VPN launched only one way

Does anyone have an idea why a site to site VPN tunnel could only be put in place a way? I have a pix to connect to a vpn tunnel using NAT - T IPSEC concentrator. Since the hub if I initiate traffic to the pix, the tunnel rises and then I can access resources behind the hub on the side pix.

If I try to open the flow of the side pix, the tunnel will not come to the top. Debugging on the pix, it's not even trying to open the tunnel.

Here is an excerpt of the pix config:

Crypto ipsec transform-set esp-3des esp-sha-hmac bench

map TestMap 10 ipsec-isakmp crypto

card crypto TestMap 10 corresponds to the address ACL_VPN

card crypto TestMap 10 peer set 10.10.10.1

card crypto TestMap 10 set transform-set bench

TestMap outside crypto map interface

ISAKMP allows outside

ISAKMP key * address 10.10.10.1 netmask 255.255.255.255

ISAKMP nat-traversal 20

part of pre authentication ISAKMP policy 10

ISAKMP policy 10 3des encryption

ISAKMP policy 10 sha hash

10 2 ISAKMP policy group

ISAKMP life duration strategy 10 86400

I'm just using 10. address of the top for the peer for example. The ACL_VPN specifies local/remote subnets correctly. The default route is the external interface of the pix.

The hub, I've specified that the tunnel is bidirectional.

Everyone why it will undertake only a way to any idea?

See you soon

Brian

Thanks for posting your "ACL_VPN" and your NAT Exemption ACL ACL.

Thank you!

Tags: Cisco Security

Similar Questions

  • Cisco IPSec VPN works only one way.

    I'm hitting my head against the wall for more than 2 weeks now. I can't get this figured out.

    We have 2 locations and a server with an Internet service provider. Currently, we are connecting to our Internet service provider via a vpn ipsec to our headquarters. later, we will add the 1 direction.

    The problem is the following. My vpn is in place, I can ping my local ip address, my IP of the tunnel, the remote tunnel interface, the vlan remote or the gateway, but I can't ping anything you wanted. The branch to the ISP I ping the router in the Internet service provider's domain controller and the server very well. but I can't ping or talk about anything either at the Office on the side of the IAF. and so I can not communicate with any host on the LAN. Can someone please help me with this?

    Can I unload the configs of the two routers here someone watching?

    Thanks in advance.

    Exemption from the NAT on the end server must include the following reject order:

    NAT extended IP access list

    5 deny ip 10.1.20.0 0.0.0.255 10.178.164.128 0.0.0.127

    Disable the ip nat translation before testing again.

  • Traffic permitted only one-way for VPN-connected computers

    Hello

    I currently have an ASA 5505.  I put up as a remote SSL VPN access. My computers can connect to the VPN very well.  They just cannot access the internal network (192.168.250.0).  They cannot ping the inside interface of the ASA, nor any of the machines.  It seems that all traffic is blocked for them.  The strange thing is that when someone is connected to the VPN, I can ping this ASA VPN connection machine and other machines inside the LAN.  It seems that the traffic allows only one way.  I messed up with ACL with nothing doesn't.  Any suggestions please?

    Pool DHCP-192.168.250.20 - 50--> for LAN

    Pool VPN: 192.168.250.100 and 192.168.250.101

    Outside interface to get the modem DHCP

    The inside interface: 192.168.1.1

    Courses Running Config:

    : Saved

    :

    ASA Version 8.2 (5)

    !

    hostname HardmanASA

    activate the password # encrypted

    passwd # encrypted

    names of

    !

    interface Ethernet0/0

    switchport access vlan 20

    !

    interface Ethernet0/1

    switchport access vlan 10

    !

    interface Ethernet0/2

    switchport access vlan 10

    !

    interface Ethernet0/3

    Shutdown

    !

    interface Ethernet0/4

    Shutdown

    !

    interface Ethernet0/5

    Shutdown

    !

    interface Ethernet0/6

    Shutdown

    !

    interface Ethernet0/7

    switchport access vlan 10

    !

    interface Vlan1

    No nameif

    no level of security

    no ip address

    !

    interface Vlan10

    nameif inside

    security-level 100

    IP 192.168.250.1 255.255.255.0

    !

    interface Vlan20

    nameif outside

    security-level 0

    IP address dhcp setroute

    !

    passive FTP mode

    DNS lookup field inside

    DNS domain-lookup outside

    pager lines 24

    Within 1500 MTU

    Outside 1500 MTU

    mask 192.168.250.100 - 192.168.250.101 255.255.255.0 IP local pool VPN_Pool

    ICMP unreachable rate-limit 1 burst-size 1

    don't allow no asdm history

    ARP timeout 14400

    Global interface 10 (external)

