Strange problem of PIX Lan2Lan VPN!

Hi, I set up my two firewalls pix for lan 2 lan vpn (ipsec) .This two firewalls connects directly with ethernet 0 and each has a local network on ethernet 1. When I try to ping SEARCH1 station2 after a period of and when ike phases are complete ping comes up with the answer, but when I try to ping station 1 station 2 I get no response. Why my vpn connection back in one direction and is not on the other side?

(pix1)

ethernet0 (outside): 20.20.20.1

Ethernet1 (inside): 10.10.10.1

research1 on inside: 10.10.10.20

(pix2)

ethernet0 (outside): 20.20.20.2

Ethernet1 (inside): 15.15.15.1

Station2 on Interior: 15.15.15.20

pix1 config:

interface Ethernet0

nameif outside

security-level 0

IP 20.20.20.1 255.255.255.0

!

interface Ethernet1

nameif inside

security-level 100

IP 10.10.10.1 255.255.255.0

!

Ping list extended access permit icmp any one

Ping list extended access permit tcp any host 10.10.10.15 eq ftp

access ip 10.10.10.0 extended list traffic allow 255.255.255.0 15.15.15.0 255.255.255.0

NAT (inside), access list 0 traffic

Access-group ping in external interface

Route outside 15.15.15.0 255.255.255.0 20.20.20.2 1

Crypto ipsec transform-set esp-3des esp-sha-hmac ipsec

address traffic map crypto crymap 1 game

peer set card crypto crymap 1 20.20.20.2

crymap 1 transform-set ipsec crypto map

crymap interface card crypto outside

crypto isakmp identity address

crypto ISAKMP allow outside

crypto ISAKMP policy 1

preshared authentication

3des encryption

sha hash

Group 2

life 1000

tunnel-group 20.20.20.2 type ipsec-l2l

IPSec-attributes tunnel-group 20.20.20.2

pre-shared-key *.

!!!!!!!! PIX 2 config

interface Ethernet0

nameif outside

security-level 0

IP 20.20.20.2 255.255.255.0

!

interface Ethernet1

nameif inside

security-level 100

IP 15.15.15.1 255.255.255.0

!

Ping list extended access permit icmp any one

Ping list extended access permit tcp any host 15.15.15.20 eq ftp

ip 15.15.15.0 expanded list access traffic allow 255.255.255.0 10.10.10.0 255.255.255.0

NAT (inside), access list 0 traffic

Access-group ping in external interface

Route outside 10.10.10.0 255.255.255.0 20.20.20.1 1

Crypto ipsec transform-set esp-3des esp-sha-hmac ipsec

address traffic map crypto crymap 1 game

peer set card crypto crymap 1 20.20.20.2

crymap 1 transform-set ipsec crypto map

crymap interface card crypto outside

crypto isakmp identity address

crypto ISAKMP allow outside

crypto ISAKMP policy 1

preshared authentication

3des encryption

sha hash

Group 2

life 1000

tunnel-group 20.20.20.1 type ipsec-l2l

IPSec-attributes tunnel-group 20.20.20.1

pre-shared-key *.

Whe I get show crypto isakmp his every thing looks fine just when I ping station 2 St1, but after that if I erase isakmp its and trying them to ping station 1 ST 2 show crypto isakmp his returns with 'no active SA' why?

Do 2 things:

1. the life set up under the IKE policy is 1000. Bring to 86400. As the life of the Isakmp Security Association must be greater than the life of the Ipsec Security Association.

2. make sure to separate for crypto ACL and the NAT ACL lists 0. you use same access-list "traffic." Create another identical access list and use it separately as Crypto ACL on both sides.

For example on PIX2:

ip 15.15.15.0 expanded list access traffic allow 255.255.255.0 10.10.10.0 255.255.255.0

Access extensive list ip 15.15.15.0 VPNACL allow 255.255.255.0 10.10.10.0 255.255.255.0

NAT (inside), access list 0 traffic

crypto map crymap 1 corresponds to the address VPNACL

Then check and validate the results.

