Several VPN first L2L works, still acting strangely

Hello

I use a Cisco 1921. I created 3 VPN L2L. Although I can get all 3 upward tunnel, I can in the case of a ping the LAN IP of the router and the 2nd on since the subnet of peers, but not vice versa. If anyone can make sense of what would be great... I can see the ACL being fired,

Annoying as the first VPN is in place and working well, in both directions... Would really appreciate a new pair of eyes...

NAT, blocking ACL works fine too...

Glasgow #show access lists

Expand the access IP 101 list

10 permit ip 172.16.20.0 0.0.0.255 192.168.0.0 0.0.0.255 (966 matches)

Extend the 104 IP access list

10 permit ip 172.16.20.0 0.0.0.255 192.168.3.0 0.0.0.255 (3606 matches)

Extend the 105 IP access list

10 permit ip 172.16.20.0 0.0.0.255 192.168.100.0 0.0.0.255 (3609 matches)

Extend 175 IP access list

10 deny ip 172.16.20.0 0.0.0.255 192.168.0.0 0.0.0.255 (2109 matches)

20 deny ip 172.16.20.0 0.0.0.255 192.168.3.0 0.0.0.255 (3616 matches)

30 deny ip 172.16.20.0 0.0.0.255 192.168.100.0 0.0.0.255 (3639 matches)

IP 172.16.20.0 allow 40 0.0.0.255 everything (1549 matches)

Here's the (sanitized) snippits sorry I hate so lazy reading peoples config dumps...

crypto ISAKMP policy 1

BA 3des

preshared authentication

Group 2

ISAKMP crypto key demopassword address 146.xx.xx.xx

ISAKMP crypto key demopassword address 212.xx.xx.xx

ISAKMP crypto key demopassword address 188.xx.xx.xx

!

!

Crypto ipsec transform-set esp-3des-sha1 esp-3des esp-sha-hmac

!

l2l 99 ipsec-isakmp crypto map

the value of 188.xx.xx.xx peer

the transform-set esp-3des-sha1 value

match address 101

l2l 100 ipsec-isakmp crypto map

the value of 212.xx.xx.xx peer

the transform-set esp-3des-sha1 value

match address 105

l2l ipsec 101-isakmp crypto map

the value of 146.xx.xx.xx peer

the transform-set esp-3des-sha1 value

match address 104

!

interface GigabitEthernet0/1

WAN description

IP address 213.xx.xx.xx 255.255.255.xx

NAT outside IP

IP virtual-reassembly in

automatic duplex

automatic speed

L2L card crypto

!

overload of IP nat inside source list 175 interface GigabitEthernet0/1

!

access-list 101 permit ip 172.16.20.0 0.0.0.255 192.168.0.0 0.0.0.255

access-list 104. allow ip 172.16.20.0 0.0.0.255 192.168.3.0 0.0.0.255

access-list 105 allow ip 172.16.20.0 0.0.0.255 192.168.100.0 0.0.0.255

access-list 175 deny ip 172.16.20.0 0.0.0.255 192.168.0.0 0.0.0.255

access-list 175 deny ip 172.16.20.0 0.0.0.255 192.168.3.0 0.0.0.255

access-list 175 deny ip 172.16.20.0 0.0.0.255 192.168.100.0 0.0.0.255

access-list 175 allow ip 172.16.20.0 0.0.0.255 any

For the second tunnel (192.168.100.0/24), as you can see from the output, it program, but no decaps counter which means, traffic is sent to the remote end, however, nothing's coming back. So it could have been blocked at the remote end since your first tunnel works very well, I guess nothing is blocking it on your side.

Tags: Cisco Security

Similar Questions

  • My computer crashed two weeks ago and all software had reinstalled in another HD. The first hard drive still has all the files and are readable. Where can I find the old catalog fall back all my work?

    My computer crashed two weeks ago and all software had reinstalled in another HD. The first hard drive still has all the files and are readable. Where can I find the old catalog fall back all my work?

