VPN launched only one way
Does anyone have an idea why a site to site VPN tunnel could only be put in place a way? I have a pix to connect to a vpn tunnel using NAT - T IPSEC concentrator. Since the hub if I initiate traffic to the pix, the tunnel rises and then I can access resources behind the hub on the side pix.
If I try to open the flow of the side pix, the tunnel will not come to the top. Debugging on the pix, it's not even trying to open the tunnel.
Here is an excerpt of the pix config:
Crypto ipsec transform-set esp-3des esp-sha-hmac bench
map TestMap 10 ipsec-isakmp crypto
card crypto TestMap 10 corresponds to the address ACL_VPN
card crypto TestMap 10 peer set 10.10.10.1
card crypto TestMap 10 set transform-set bench
TestMap outside crypto map interface
ISAKMP allows outside
ISAKMP key * address 10.10.10.1 netmask 255.255.255.255
ISAKMP nat-traversal 20
part of pre authentication ISAKMP policy 10
ISAKMP policy 10 3des encryption
ISAKMP policy 10 sha hash
10 2 ISAKMP policy group
ISAKMP life duration strategy 10 86400
I'm just using 10. address of the top for the peer for example. The ACL_VPN specifies local/remote subnets correctly. The default route is the external interface of the pix.
The hub, I've specified that the tunnel is bidirectional.
Everyone why it will undertake only a way to any idea?
See you soon
Brian
Thanks for posting your "ACL_VPN" and your NAT Exemption ACL ACL.
Thank you!
Tags: Cisco Security
Similar Questions
-
Cisco IPSec VPN works only one way.
I'm hitting my head against the wall for more than 2 weeks now. I can't get this figured out.
We have 2 locations and a server with an Internet service provider. Currently, we are connecting to our Internet service provider via a vpn ipsec to our headquarters. later, we will add the 1 direction.
The problem is the following. My vpn is in place, I can ping my local ip address, my IP of the tunnel, the remote tunnel interface, the vlan remote or the gateway, but I can't ping anything you wanted. The branch to the ISP I ping the router in the Internet service provider's domain controller and the server very well. but I can't ping or talk about anything either at the Office on the side of the IAF. and so I can not communicate with any host on the LAN. Can someone please help me with this?
Can I unload the configs of the two routers here someone watching?
Thanks in advance.
Exemption from the NAT on the end server must include the following reject order:
NAT extended IP access list
5 deny ip 10.1.20.0 0.0.0.255 10.178.164.128 0.0.0.127
Disable the ip nat translation before testing again.
-
Traffic permitted only one-way for VPN-connected computers
Hello
I currently have an ASA 5505. I put up as a remote SSL VPN access. My computers can connect to the VPN very well. They just cannot access the internal network (192.168.250.0). They cannot ping the inside interface of the ASA, nor any of the machines. It seems that all traffic is blocked for them. The strange thing is that when someone is connected to the VPN, I can ping this ASA VPN connection machine and other machines inside the LAN. It seems that the traffic allows only one way. I messed up with ACL with nothing doesn't. Any suggestions please?
Pool DHCP-192.168.250.20 - 50--> for LAN
Pool VPN: 192.168.250.100 and 192.168.250.101
Outside interface to get the modem DHCP
The inside interface: 192.168.1.1
Courses Running Config:
: Saved
:
ASA Version 8.2 (5)
!
hostname HardmanASA
activate the password # encrypted
passwd # encrypted
names of
!
interface Ethernet0/0
switchport access vlan 20
!
interface Ethernet0/1
switchport access vlan 10
!
interface Ethernet0/2
switchport access vlan 10
!
interface Ethernet0/3
Shutdown
!
interface Ethernet0/4
Shutdown
!
interface Ethernet0/5
Shutdown
!
interface Ethernet0/6
Shutdown
!
interface Ethernet0/7
switchport access vlan 10
!
interface Vlan1
No nameif
no level of security
no ip address
!
interface Vlan10
nameif inside
security-level 100
IP 192.168.250.1 255.255.255.0
!
interface Vlan20
nameif outside
security-level 0
IP address dhcp setroute
!