HTH

Sangaré

Pls rate helpful messages

Tags: Cisco Security

Similar Questions

  • Logging strange problem with PIX

    Since I upgraded to v7.0 on my PIX525 I noticed a weird problem that I have been unable to resolve in what concerns my PIX syslogging. A handful of times a week, I get messages stating that my email gateway trying to send about 4.2 GB e-mail messages to mail servers different.

    Problem is I don't see any indication of this in my mail server logs, my SMTP gateway logs, and my bandwidth monitor is not reported this. We move usually about 1.5 GB per day through our internet pipe so if there was a 4.2 GB extra traffic, I know. I tried to sniff the traffic of the mail server and I do not take into account everything that matches the entry in syslog. I can't find any info regarding no matter where this and I was wondering if anyone has seen this issue.

    Thank you.

    Trac bug Cisco messages the following warning, corrected in version 7.02:

    CSCeh96708 Yes Syslog reports erroneous transfer size in syslog TCP disassembly 302014

    Please upgrade to version 7.02 and these messages will be fixed.

    Please rate this post if this has been helpful.

  • Cannot resolve the problem between ASA - CheckPoint (VPN)

    Hi team,

    I have a strange problem with a L2L VPN between an ASA on my side and a checkpoint as her counterpart.

    The IPsec tunnel works very well, but from time to time, the traffic stop through the tunnel.

    Scenario:

    172.31.250.0/28--ASA---Internet---checkpoint---200.122.x.y/32

    I've done many tunnels between ASAs and control points, but this time we found this:

    access extensive list ip 172.31.250.0 outside_1_cryptomap allow 255.255.255.240 host 200.122.164.165

    local ident (addr, mask, prot, port): (172.31.250.0/255.255.255.240/0/0)

    Remote ident (addr, mask, prot, port): (200.122.164.165/255.255.255.255/0/0)

    #pkts program: encrypt 0, #pkts: 0, #pkts digest: 0

    #pkts decaps: 1148, #pkts decrypt: 1148, #pkts check: 1148

    local ident (addr, mask, prot, port): (172.31.250.8/255.255.255.248/0/0)

    Remote ident (addr, mask, prot, port): (200.122.164.0/255.255.255.0/0/0)

    #pkts program: 27682, #pkts encrypt: 27683, #pkts digest: 27683

    #pkts decaps: 27683, #pkts decrypt: 27683, #pkts check: 27683

    local ident (addr, mask, prot, port): (172.31.250.8/255.255.255.248/0/0)

    Remote ident (addr, mask, prot, port): (200.122.164.165/255.255.255.255/0/0)

    #pkts program: 3579, #pkts encrypt: 3579, #pkts digest: 3579

    #pkts decaps: 10443, #pkts decrypt: 10443, #pkts check: 10443

    Traffic is defined between 172.31.250.0/28 and a single host, but I see three SAs:

    1 172.31.250.0/28 - 200.122.164.165/32

    2 172.31.250.8/32 - 200.122.164.0/24

    3 172.31.250.8/32 - 200.122.164.165/32

    What is the reason for this?

    The reason why I have paste this above is because the control point defines the traffic "interesting" as two rules (one in each direction).

    Control point:

    Rule 1: The traffic of 200.122.164.165/32 172.31.250.0/28

    Rule 2: The traffic of 172.31.250.0/28 200.122.164.165/32

    So, I think that the problem occurs because we hear by the SAs of the phase 2 bidirectional rules (crypto ACL), and control point sets the SAs of the phase 2 as one-way rules. Even if traffic matches, I see the output above.

    I think this means that the ASA receives a portion of the traffic in a SA and send it via another, and I don't know if that is causing the problem and if so, how to fix?

    The problem is totally random. We have reduced the time to generate a new key for 2 minutes at the minute of the phase 2 and 5 on the phase 1 and there is no problem during the generate a new key.

    We had not been able to capture the log at the exact moment of the problem. Then the tunnel suddenly rises again and start working.

    ASA 5510 version 8.2 (5)

    Any help is appreciated!

    Federico.

    Federico,

    New installation SAs is not so to generate a new key, it consicides with a homologous assuming it matches traffic again and must so initial has ITS new.

    Now when we have a static, selector of this SA traffic encryption card new must match what we defined in the ACL.

    Generally, you will get an error if there is absolutely no match and tunnel would fail to phase 2.