    My lightroom was great before the crash to work and I have a lot of work still pending.

    You will need the catalog file and all your images. If you have also stored your images on which crashed HDD you will need to copy them as well.

    The default location of the LR catalog file is in your user name folder in the folder on the ROOT of the drive users

  • Networks VPN NAT l2l problem-Dup-HELP!

    I use a router IOS as a VPN L2L device to connect my site to several different customer locations, some of them use the same internal IP addresses.  These VPNS have been working well.

    I recently added another client to this system and I am now having a problem with the new configuration.  With this configuration, I have NAT my internal addresses.  NAT works correctly, but it NAT my bad common NAT addresses and therefore do not generate the tunnel.

    My internal IP 10.10.x.x

    incorrect NAT pool 10.129.x.x

    decent NAT pool 10.99.x.x

    Help... :))

    Thank you

    The problem is simple. You have almost an identical ACL for two guests. As the first NAT rule has been added previously, it comes into play. To resolve this issue, you must set explicit host/subnet destination match instead of 'none' keyword.

    For example like this:

    ip access-list extended ME-CRYPTO-ACL

      permit ip 10.129.40.0 0.0.0.255 host 10.10.131.63

    ip access-list extended ME-NAT-ACL

      permit ip 10.10.10.0 0.0.0.255 host 10.10.131.63

    ip access-list extended SA-CRYPTO-ACL

      permit ip 10.96.21.0 0.0.0.255 host 10.99.2.95

    ip access-list extended SA-NAT-ACL

      permit ip 10.10.10.0 0.0.0.255 host 10.99.2.95

    Another solution is more complex and harder to understand (and explain), you can use Virtual models with tunnel-protection for each customer, VRF and NAT for common services.

    ___

    HTH. Please rate this post if this has been helpful. If it solves your problem, please mark this message as "right answer".

  • My apostrophe key acted strange since yesterday. Instead of typing an apostrophe, it's rather type a slash

    Hello, my apostrophe key acted strange since yesterday. Instead of typing an apostrophe, it's rather type a slash, placing the position where I type at the bottom of my sentence (don't know what his name), and sometimes it sticks all what I have on my Clipboard in where it is. It was very irritating at this point and I was not able to find anything that helps anywhere else. I tried to restart my computer earlier, but without success.

    This kind of behavior is usually the first sign of a faulty keyboard.  Try another keyboard plugged into a USB port to check.

    If yours is a desktop computer, replace the keyboard.  Certainly simple and cheap

    If yours is a laptop, you will need the services of a competent technician with the RIGHT part.  Beware, there are several laptop keyboard parts which are similar, but not the right ones.  This will probably cost you more than $100.  You should consider a solution much easier and less costly - buy and use an external keyboard.

  • DW acting strange - does code view

    My Dreamweaver CS3 started acting strangely since I've upgraded to a new version of CS3 studio.
    I worked with CS3 for a while now without needing too much adjustment of DW8.
    However, I just bought a new computer and I had to reinstall all my software.


    On the new box, DW is very strange:

    (1) when I'm in page layout mode and click on an item to go to the corresponding line of the code of the item that is no longer, it goes to the line. However, it does when I right click on it. It's a bit embarrassing because it also opens the context menu at the same time.

    (2) when I'm in mode code (which is 99% of the time) and I click on an item, it shows me is no longer the corresponding CSS rule in the CSS pane. Once again, if I click right sometiomes it works, but it is not reliable in any event. Sometimes it works if I double click, but most of the time it isn't.


    (3) the icon of comment in the toolbar code is often dimmed. No reason so that I can see and every so often he work wil on the same line of code where it did not a minute before.

    I've raked the preferences line by line, without success.
    On my old computer I never had problems like that. I find it very strange and it's crimping considerably my workflow. Did someone knowing theis behavior or how to fix it?

    > If I reinstall I will lose all of it.

    It's unfortunate, but maybe it's your only option.

    > 20 hours

    Seems a bit long for me. I uninstalled CS3 at least 20 times and none
    has taken more than two hours, with complementing most much faster than that.