    NAT (inside) 10 192.168.250.0 255.255.255.0

    Timeout xlate 03:00

    Timeout conn 01:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02

    Sunrpc timeout 0:10:00 h323 0:05:00 h225 mgcp from 01:00 0:05:00 mgcp-pat 0:05:00

    Sip timeout 0:30:00 sip_media 0:02:00 prompt Protocol sip-0: 03:00 sip - disconnect 0:02:00

    Timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute

    timeout tcp-proxy-reassembly 0:01:00

    Floating conn timeout 0:00:00

    dynamic-access-policy-registration DfltAccessPolicy

    the ssh LOCAL console AAA authentication

    Enable http server

    http 192.168.250.0 255.255.255.0 inside

    No snmp server location

    No snmp Server contact

    Server enable SNMP traps snmp authentication linkup, linkdown cold start

    life crypto ipsec security association seconds 28800

    Crypto ipsec kilobytes of life - safety 4608000 association

    Telnet timeout 5

    SSH 192.168.250.0 255.255.255.0 inside

    SSH timeout 5

    SSH version 2

    Console timeout 0

    dhcpd dns 8.8.8.8

    !

    dhcpd address 192.168.250.20 - 192.168.250.50 inside

    dhcpd allow inside

    !

    a basic threat threat detection

    Statistics-list of access threat detection

    no statistical threat detection tcp-interception

    WebVPN

    allow outside

    SVC disk0:/anyconnect-win-2.5.2014-k9.pkg 1 image

    SVC disk0:/anyconnect-macosx-i386-2.5.2014-k9.pkg 2 image

    Picture disk0:/anyconnect-linux-2.5.2014-k9.pkg 3 SVC

    enable SVC

    tunnel-group-list activate

    attributes of Group Policy DfltGrpPolicy

    value of server DNS 8.8.8.8

    Protocol-tunnel-VPN IPSec l2tp ipsec svc webvpn

    tunnel-group AnyConnect type remote access

    tunnel-group AnyConnect General attributes

    address pool VPN_Pool

    tunnel-group AnyConnect webvpn-attributes

    enable AnyConnect group-alias

    !

    class-map inspection_default

    match default-inspection-traffic

    !

    !

    type of policy-card inspect dns preset_dns_map

    parameters

    maximum message length automatic of customer

    message-length maximum 512

    Policy-map global_policy

    class inspection_default

    inspect the preset_dns_map dns

    inspect the ftp

    inspect h323 h225

    inspect the h323 ras

    Review the ip options

    inspect the netbios

    inspect the rsh

    inspect the rtsp

    inspect the skinny

    inspect esmtp

    inspect sqlnet

    inspect sunrpc

    inspect the tftp

    inspect the sip

    inspect xdmcp

    !

    global service-policy global_policy

    context of prompt hostname

    no remote anonymous reporting call

    call-home

    Profile of CiscoTAC-1

    no active account

    http https://tools.cisco.com/its/service/oddce/services/DDCEService destination address

    email address of destination [email protected] / * /

    destination-mode http transport

    Subscribe to alert-group diagnosis

    Subscribe to alert-group environment

    Subscribe to alert-group monthly periodic inventory

    monthly periodicals to subscribe to alert-group configuration

    daily periodic subscribe to alert-group telemetry

    Cryptochecksum:30fadff4b400e42e73e17167828e046f

    : end

    Hello

    No worries

    As we change the config I would do as well as possible.

    First, it is strongly recommended to use a different range of IP addresses for VPN clients and the internal network

    No VPN_Pool 192.168.250.100 - 192.168.250.101 255.255.255.0 ip local pool mask

    mask 192.168.251.100 - 192.168.251.101 255.255.255.0 IP local pool VPN_Pool

    NAT_0 ip 192.168.250.0 access list allow 255.255.255.0 192.168.251.0 255.255.255.0

    NAT (inside) 0-list of access NAT_0

    Then give it a try and it work note this post hehe

  • BBM BBM works only one-way

    Hello

    Since yesterday (2016-01-26) the following error portfolio:

    Messages sent from a BlackBerry device are received, but the messages that I send to a BlackBerry smartphone get only the check box, but no D or R marking.

    I use BBM on an Android phone, with the most recent version 2.11.0.18

    Try to solve the problem I did the following steps - but none of them changed something in the behaviour:

    . Restart of BBM

    . Restaring the phone

    . Reinstalling BBM

    . Try BBM on two other Android devices

    . Try to create a group - for this my invitation was received by the BlackBerry device, but cannot be accepted

    . You try to join a group - I received the invitation and I could accept it, but the group does not appear

    . Try a cat prlvate

    . Try another account

    The only thing that works is the exchange between two Android devices.

    Another curiosity: yesterday and today, that one message has send - only!

    I have some other ideas that I could try to solve the problem - did someone knows more? Is there a network BlackBerry problem?

    Today, I was able to exchange a few messages again, it seams to work again.