    I want to just make sure we're on the same page. When it ends on a dynamic encryption card, we know (or rarely know) what will look like the SA distance so we accept everything.

    I do not say that this checkpoint of the half was here half it matched. I say it's more likely (for some reason I couldn't be aware, or a bug) implemented match the ACL under static crypto map.

    Marcin

  • Problem of PIX - loss of connectivity

    We are expeiencing that a very strange problem and any ideas would be appreciated. Here's the scenario, then I will describe the problem.

    Store #1

    Computer = 192.168.4.11 XP connects to

    ADTRAN router = 192.168.4.1 connects to

    SBC 64 k frame

    Ministry of the Interior WAN router = 192.168.0.1 with a gateway of last resort = 192.168.0.90

    which is the address of the pix that sends all internet traffic to the 64.x.x.x (external) address

    All the store suddenly can not access the internet. However, it can access other shops and HO without any problem. When I try to make a ping or use IE at the store, it resolves the address, but a few times out.

    In the pix, there is the following line to take all internet traffic in the stores and will forward it to the external side of the pix and on the internet

    Route 192.168.0.0 255.255.0.0 64.x.x.x 1

    As I said this has worked fine until today. We are at a loss.

    Help, please!

    Let's see if we can help you.

    The declaration of the route that you have shared with us doesn't seem right.

    Most likely, your itinerary records should look like this:

    route 0.0.0.0 0.0.0.0 64.x.x.x 1<--- tells="" the="" pix="" to="" use="" the="" outside="" network="" as="" gateway="" of="" last="">

    Route 192.168.4.0 255.255.255.0 192.168.0.1<--- tells="" the="" pix="" that="" the="" 192.168.4.0="" exists="" on="" the="" inside="">

    Does make sense?

    You would have additional road statements for other internal networks pointing a device inside like 192.168.0.1 router WAN HO for the Pix knows how to route packets to them.

    Maybe you can share with us the statement "see the road" so we can help you determine if this is indeed the cause.

    Thank you

    Peter

  • Strange problem with ASDM

    Hi, today we had a strange problem with one of our 5550. I worked through ASDM on it and all of a sudden I couldn't connect via asdm on the interface of management or inside interface. Nothing helps.

    When I connected with a vpn, then use asdm, it works. My ip on the network when it did not work was 1xx.xxx.81.235. When I use the vpn is a 1xx.xxx.55.1 from a different ip address. I can build a connection on the inside interface with asdm (with vpn).

    I tried closed and without stop the interface of man, that does not.

    It may be that the things asa, I am an intruder and dynamically blocks my netwerk range? If yes where can I find this info.

    Other users of our team had the same problem.

    I also checked the syslog nothing.

    THX,

    Marc

    Although I've ever experienced this myself, but if the running-config has not changed and worked before its possible that the ASA

    may have shunned your connection?

    To the CLI:

    # sh shun

    look if your IP address is present, if any make:

    # claire shun

    http://www.Cisco.com/en/us/docs/security/ASA/asa80/configuration/guide/protect.html#wp1058270

    More than likely it is do to a change to the running configuration, I would start by looking at a previously working with the gift of running-config running-config.

  • I have a strange problem with my RAM supported by installers. When I check the activity monitor, 3 installers are open and they start around 80 MB memory RAM used for about 7 or 10:08 minutes or so.

    I have a strange problem with my RAM supported by installers. When I check the activity monitor, 3 installers are open and they start around 80 MB memory RAM used for about 7 or 8 concerts after 10 minutes. I have to force them to quit, but I don't know what I am closing or why they open in the first place. Applications downloaded on iTunes?

    In addition, the Console has opened with the same message several times, but I don't know what that means.

    Any help would be appreciated.

    Hello

    The last is a picture of the Terminal window.

    Just because it lists 'Console' does not mean that it has nothing to do with this application.

    You have not said why or what you're trying to install so I can't help with that.

    You can use the activity monitor to leave their.

    After you select an item, use the X in a type of stop sign icon and confirm force quit.

    21:36 Thursday; September 15, 2016

     iMac 2.5 Ghz i5 2011 (El Capitan)
     G4/1GhzDual MDD (Leopard 10.5.8)
     MacBookPro (Snow Leopard 10.6.8) 2 GB
     Mac OS X (10.6.8).
     iPhone and iPad (2)

  • Strange problems with Firefox!