    > If anyone has experienced this before, I'm all ears. Thank you

    Why not communicate directly with Adobe and use one of your support individualized
    incidents?

    http://www.Adobe.com/support/programs/Dreamweaver/index.HTML?tab:contact = 1

    --
    Murray - ICQ 71997575
    Adobe Community Expert
    (If you * MUST * write me, don't don't LAUGH when you do!)
    ==================
    http://www.dreamweavermx-templates.com - template Triage!
    http://www.projectseven.com/go - DW FAQs, tutorials & resources
    http://www.dwfaq.com - DW FAQs, tutorials & resources
    http://www.macromedia.com/support/search/ - Macromedia (MM) Technotes
    ==================

    "corradoconti" wrote in message
    News:f8jbp5$9EH$1@forums. Macromedia.com...
    > Thank you for your response. Indeed, a new facility was something that I was
    > contemplating. The only problem is that, according to other messages I read
    > here
    > and there, unistalling the CS3 studio takes a long time (a poster
    > claimed it took him nearly 20 hours - maybe it was exaggerated but
    (> anyway...).
    > As I have already set up my preferences and several plug-ins
    > Illustrator and Photoshop. If I reinstall I will lose all of it.
    >
    > As far as I know, the Adobe CS3 installer doesn't let you choose
    > and
    > choose the desired installation. It's all or nothing. Am I wrong? Or is
    > It
    > something to uninstall and reinstall the app only one?
    >
    > By the way, I have a copy of Dreamweaver CS3, I bought mine
    > (a
    > update since DW8 before this company hired me and gave me their at the site level
    (> license) but I am wary of installing it on the present Studio
    > installation. For
    > one thing it can just keep preferences corrupt for another I don't have
    > idea
    > how it would play with the existing installation of Studio on the other
    > programs.
    >
    > If anyone has experienced this before, I'm all ears. Thank you
    >

  • Keyboard started acting strange on my laptop satellite

    I have Toshiba Satellite and its working fine, but recently my keyboard started acting strange (he has a period). I play NFS undercover (Bioshok, GTA) and keyboard works fine, but when I m playing WarCraft 3 Frozen Throne I have a terrible lag (0.5 ~ 1.5 sec).
    Please help me.

    It is bc of video card?
    My computer spec:
    XP pro, CPU Geniune Intel (r) 585-2, 16GHz
    RAM: 1, 5 GB
    DirectX 9
    Mobile Intel (r) 4 series express chipset family 768 MB of RAM
    DirectDraw is running
    Direct3D is enabled

    Hey,.

    I think that anyone here can answer why it s does happen no more. As you may already know, not for all the problems, there is an explanation. ;)

    Just be happy that your issue is resolved and have funds with your laptop! :)

  • A connection VPN (PPTP), who worked previously no longer works.

    original title: VPN works not

    PROBLEM:

    I'm running Vista 64 Ultimate SP2, with all Microsoft Updates applied.  My original CD is pre - SP1.
    A connection VPN (PPTP), who worked previously no longer works.
    I think that the problem is related to an installation of Virtual PC or iTunes, but I can't confirm either way.
    Unfortuantely, I do not have a restore point dated to before the problem.

    DETAILS OF THE PROBLEM:

    When I'm viewing the network drivers in Device Manager, the following drivers displayed an error:

    Miniport Wan (IP)
    Miniport Wan WAN (IPv6)
    Miniport Wan (Network Monitor)
    Miniport WAN (PPPOE)
    Miniport Wan WAN (PPTP)

    The error for each text is: "Windows cannot load the driver for this hardware device. The driver may be corrupted or missing. (Code 39) »

    The following drivers do NOT display an error:

    Miniport Wan WAN (L2TP)
    Miniport WAN (SSTP)

    SOLUTIONS ALREADY ATTEMPTED:

    Uninstalling Virtual PC has not solved the problem.
    Uninstall device drivers and re - install it as described in the following web pages did not help the problem:

    http://www.chicagotech.NET/NetForums/viewtopic.php?p=988&SID=39aeb8e5e43c459
    http://www.howtonetworking.com/Vista/rebuildminiport.htm
    http://www.experts-exchange.com/software/System_Utilities/Remote_Access/VPN/Q_24291900.html

    In general, I am able to uninstall device drivers, but re-plant fails (sometimes reported as successful, sometimes not).