    Without changing anything.

  • BlackBerry Smartphones help BB Storm will synchronize only one way

    When I enter an appointment in my calendar from device, and then try Outlook 2003 calendar SYC, it will not be synchronized (appointments appear in my Outlook calendar).  If I enter my Outlook calendar appointment it will synchronize the appointments on my device.  I have entered in the configuration of the Fund Manager and assign the two-way synchronization. Still no luck.

    I found the problem.  When you create a new appointment, there is an article that says "send help:" this is a list of all email addresses you receive from emails on your Blackberry.  In some ways, the email address was changed to another.  This has caused the problem of synchronization.  Once I changed it to one that was already there, the two way sync worked.

    I still don't know where you configure what email address it uses.  If someone knows let me know.  Or email to three addresses are emails that I synchronize in Outlook.

  • BlackBerry Smartphones Yahoo contacts synchronizes only one way

    Sync OTA between the Contacts of Yahoo and the BB address book synchronizes only Yahoo for my BB.  If I make changes on a contact in Yahoo, it appears on the BB in 4 hours.  But if I make a change to a contact on my BB, the change does not appear in Yahoo.  Does anyone else have this problem or does anyone know if this is supposed to work this way or not?

    After you delete the account of the phone completely and then add, everything worked normally.  In fact, it seems to be synchronization immediately, rather than the 4 hour time limit specified in the master of BIS.

  • Calendar sync only one way

    Hello

    my iphone 4S calendar calendar app and google used to synchronize with each other, but only the application of the phone's calendar now receives new entries.
    IE: no appointment I do on the phone do not appear on my calendar google on a computer. It is a new problem, but I don't think I've changed settings to icloud. I've read through similar forum posts. Any ideas?

    Thank you

    Your profile says you have an iPhone 4 running iOS 7.1.2 s.  I'll assume that you have indeed an iPhone 4s, but it runs the latest version of iOS (9.3.2).

    Open the calendar on your iPhone app.  Click on the "Calendars" button at the bottom in the Center.  Are shown the correct calendars?  Are you sure when you add an event on the iPhone, he's going to the desired calendar?

  • VMotion migration works only one way...

    I have 2 hosts running ESX 4.0 I installed Vcenter and I use the VSphere GUI client to manage hosts.

    I am able to perform dynamic migration from one host to another, but not the reverse, and when I try to run the

    migration, I get the following error: "a general error has occurred: cannot create the log file supplied cannot open"/var/log/vmware/journal/1234xxxxxx.xx"to write" I don't think that it was due to lack of disk space.

    Can someone help me?

    Have you tried to connect to the console and check if it

    is the space on the host by using the command 'df '? It's the

    version ESX console I recommend you connect to the shell and

    perform a "tail-f/var/log/vmkernel" as he tried to emigrate in the

    a direction that does not work. I found that the error messages

    reported in vCenter don't always point you in the right place. You

    can get a little more information to facilitate your search, if it turns out not to make disk space.

  • Universal Clipboard works only one way

    Hello

    I have a MacBook Pro running Mac OS Sierra and an iPhone 5 iOS running 10 of the retina

    Universal Clipboard does work for my Mac to my iPhone.

    When you try to copy stuff from my iPhone Mac does not seem to be able to paste them.

    I checked the time phone and Mac are recorded in the same Apple ID

    The Wi - Fi or Bluetooth connection are on both devices

    I disabled and enabled the transfer option in the settings of devices

    Someone knows what to do?

    Thanks, Idan

    Me too. Exactly the same problem. I have iPhone 6 with iOS 10.0.1 and MacBook Air Early-2015 with macOS Sierra installed on Mac App Store, this morning. Mac & iPhone copy paste works, but the reverse is not.

  • Calendar only one-way synchronization

    My iphone calendar events may not sync to my mac BUT my mac calendar events synchronize to my phone.  What Miss me?

    the fixed!

  • Only one way to work network

    I have a desktop running Vista Home E. and a laptop running Windows 7. Home Edition
    I can access my files on the "Vista Office" of the "Window7 laptop" but from the office, he continues to ask for a user name and password.
    I have never installed a password.
    Can I uninstall this application?
    Anyone can shed some light on this?
    I thank you all.
    John

    Hello

    You can try to disable the "password protected sharing" in WIndows 7. Here's how:

    http://www.groovypost.com/HOWTO/Microsoft/password-protect-sharing-in-Windows-7/

    LC

  • QSettings works only one way?

    I created a color object:

    Color myColor;
    

    The implementation, I did this:

    QSettings settings; // organization and app name set previously
    myColor = settings.value("mycolor").value();
    

    So far so good, but when I try to save the color:

    settings.setValue("mycolor", myColor);
    

    I get an error:

    No function call corresponding to ' QSettings::setValue(const char[12], bb:cascades::Color&)

    I've been reviewing the docs here (find "QVariant and Types of GUI" on the page)

    https://developer.BlackBerry.com/Cascades/reference/qsettings.html

    Any ideas?