    Hello.
    I am a user of Mozilla Firefox about 3 years. I use it on my desktop and on my laptop. in the PC, I have no problem; but in the laptop, I have strange problems. I searched this problem to support Mozilla and Google also! but I can't find any answer.
    Also, I have reset Firefox and problem resists. even I uninstall and install after. but the problem remains.
    Now, I'm under Firefox 22.0.

    Problems:
    1. download icon in the header does not work. ( http://www.8pic.ir/viewer.php?file=30576184770845961788.jpg )
    2. sometimes I can't switch between tabs.the there is no need to click!
    3 Middle click of the mouse to move around the page work; but its icon is not displayed! ( http://www.8pic.ir/viewer.php?file=44434592402706809052.jpg )
    4. some of the Add-ons not work! for example; I use "Video download 1.97.2 pure", but its icon in the header will work not (just like the download icon that mentioned in 1). There is no need to click! (I use this add-on in my PC and it works).

    Hello

    Try Firefox Safe mode to see if the problem goes away. Safe mode is a troubleshooting mode, which disables most of the modules.

    (If you use it, switch to the default theme).

    • You can open Firefox 4.0 + in Safe Mode holding the key SHIFT key when you open the desktop Firefox or shortcut in the start menu.
    • Or open the Help menu and click on the restart with the disabled... modules menu item while Firefox is running.

    Once you get the pop-up, simply select "" boot mode safe. "

    If the issue is not present in Firefox Safe Mode, your problem is probably caused by an extension, and you need to understand that one. To do this, please follow article Troubleshooting extensions, themes and problems of hardware acceleration to resolve common Firefox problems .

    To exit safe mode of Firefox, simply close Firefox and wait a few seconds before you open Firefox for normal use again.

    When find you what is causing your problems, please let us know. It might help others who have the same problem.

    Thank you.

  • Satellite Pro C850 - strange problem with LAN connection

    Hello world

    I just signed up on this forum because I hope you guys can help me with a really strange problem.

    I recently bought a Satellite Pro C850-1MX
    It came with Win8, but given that I don't really like Win8, I bought an additional Windows 7 Pro (64 bit) license and installed on the laptop.

    The problem I describe, also arrived on 8 to win, which makes it even more strange.

    As soon as I connect a cable to the RJ-45 port, Windows tells me, that the LAN connection is not connected.
    As soon as I unplug the cable, Windows starts looking for a network and actually found one!

    So, the only way to connect to my LAN cable is... I have activate the LAN connection, wait that it detects a network (without the cable connected!) and meanwhile to connect the cable to the network port.
    Now... If I disconnect the cable once again, Windows still shows its connected.

    I must say, that I am a Director of professional network for more than 10 years now, so I should know my systems, but this never happened to me before. Event log shows nothing, re-installing drivers did nothing either. IM quite confused here and I hope you guys can help me.

    Thanks for reading, and let me know if you need any additional info!

    Greetings from the Germany,
    Sandro

    Hello Sandro,

    To be honest I confused m.

    I would try to start talking about the drivers installed, since you changed the system for Win 7.
    All the network devices, such as card WLan and LAN card are properly recognized in Device Manager?

    As I m not wrong not the laptop was equipped with a network card Realtek-8111F (1000BASE-T/100Base-TX/10Base-T) and WLan RTL8723AE Realtek b/g/n card.
    If both should appear in the device properly Manager if you have installed the drivers correctly.

    2nd question:
    You said:
    > As soon as I unplug the cable, Windows starts looking for a network and actually found one!
    Are you sure that you speak of LAN and WLAN?
    For me it made no further since. If the network cable is unplugged, the notebook would connect to the WLan where WiFi is enabled.

  • strange problem see my own profile

    Hello there is a strange problem.

    In my my contact list, I see a contact with the same Skype name like myself who appears here. Even if I delete it or block it, he always comes to the top. The strange question is that it is always offline and he said my Skype name and messenger as it gets then online via messenger.

    First time I see that. Please help me

    Am I hacked?

    I tried to uninstall the Skype change password always the same thing.