passive FTP mode
DNS lookup field inside
DNS domain-lookup outside
pager lines 24
Within 1500 MTU
Outside 1500 MTU
mask 192.168.250.100 - 192.168.250.101 255.255.255.0 IP local pool VPN_Pool
ICMP unreachable rate-limit 1 burst-size 1
don't allow no asdm history
ARP timeout 14400
Global interface 10 (external)
NAT (inside) 10 192.168.250.0 255.255.255.0
Timeout xlate 03:00
Timeout conn 01:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02
Sunrpc timeout 0:10:00 h323 0:05:00 h225 mgcp from 01:00 0:05:00 mgcp-pat 0:05:00
Sip timeout 0:30:00 sip_media 0:02:00 prompt Protocol sip-0: 03:00 sip - disconnect 0:02:00
Timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute
timeout tcp-proxy-reassembly 0:01:00
Floating conn timeout 0:00:00
dynamic-access-policy-registration DfltAccessPolicy
the ssh LOCAL console AAA authentication
Enable http server
http 192.168.250.0 255.255.255.0 inside
No snmp server location
No snmp Server contact
Server enable SNMP traps snmp authentication linkup, linkdown cold start
life crypto ipsec security association seconds 28800
Crypto ipsec kilobytes of life - safety 4608000 association
Telnet timeout 5
SSH 192.168.250.0 255.255.255.0 inside
SSH timeout 5
SSH version 2
Console timeout 0
dhcpd dns 8.8.8.8
!
dhcpd address 192.168.250.20 - 192.168.250.50 inside
dhcpd allow inside
!
a basic threat threat detection
Statistics-list of access threat detection
no statistical threat detection tcp-interception
WebVPN
allow outside
SVC disk0:/anyconnect-win-2.5.2014-k9.pkg 1 image
SVC disk0:/anyconnect-macosx-i386-2.5.2014-k9.pkg 2 image
Picture disk0:/anyconnect-linux-2.5.2014-k9.pkg 3 SVC
enable SVC
tunnel-group-list activate
attributes of Group Policy DfltGrpPolicy
value of server DNS 8.8.8.8
Protocol-tunnel-VPN IPSec l2tp ipsec svc webvpn
tunnel-group AnyConnect type remote access
tunnel-group AnyConnect General attributes
address pool VPN_Pool
tunnel-group AnyConnect webvpn-attributes
enable AnyConnect group-alias
!
class-map inspection_default
match default-inspection-traffic
!
!
type of policy-card inspect dns preset_dns_map
parameters
maximum message length automatic of customer
message-length maximum 512
Policy-map global_policy
class inspection_default
inspect the preset_dns_map dns
inspect the ftp
inspect h323 h225
inspect the h323 ras
Review the ip options
inspect the netbios
inspect the rsh
inspect the rtsp
inspect the skinny
inspect esmtp
inspect sqlnet
inspect sunrpc
inspect the tftp
inspect the sip
inspect xdmcp
!
global service-policy global_policy
context of prompt hostname
no remote anonymous reporting call
call-home
Profile of CiscoTAC-1
no active account
http https://tools.cisco.com/its/service/oddce/services/DDCEService destination address
email address of destination [email protected] / * /
destination-mode http transport
Subscribe to alert-group diagnosis
Subscribe to alert-group environment
Subscribe to alert-group monthly periodic inventory
monthly periodicals to subscribe to alert-group configuration
daily periodic subscribe to alert-group telemetry
Cryptochecksum:30fadff4b400e42e73e17167828e046f
: end
Hello
No worries
As we change the config I would do as well as possible.
First, it is strongly recommended to use a different range of IP addresses for VPN clients and the internal network
No VPN_Pool 192.168.250.100 - 192.168.250.101 255.255.255.0 ip local pool mask
mask 192.168.251.100 - 192.168.251.101 255.255.255.0 IP local pool VPN_Pool
NAT_0 ip 192.168.250.0 access list allow 255.255.255.0 192.168.251.0 255.255.255.0
NAT (inside) 0-list of access NAT_0
Then give it a try and it work note this post hehe
-
Hello
Since yesterday (2016-01-26) the following error portfolio:
Messages sent from a BlackBerry device are received, but the messages that I send to a BlackBerry smartphone get only the check box, but no D or R marking.
I use BBM on an Android phone, with the most recent version 2.11.0.18
Try to solve the problem I did the following steps - but none of them changed something in the behaviour:
. Restart of BBM
. Restaring the phone
. Reinstalling BBM
. Try BBM on two other Android devices
. Try to create a group - for this my invitation was received by the BlackBerry device, but cannot be accepted
. You try to join a group - I received the invitation and I could accept it, but the group does not appear
. Try a cat prlvate
. Try another account
The only thing that works is the exchange between two Android devices.
Another curiosity: yesterday and today, that one message has send - only!
I have some other ideas that I could try to solve the problem - did someone knows more? Is there a network BlackBerry problem?
Today, I was able to exchange a few messages again, it seams to work again.