    I have presented a problem report on the failure of resettlement of Microsoft (including the following in the log files), but have received no solution:

    DMIC8E.tmp.log.XML
    LOGC9F.tmp
    netrasa.inf
    Setupapi.app.log
    Setupapi.dev.log

    I noticed that the device (loser) of WAN Miniport (PPTP) lists two files: 'ndistapi.sys' and "raspptp.sys", of which the first is NOT digitally signed, but the second is.  However, the peripheral Miniport WAN (L2TP) (work) lists only one file: "rasl2tp.sys" which is signed digitally.  This brings me to the question if my netrasa.inf installation file is currupted. (?)

    Any help would be greatly appreciated.  I am technically competent and can deal with editing the registry, etc, but need a plan of attack.

    Thank you!

    -Tad Richard

    Hi Tadrichard,

    Thanks for choosing Microsoft answers Forum.

    Is there an error when they try to establish the connection, if so, what is the error?

    Are there errors in the event logs?

    Forward for you help.
    Kind regards
    Support of yama - Microsoft.

  • First pro works fine for about 30 seconds, then playback starts lagging and insight cannot be rendered

    Hello.

    When I run the pro first, everything works fine. Playback is smooth, and the timeline can be préaffichée.

    After about half a minute, playback starts lagging badly, audio lags too sometimes. If I choose "sequence > make the whole work area", I get "error video preview. Movie compilation error. Unknown error. »

    The lag is so bad that the software is virtually unusable.

    The last project that I'm a 5s 2 clips, so it is really light, also the same problem persists in other projects.

    Made real works very well.

    After Effects works very well.

    I tried reinstalling the software several times, clear the cache, move the cache to different disks and uninstalling software with cloud creative cleaner.

    I have an Intel Core i7 - 6700K @ 4.00 Ghz cpu

    960 NVIDIA graphics card

    32 GB of ram

    I'm in first pro CC 2015.2

    Any help would be much appreciated, I have no idea how to do this (as I'm not a computer guru, so there might be something obvious I missed)

    Thanks in advance

    I've now updated to cc 2015.3, fingers crossed...

    Hi oskaria,

    You have the same problem on Premiere Pro 2015.3?

    You have enough disk space in the drive?

    Have you tried to change the only software video rendering engine?

    Thank you

    Regalo

  • integrated macOS Sierra Cisco IPsec VPN does not work anymore (impossible to validate the server certificate)

    Hello

    I just upgraded to macOS Sierra and built-in Cisco IPsec VPN no longer works. When you try to connect, I get a "cannot validate the certificate of the server. "Check your settings and try to reconnect" error message. I use Cisco ASA with self-signed certificates and everything worked fine with previous versions of OS X.

    Please help me, I need my VPN Thx a lot

    I am having the same problem with StrongSwan and help cert signed with the channel to complete certificates included in the pkcs12 file imported to the keychain. It was working properly in El Capitan, but now broken in the Sierra.

  • Had cracked screen but the phone works still. Today screen is become white, and the phone rang again.  Did hard reset and now the phone is completely turned off and will not be exposed - not even the Red of the battery is displayed

    Had cracked screen but the phone works still. Today screen is become white, and the phone rang again.  Did hard reset and now the phone is completely turned off and will not be exposed - not even the Red of the battery is displayed

    He broke. Make an appointment at the genius bar and get it fixed / replaced. There is no magic words that will do well.

  • Health that ap on my 6 s iPhone is frozen. I rebooted the phone several times, but it is still frozen

    health that ap on my 6 s iPhone is frozen. I rebooted the phone several times, but it is still frozen.  Can someone help please

    Hi, Lynne.