    This is a bug known on Skype servers.

    http://community.Skype.com/T5/Windows-desktop-client/Skype-Messenger-allows-me-to-open-a-chat-window...

  • Satellite L850 - 1 H 4 - a strange problem with the FN key

    Hello

    I have a strange problem on my laptop. When I uninstall my PVAT my start "FN" key works, when I install it it s not working not properly. Its market not only the volume key (F9 and F10) without pressing the "Fn", if I want to press F9 or F10 I have to press FN + F9, even with the rest of the buttons.

    When I install PVAT I have to press FN, so I can use my F keys (e.g. F3 to search on the browser tool, alt + f4 - I have to press Fn + alt + f4), and I can't use real functions like mute, disable Touchpad etc. Use the volume keys only. Y at - it a problem if I run my computer without PVAT, this may affect its performance?

    Where could be the problem and can I fix it? I'm with Windows7 x 64, but the laptop was with no OS when I bought it. And there is a problem with this version, I bought its impossible to install the Pakc3 Service, it s with SP1, can be the problem? I put t know what to do... perhaps I run the laptop without PVAT, sounds good, because the buttons work fine without it, but I don't know if it interacts with something else.

    Thanks in advance!

    Its possible to use the function buttons by pressing another button without the use of the fn or FN.
    This option can be changed in the BIOS.

    Go to the BIOS by pressing F2.
    In the BIOS, choose Advanced-> system configuration Options
    Here you should find the option that allows to change the special function keys which allows you to use the function FN or without button Fn button

    By the way: this theme has already spoken here in the forum several times. therefore recommend that you use the advanced search to Forums before posting new thread

  • More strange problem with keyboard and mouse on Satellite 1900

    Clicking on files or folders, I wonder to confirm the deletion of the clicked elements. The "Left shift" is interpreted as a backspace. I was afraid of a virus; but no viruses or spyware are present. I reformatted and reinstalled evrything; the problem persists. Everyone has known and resolved this strange problem.
    Thank you for the help.

    Hello

    It's very strange. Unfortunately I have no precise explanation. I suggest you check this with external keyboard to see if the keyboard is not defective.

  • Strange problem with Toshiba Express Media Player on Satellite M115-S3094

    I am facing a strange problem in my Toshiba M115-S3094, which has been pre-installed with Windows XP Media Center edition and which also had the Toshiba Express Media Player.

    I had already done a clean install of Vista on it, and then I decided to go back to XP with my recovery DVDs. I did the same procedures of first installation Express Media Player to backup (that I did when I bought the laptop) and then installing Windows XP DVD de Toshiba Recovery XP.

    The steps included:
    1 deleted recovery Express media player disk partitions
    2. installed express media player
    3 extracted Xp Recovery DVD, by selecting 'Recover without changing the Partitions' (there is no expert mode)

    Everything was fine (i.e. installation)... But now, after the turning off my laptop I press the Express Media Center button, the logo "Express Media Player" appears on the screen after loading of closures of laptop for 5 seconds.

    I tried to open it again and again, but the logo is displayed for 5 seconds and then my laptop stop...

    Laptop works fine when I connect to windows by pressing the power button / stop.

    Can someone help me on this strange question... ?

    Hello

    The whole story is a bit confusing
    First of all, I would like to know if your laptop is already preinstalled with the Media Express Player and if you were able to use it on your laptop in the past.

    Now something about the Express Media Player installation;
    In order to use the media functions Express the Mediaplayer Express Recovery CD must be performed before performing the recovery from the recovery DVD-ROM products.

    In addition, on the HARD drive should at least 150-200 MB of free space available.
    This free space must be on the end of the HARD drive and there must be unallocated. To get these free space on party products 3rd HARD drive should be used as Partitions Magic 8.

    I m not 100% sure that on error ID system badly but maybe it corresponds to the DMI evil information stored on the motherboard. If we're not DMI, you will not be able to reinstall Express Media player using the recovery media express CD.
    In the DMI must be set properly the manufacturing: Toshiba, product name: for example by Satellite M115-S30

    Finally and most importantly, I found this thread useful forum on the Media Express recovery procedure:
    http://forums.computers.Toshiba-Europe.com/forums/thread.jspa?MessageID=51801쩙

    Could be useful for you!