Without changing anything.
-
BlackBerry Smartphones help BB Storm will synchronize only one way
When I enter an appointment in my calendar from device, and then try Outlook 2003 calendar SYC, it will not be synchronized (appointments appear in my Outlook calendar). If I enter my Outlook calendar appointment it will synchronize the appointments on my device. I have entered in the configuration of the Fund Manager and assign the two-way synchronization. Still no luck.
I found the problem. When you create a new appointment, there is an article that says "send help:" this is a list of all email addresses you receive from emails on your Blackberry. In some ways, the email address was changed to another. This has caused the problem of synchronization. Once I changed it to one that was already there, the two way sync worked.
I still don't know where you configure what email address it uses. If someone knows let me know. Or email to three addresses are emails that I synchronize in Outlook.
-
BlackBerry Smartphones Yahoo contacts synchronizes only one way
Sync OTA between the Contacts of Yahoo and the BB address book synchronizes only Yahoo for my BB. If I make changes on a contact in Yahoo, it appears on the BB in 4 hours. But if I make a change to a contact on my BB, the change does not appear in Yahoo. Does anyone else have this problem or does anyone know if this is supposed to work this way or not?
After you delete the account of the phone completely and then add, everything worked normally. In fact, it seems to be synchronization immediately, rather than the 4 hour time limit specified in the master of BIS.
-
Hello
my iphone 4S calendar calendar app and google used to synchronize with each other, but only the application of the phone's calendar now receives new entries.
IE: no appointment I do on the phone do not appear on my calendar google on a computer. It is a new problem, but I don't think I've changed settings to icloud. I've read through similar forum posts. Any ideas?Thank you
Your profile says you have an iPhone 4 running iOS 7.1.2 s. I'll assume that you have indeed an iPhone 4s, but it runs the latest version of iOS (9.3.2).
Open the calendar on your iPhone app. Click on the "Calendars" button at the bottom in the Center. Are shown the correct calendars? Are you sure when you add an event on the iPhone, he's going to the desired calendar?
-
VMotion migration works only one way...
I have 2 hosts running ESX 4.0 I installed Vcenter and I use the VSphere GUI client to manage hosts.
I am able to perform dynamic migration from one host to another, but not the reverse, and when I try to run the
migration, I get the following error: "a general error has occurred: cannot create the log file supplied cannot open"/var/log/vmware/journal/1234xxxxxx.xx"to write" I don't think that it was due to lack of disk space.
Can someone help me?
Have you tried to connect to the console and check if it
is the space on the host by using the command 'df '? It's the
version ESX console I recommend you connect to the shell and
perform a "tail-f/var/log/vmkernel" as he tried to emigrate in the
a direction that does not work. I found that the error messages
reported in vCenter don't always point you in the right place. You
can get a little more information to facilitate your search, if it turns out not to make disk space.
-
Universal Clipboard works only one way
Hello
I have a MacBook Pro running Mac OS Sierra and an iPhone 5 iOS running 10 of the retina
Universal Clipboard does work for my Mac to my iPhone.
When you try to copy stuff from my iPhone Mac does not seem to be able to paste them.
I checked the time phone and Mac are recorded in the same Apple ID
The Wi - Fi or Bluetooth connection are on both devices
I disabled and enabled the transfer option in the settings of devices
Someone knows what to do?
Thanks, Idan
Me too. Exactly the same problem. I have iPhone 6 with iOS 10.0.1 and MacBook Air Early-2015 with macOS Sierra installed on Mac App Store, this morning. Mac & iPhone copy paste works, but the reverse is not.
-
Calendar only one-way synchronization
My iphone calendar events may not sync to my mac BUT my mac calendar events synchronize to my phone. What Miss me?
the fixed!
-
I have a desktop running Vista Home E. and a laptop running Windows 7. Home Edition
I can access my files on the "Vista Office" of the "Window7 laptop" but from the office, he continues to ask for a user name and password.
I have never installed a password.
Can I uninstall this application?
Anyone can shed some light on this?
I thank you all.
JohnHello
You can try to disable the "password protected sharing" in WIndows 7. Here's how:
http://www.groovypost.com/HOWTO/Microsoft/password-protect-sharing-in-Windows-7/
LC
-
QSettings works only one way?
I created a color object:
Color myColor;
The implementation, I did this:
QSettings settings; // organization and app name set previously myColor = settings.value("mycolor").value
(); So far so good, but when I try to save the color:
settings.setValue("mycolor", myColor);
I get an error:
No function call corresponding to ' QSettings::setValue(const char[12], bb:cascades::Color&)
I've been reviewing the docs here (find "QVariant and Types of GUI" on the page)
https://developer.BlackBerry.com/Cascades/reference/qsettings.html
Any ideas?