    QVariant is QtCore class and does not work with bb::cascades classes. Try to convert to QColor first (not tested):

    bb::cascades::Color myColor;
    QColor color(myColor.red() * 255, myColor.green() * 255, myColor.blue() * 255, myColor.alpha() * 255);
    settings.setValue("color", color);
    

    Reading requires a reverse conversion.

  • Homegroup sharing only one-way

    I just installed windows 7 on my laptop and desktop. I created a homegroup easily and it works fine as I get info on my desktop from my laptop. However, my office is unable to see all the information on my laptop. I tried to turn off my antivirus and firewall on both computers, tried to leave, join and create a whole new homegroup. Nothing seems to work. These are two installs I own outside the AVG 9 and now some programs, but nothing big because they are new. Any ideas?

    I use a Netgear WGT624 v3 router. My office is currently running windows 7 pro, and my laptop is under Home Premium. They both have a lot of power.

    Hi jtskier1200r,
     
    First of all, I suggest you Open Homegroup troubleshooter on your desktop.
     
    If your computer has problems viewing computers or shared files in your homegroup, try to use the resolution of the problems of the residential group to solve the problem. It ensures that your computer different network services work correctly, and that your computer is a member of a homegroup.
     
    Open the homegroup troubleshooting utility
    http://Windows.Microsoft.com/en-us/Windows7/open-the-HomeGroup-Troubleshooter
     
    If that does not come to the top with conclusive answers, you can check whether or not network discovery is turned on in your office.
     
    If network discovery is off, turn it on.
     
    Enable or disable network discovery
    http://Windows.Microsoft.com/en-us/Windows7/enable-or-disable-network-discovery
     
    Also files and printers, sharing on both machines.
     
    Activate the file sharing and printers (valid also for Windows 7)
    http://Windows.Microsoft.com/en-us/Windows-Vista/enable-file-and-printer-sharing
     
    See also:
     
    Why I can't join a homegroup?
    http://Windows.Microsoft.com/en-us/Windows7/why-can-t-I-join-a-HomeGroup
     
    FYI: If you have set passwords, make sure the passwords are the same on both machines.

    Aziz Nadeem - Microsoft Support

  • AirDrop only works one way between iMac and MacBook Air

    Hello

    Surely I can't be the only one with this problem. I searched online help and followed all of the suggestions, but nothing works. I can AirDrop OF my MacBook Air (OS X Yosemite, mi 2013 construction) to the iMac (OS X El Capitan, end 2013) almost 100% of the time, but NOT vice versa. The iMac won't discover the MB Air. I even tried "find an old MAc" - no go. Drop settings are as well 'discovered by everybody' and the privacy settings firewall does not block incoming signals.

    Does anyone have a solution to short to go to the Genius bar?

    Thanks for your help, Cinilla

    You use a third-party software that modifies the behavior of the trackpad or Magic Mouse, such as "BetterTouchTool" or "MagicPrefs? If so, please, turn it off, then log off or restart the computer and test.

  • Is it only a one-way sync?

    It does not appear the changes I do either Illustrator or Indesign gets returned to the application?  It would be really great.  Maybe I'm not saving correctly?  In any case, looks very promising!

    J.

    It is one-way. The application of the model is to make a model, a "global," sketching a layout.

    The file is sent to InDesign/Illustrator/Photoshop for the realization of the project.

    He actually quite brilliantly designed and implemented, especially for a 1.0 release.

Maybe you are looking for

  • Need to recover the laptop HP G60

    Trying to recover a laptop.  I know that the disc is good that I pulled and plugged into a USB device and scanned to get rid of malware that took out the boot sector. I can start on a Win 7 (from MSDN) installation disc and I can boot to the BIOS men

  • How to change the COM2 to COM1 in Windows 98

    It lists, in my system under Virtual Ports infrared properties Port LPT, Infrafred's virtual COM port Communications Port (COM2) and the printer ECP (LPT1) Port.  I have a request I attach serial to serial port cable.  I believe that the application

  • addition of removed windows xp home

    I got the black screen of death, my system has been removed from the addition of windows xp at home and didn't return until I can get the original program that has been installed on my computer?

  • my files has increased from 3 000 to 3 days without program installed, how can I delete unnecessary files safely?

    With no program installs or any change to the actual system W.7, in three days my record amount raised by 3 000 records. This weird me based on any change or new program installs, etc etc. How do I find and remove unnecessary files or duplicate? Used

  • Delete a Bluetooth partnership

    Is there a limit on the number of matches Bluetooth device will support? I am assuming that this varies depending on the version of OS and perhaps platforms. What happens when the maximum is reached and the connection attempt is performed by a connec