  • Strange problems on Satellite P30

    Hello
    Hope someone can help me that this laptop is causing me a massive headache

    The P30 for 2 1/2 years now, had my share of problems, DC have to be repaired and overheating due to the obstruction of the fan/radiator etc.

    a few months I ve noticed problems again with the domain controller, connection, works ok, but if you hit the laptop a little, it loses its charge and the amber light turns off and it extends the battery, the laptop must be turned off in so he can be charged. Also, there is a hissing/crackling noise from the charger when it is plugged

    I downloaded ATI Catalyst software a few days back and since then I ve had nothing other than problems, I got a mom.exe error and since then I have times m restarting constantly randomly, I formatted my system using the master CD, the laptop was returned to the factory settings, but 2 minutes in windows, I restarted, I formatted again and put an original disc of XP SP2 and who used to put a fresh xp on my laptop. But once I was doing restarted without any warning. Of course, I had installed my hardware from Toshiba disk drivers.

    Now my system is totally messing with my head, I can't get into windows without problem, I can surf the internet without problem, I tested a game for 5 hours last night (set of high spec) there was no reboot at all, and the computer ran fine. If I open windows media player and search for songs my computer restarts, I have tried to install software like nero and System Mechanic it restarts again, I watched a movie using windows media player and who ran late, its when its looking for songs it turns off, I do not understand is how random, I don't see the problem is the video card (games will work perfectly) and I do not think that the problem are a nuisance power because the game ran fine with the fans spinning, got a little hot, but that's normal I guess. It s mainly when I m access some files on my drive C: is when it restarts

    Please can someone help with this strange problem?
    Thanks in advance

    Oh 1 still a thing, I also have problems with my m * a UJ820S mat, when I connect to windows, it is not in my computer, if I remove the Bay and restart the machine, it appears and works fine until my computer is off again

    Hello

    I read all strange story twice and believe me, confuses the issue description
    I can't give you a solution to the problem, but I can try to make some suggestions
    To me, it looks like a motherboard problem

    Several years ago I also had a strange problem with my old no Toshiba laptop.
    The laptop always closes if I open the html files. But this happened only while the laptop was connected to the main power supply.
    It's very strange for me and the ASP could not believe that finally, the technician changed the motherboard and since this replacement everything runs great

    I think you should also try to contact the service provider in your country for detailed notebook verification.
    In your case, it s really necessary

  • Really strange problem with Yoga tab 3 10.1 "

    OK, up until that today ' today all was well with my new Yoga 3 tab 10.1 ". Today, he has developed a strange problem.

    The screen kept going blank and in return then and also would lose some wallpaer I had and went back to the default.

    So, as my wallpaper is all stored on the card microSD, I decided to turn off the power and remove the card.

    After plugging everything seems OK... So far, that is.

    I'm currently copy everything off the card on my PC and the test card and reformat to see if that takes care of it, and I'm going to order a new card just as a precautionary measure.

    No idea why these symptoms?

    Well, after doing a formatting FULL of the microSD card on my machine Win7 and retransfering files back to him, he seems to have solved the problem. I think that full format dealt with issues on the map.

    But, because I'm a FIRM believer in the CYA, I also ordered another card anyway. Figure better than cure.

  • strange problem of typing

    Then I searched through six pages and don't see my problem. I hope that I did not lack the thread for him.

    My problem is when I type with the physical keyboard, he decides to randomly not automatically correct. It will not capitalize the words at the beginning of sentences or add in apostrophes, etc. The strange thing is if I use the keyboard screen on and then back to the physical keyboard, AutoCorrect works again... briefly. It seems that I can't run contiunously and reliantly. Any help on this would be greatly appreciated.

    This task manager up to cause some strange problems when used. I try not to use it and see if it solves your problem. A case in point is that if you kill Gallery it will stop the music player, so it can cause problems. I just leave it alone, unless I know a real application that is a problem. Let me know if it helps. Also after you have unchecked everything restart your phone.

    amybud1 wrote:

    I use the best keyboard for my screen keyboard on. I checked the settings for the best keyboard and the stock keyboard. I use Task Manager who came on the phone, but I don't have a best keyboard on the auto-fin list.

Maybe you are looking for