QVariant is QtCore class and does not work with bb::cascades classes. Try to convert to QColor first (not tested):
bb::cascades::Color myColor; QColor color(myColor.red() * 255, myColor.green() * 255, myColor.blue() * 255, myColor.alpha() * 255); settings.setValue("color", color);
Reading requires a reverse conversion.
-
Homegroup sharing only one-way
I just installed windows 7 on my laptop and desktop. I created a homegroup easily and it works fine as I get info on my desktop from my laptop. However, my office is unable to see all the information on my laptop. I tried to turn off my antivirus and firewall on both computers, tried to leave, join and create a whole new homegroup. Nothing seems to work. These are two installs I own outside the AVG 9 and now some programs, but nothing big because they are new. Any ideas?
I use a Netgear WGT624 v3 router. My office is currently running windows 7 pro, and my laptop is under Home Premium. They both have a lot of power.
Hi jtskier1200r,
First of all, I suggest you Open Homegroup troubleshooter on your desktop.
If your computer has problems viewing computers or shared files in your homegroup, try to use the resolution of the problems of the residential group to solve the problem. It ensures that your computer different network services work correctly, and that your computer is a member of a homegroup.
Open the homegroup troubleshooting utility
http://Windows.Microsoft.com/en-us/Windows7/open-the-HomeGroup-Troubleshooter
If that does not come to the top with conclusive answers, you can check whether or not network discovery is turned on in your office.
If network discovery is off, turn it on.
Enable or disable network discovery
http://Windows.Microsoft.com/en-us/Windows7/enable-or-disable-network-discovery
Also files and printers, sharing on both machines.
Activate the file sharing and printers (valid also for Windows 7)
http://Windows.Microsoft.com/en-us/Windows-Vista/enable-file-and-printer-sharing
See also:
Why I can't join a homegroup?
http://Windows.Microsoft.com/en-us/Windows7/why-can-t-I-join-a-HomeGroup
FYI: If you have set passwords, make sure the passwords are the same on both machines.Aziz Nadeem - Microsoft Support
-
AirDrop only works one way between iMac and MacBook Air
Hello
Surely I can't be the only one with this problem. I searched online help and followed all of the suggestions, but nothing works. I can AirDrop OF my MacBook Air (OS X Yosemite, mi 2013 construction) to the iMac (OS X El Capitan, end 2013) almost 100% of the time, but NOT vice versa. The iMac won't discover the MB Air. I even tried "find an old MAc" - no go. Drop settings are as well 'discovered by everybody' and the privacy settings firewall does not block incoming signals.
Does anyone have a solution to short to go to the Genius bar?
Thanks for your help, Cinilla
You use a third-party software that modifies the behavior of the trackpad or Magic Mouse, such as "BetterTouchTool" or "MagicPrefs? If so, please, turn it off, then log off or restart the computer and test.
-
Is it only a one-way sync?
It does not appear the changes I do either Illustrator or Indesign gets returned to the application? It would be really great. Maybe I'm not saving correctly? In any case, looks very promising!
J.
It is one-way. The application of the model is to make a model, a "global," sketching a layout.
The file is sent to InDesign/Illustrator/Photoshop for the realization of the project.
He actually quite brilliantly designed and implemented, especially for a 1.0 release.
Maybe you are looking for
-
Need to recover the laptop HP G60
Trying to recover a laptop. I know that the disc is good that I pulled and plugged into a USB device and scanned to get rid of malware that took out the boot sector. I can start on a Win 7 (from MSDN) installation disc and I can boot to the BIOS men
-
How to change the COM2 to COM1 in Windows 98
It lists, in my system under Virtual Ports infrared properties Port LPT, Infrafred's virtual COM port Communications Port (COM2) and the printer ECP (LPT1) Port. I have a request I attach serial to serial port cable. I believe that the application
-
addition of removed windows xp home
I got the black screen of death, my system has been removed from the addition of windows xp at home and didn't return until I can get the original program that has been installed on my computer?
-
With no program installs or any change to the actual system W.7, in three days my record amount raised by 3 000 records. This weird me based on any change or new program installs, etc etc. How do I find and remove unnecessary files or duplicate? Used
-
Delete a Bluetooth partnership
Is there a limit on the number of matches Bluetooth device will support? I am assuming that this varies depending on the version of OS and perhaps platforms. What happens when the maximum is reached and the connection attempt is performed by a connec