLan portal and to update:
    http://APS2.toshiba-tro.de/WLAN/

    On this Wlan site, you will find three different WLan drivers for three types of WLan cards. First check your wireless network card, and then use the right driver!

    See you soon

  • Samsung S6 connects to the router but no internet

    When I switched to xfinity I bought a C6300. I had problems with the first not allowing my NAS to connect so I exchanged against another. My phone would connect to the router and work fine for awhile then lose Internet connectivity. The only way to get it back is to reboot the router. I tried several different units, and I am now on a C3700. The problem still exists and seems to be deteriorating. All of the suggestions.

    I solved my problem by replacing the Netgear with a Zoom. It was the only one that I could find who said it would work with Android. I hope that Netgear will get things straightened.

  • Unable to connect to the router (even after reset)

    I'm really frustrated, and I hope that this community can provide an answer. After all the hype around this router, it is he who gave me the most trouble.

    About a month and a half... completely randomly it seems to me, I could not connect to the router more. Not through intellectual property, routerlogin.net/com...nothing. It just says: cannot display the page. I did everything I could possibly think, tried all of the suggestions I could find here and elsewhere and still nothing would work.

    I finally did a hard reset and obviously lost all my settings... and RIGHT AFTER the hard reset after upgrading the firmware, I can't connect to the router again. This could be the cause? Is there a way around it?

    The router worked fine until about a month and half ago. Then I stopped being able to connect to the admin page. Several resets hard did nothing.

    I ended up RMA'ing it and the new replacement works fine (for now).

Maybe you are looking for