Site to Site VPN will not be forwarded to individual hosts, only of the whole networks

I have a VPN site-to-site built between a Cisco 1750 router and an ASA 5555 X running 5 9.2 (4)

There is no problem with the change sets, key exchange. However, I noticed that the ACL that is used to create the field of encryption on the SAA does not work correctly if the network on the 1750 is compared to the individual hosts on the SAA.

Example of

permit access-list extended access acme ip 172.25.91.64 255.255.255.224 host 192.168.10.24

on the SAA where 192.168.10.24 is the remote host and 17.25.91.64 27 is protected behind the ASA network. If the 192.168.10.24 host tries to ping 172.25.91.70, I see the tunnel begin to form on the ASA and then fail with a message "failed policy."

If I go the other way around, the 172.25.91.70 host to 192.168.10.24, the tunnel is built and traffic is allowed.

If I change the ACL to use only the network address (in other words, use 192.168.10.0/24), it works in two ways.

What happens here? If I use a group of objects instead of individual hosts directly going to work? Not sure why it's a failure.

It depends on the implementation of the provider.

Using the baseline IPSEC policy, the networks of each side must match. Filtering in the tunnel does not rely on the establishment of a tunnel, one can be a host or a subnet.

Tags: Cisco Security

Similar Questions

Maybe you are looking for

  • Re: Equium A100-027: update issues

    HelloI want to upgrade my laptop, as much as I can. I need a new minimum of 7200 RPM fast hard disk and the best memory regiion. can anyone help?I'm confused about S - ATA 150 and 300 S - ATA. What is the difference? In addition, which would accelera

  • HP 15-g039wm Notebook PC (ENERGY: does not function keys)

    I recently bought my refurbished HP 15-g039wm Notebook PC (ENERGY STAR) and immediately improved Windows 8.1 to Windows 10. Since then, the function keys do not work. Is is possible to make them work again?

  • How to develop VB6.0 to display the Khmer language

    Hi Sir/Madam I develop a feature which was asked to show the Khmer language in VB6 program. and even ask to print the Khmer language by crystal report Marco Cuscapi.

  • Reading of .bkf files on xp pro with windows vista or windows 7.

    It comes to clarify my previous post. How can I open the files in .bkf created with xp pro backup tool with my windows vista machine? I have similar problems with windows 7 to use these saved files with my new computer?

  • How to pass 'SIGNAL' object as a parameter of QML

    Hi all I'm in a fundamental need for the object that caused the SIGNAL to occur, E.g. by a signal "onClicked" (in QML) of the button if I call a method of CRACK or Q_INVOKABLE, then what I have the purpose of the call? As, Button {} text: 'Add contai