    Please visit Apple support communities.

    I understand that the application of health stops responding on your iPhone 6s.  Since this has not resolved this problem, try to force the application to close and test.

    Force an app to close the iOS

    If the tags are correct for your position and you run iOS 8.3, be sure to upgrade to the newest iOS available and test.

    Update the software on your iPhone, iPad or iPod touch iOS

    See you soon

  • Good day, notification of save my icloud does not close. I pressed the bottun close several times, but he's still on my screen. How this can be fixed.

    Good day, notification of save my icloud does not close. I pressed the bottun close several times, but he's still on my screen. How this can be fixed.

    Restart the device - without loss of data

    1. Restart your iPhone, iPad or iPod touch - Apple Support
  • I can't reset my files, windows acting strange, so before I would just reset my files, now I can't seem to beable to do.

    I have windows vista, and for some windows reason act strange, I have always used just reset my files but for some reason I can't do it now.

    "[your] reset files".<-- is="" that="" your="" way="" of="" saying="" that="" you="" implemented="" some="" oem="" (original="" equipment="" maufacturer)="" built-in="" system="" restoration/recovery="" process="" that="" reverted="" the="" machine="" to="" the="" 'as-shipped'="" or="" 'factory="" default'="">

    If so - this process was created and supported by OEM - seller who makes your computer (HP?  Reference Dell?  Lenovo?  Entry door?  Others?)

  • After the upgrade yesterday from Vista to Windows 7, now my Cisco VPN does not work and I get an error message titled: grounds 440 driver fault. Any ideas to fix this?

    After the upgrade yesterday from Vista to Windows 7, now my Cisco VPN does not work and I get an error message titled: grounds 440 driver fault.  Any ideas to fix this?

    This was the solution!  The works of vpn as $ 1 million now.  I followed the instructions above to enter the uninstall program and selecting the repair option.  I rebooted the machine, then used the troubleshooting on vpn software compatibility option.  Selected Windows windows xp (service pack 2) as the correct software and cisco vpn client started right up.

    Thanks, Nick!

    Rick

  • Sony Vaio SVE14112FXP. A few days ago the integrated webcam doesn't work. The strange thing is that it is not recognized by the administrator of the material, not even as an unknown device

    Hello

    I have a Sony Vaio SVE14112FXP. A few days ago the integrated webcam doesn't work. The strange thing is that it is not recognized by the administrator of the material, not even as an unknown device. I uninstalled and installed Arcsoft Webcam Suite, which has drivers, but nothing new.
    It seems that the built-in webcam is not connected.
    Thank you

    See Sony support site or their forum, this is a Sony webcam

    And no this isn't a feature of device, or something that should appear in the devices & Printers

Maybe you are looking for

  • Is it safe/simple to remove and re-add the account Mail in Internet accounts?

    I've dealt with this for months and months, and it drives me crazy. I have my email from Comcast (IMAP) account as my email account (accessible via Macbook Pro running El Capitan and my iPad), and whenever I turn the e-mail or the computer wake from

  • Path missing iTunes Songs (already tried script)

    Hello recently I moved all of my itunes library to my new computer (Mac-> Windows), I noticed that some songs bad location path, and I discovered that the songs with special characters (like aeioun, Yes, I'm Spanish) are those who have suffered from

  • FaceTime activation

    Hi, FaceTime worked very well on my iPhone until I changed my apple id password then it won't sign in FaceTime activation it kee saying a hard occ error enable FaceTime, try again later. iMessage is working well. I tried to contact the Apple support,

  • Java is sure turn on now?

    The last update of Java 7 17 is sure turn on now? I noticed after update, it is still disabled, but is no longer blocked in red by Firefox. My hypothesis is that it is safe, since the step 'in the Red' currently. However, I want of course until I re

  • removal of the Mpeg4 videos

    I can't delete videos Mpeg4 remove in the trash. Said it may still be full-time or in-service