VPN only 1 end allows the transmission

Hello

Worked on a question VPN site to site of weeks now and I still can't solve, would appreciate anyones help (where is Keith Barker when you need him ;)

Basically, a branch on a 5505 VPN for the main office, simple site to another, everything works fine.

Main office has a new building with a new 5515 ASA. you will need to move the VPN connection to this new ASA.

created the tunnel VPN rises without problem (all good isakmp)

However, only the branch can be seen to pass, he gets nothing in return. You can see on the end of the siege, he receives these packets transmitted but nothing in return. Let to believe that the issue is on this new ASA.

Here is the result to see the crypto ipsec her both:

#pkts program: encrypt 0, #pkts: 0, #pkts digest: 0
#pkts decaps: 14, #pkts decrypt: 14, #pkts check: 14
compressed #pkts: 0, unzipped #pkts: 0
#pkts uncompressed: 0, comp #pkts failed: 0, #pkts Dang failed: 0
success #frag before: 0, failures before #frag: 0, #fragments created: 0
Sent #PMTUs: 0, #PMTUs rcvd: 0, reassembly: 20th century / of frgs #decapsulated: 0
      
      
#pkts program: 14, #pkts encrypt: 14, #pkts digest: 14
#pkts decaps: 0, #pkts decrypt: 0, #pkts check: 0
compressed #pkts: 0, unzipped #pkts: 0
#pkts uncompressed: 14, comp #pkts failed: 0, #pkts Dang failed: 0
success #frag before: 0, failures before #frag: 0, #fragments created: 0
Sent #PMTUs: 0, #PMTUs rcvd: 0, reassembly: 20th century / of frgs #decapsulated: 0

I don't know why he used to convey, any help is the apprecited

keys, cryptographic cards are good, that they have been checked. using PFS with DH2

Phase: 3
Type: NAT
Definition of dynamic 172.17.10.1/0 to 81.128.141.106/64164

In looking at packet - trace, it seems to be reflecting the source of 172.17.10.1to 81.128.141.106 when sending the package to 192.168.7.1.

Can you confirm if you have the correct nat exemption for that traffic.
Please let us know of the natting command used for this side.

Kind regards
Dinesh Moudgil

PS Please rate helpful messages.

Tags: Cisco Security

Similar Questions

  • Satellite L100-120: Wlan does not allow the transmission of large data packets

    Satellite L100-120, Intel 3945ABG.
    Router Wi - fi is 3COM OfficeConnect Wireless, same problem with Dlink DI-524.

    By default my wi - fi card does not allow the transmission of packets of data.

    I use ping-f-l 1464 192.168.1.1 to check if it is possible to send a large package. All packages more then 600 large fail to be sent.

    It is tragically wireless performance and I almost cannot use internet at all. I solved the problem partially by setting the MTU to map wi - fi at 548. Connection is now stable, although I can not yet send massive emails. Anyway, it is not a good situation to have such a low MTU value.

    Everybody respected this problem?

    I think you will find the solution in this announcement:
    http://forums.computers.Toshiba-Europe.com/forums/thread.jspa?threadID=15101

    I think the secret is the update of the BIOS!

  • Panoramic via changes in the 'Position' product pan keyframes only at * end * of the clip

    Hello. I have tried to create pans through shots of forfeiture relatively shortly. When I do this by making two keyframes for Position, the pan happens quickly in the last tenth of the clamp, or so. To make the dish itself play out through the full clip, I do an anchor of keyframes. I don't care, but you can simply drag the image with this value - you must manually manipulate the values X and Y.

    I don't know if it's important, but I work with Photo-JPEG clips which can be several gigabytes in size. The resolution of images in the breast are often above 4000 x 4000, which explains why I want to do some mussels (to show the subject in full resolution).

    Any ideas?

    Thank you

    Joel

    Your position coordinates are the same for each keyframe. You should not have any movement between them when he reads now. If you were panoramic 1021.6 value would be different.

    Do you have another keyframe in the clip with a different value that you trimmed on the timeline? If so, the values (and the insueing movement) would be to interpolate after your second keyframe.

    Time-remapping? What is happening with the keyframe here?

  • Allowing the VPN Clients to the management network - nat woes

    Try to allow the VPNClient IPSEC access to the management network.  packet trace stops on the vpn encrypt even through phase 7 States it's NAT EXEMPT, he said his tent still NAT by a static.  The only thing I can think to put a rule of nat exempted for the subnet on the external interface.

    Please notify.  Thank you.

    Phase: 1
    Type: ACCESS-LIST
    Subtype:
    Result: ALLOW
    Config:
    Implicit rule
    Additional information:
    MAC access list

    Phase: 2
    Type: FLOW-SEARCH
    Subtype:
    Result: ALLOW
    Config:
    Additional information:
    Not found no corresponding stream, creating a new stream

    Phase: 3
    Type:-ROUTE SEARCH
    Subtype: entry
    Result: ALLOW
    Config:
    Additional information:
    in 0.0.0.0 0.0.0.0 outdoors

    Phase: 4
    Type: ACCESS-LIST
    Subtype: Journal
    Result: ALLOW
    Config:
    Access-group MANAGEMENT-IN in the management interface
    access-list MANAGEMENT-IN-scope ip allowed any one
    Additional information:

    Phase: 5
    Type: IP-OPTIONS
    Subtype:
    Result: ALLOW
    Config:
    Additional information:

    Phase: 6
    Type: FOVER
    Subtype: Eve-updated
    Result: ALLOW
    Config:
    Additional information:

    Phase: 7
    Type: NAT-FREE
    Subtype:
    Result: ALLOW
    Config:
    match ip MANAGEMENT 10.10.10.0 255.255.255.0 outside 172.18.0.32 255.255.255.240
    Exempt from NAT
    translate_hits = 3, untranslate_hits = 33
    Additional information:

    Phase: 8
    Type: NAT
    Subtype:
    Result: ALLOW
    Config:
    static (MANAGEMENT, outside) 203.23.23.75 10.10.10.10 netmask 255.255.255.255
    MANAGEMENT ip 10.10.10.10 host game OUTSIDE of any
    static translation at 203.23.176.75
    translate_hits = 0, untranslate_hits = 1
    Additional information:

    Phase: 9
    Type: NAT
    Subtype: host-limits
    Result: ALLOW
    Config:
    static (MANAGEMENT, outside) 203.23.23.75 10.10.10.10 netmask 255.255.255.255
    MANAGEMENT ip 10.10.10.10 host game OUTSIDE of any
    static translation at 203.23.23.75
    translate_hits = 0, untranslate_hits = 1
    Additional information:

    Phase: 10
    Type: VPN
    Subtype: encrypt
    Result: DECLINE
    Config:
    Additional information:

    Result:
    input interface: MANAGEMENT
    entry status: to the top
    entry-line-status: to the top
    output interface: OUTSIDE
    the status of the output: to the top
    output-line-status: to the top
    Action: drop
    Drop-reason: flow (acl-drop) is denied by the configured rule

    -EXCERPT FROM CONFIG-

    CorpVPN to access extended list ip 10.10.10.0 allow 255.255.255.0 172.18.0.32 255.255.255.240
    Access extensive list ip 172.18.0.32 CorpVPN allow 255.255.255.240 10.10.10.0 255.255.255.0

    mask 172.18.0.33 - 172.18.0.46 255.255.255.240 IP local pool CorpVPN

    access-list MANAGEMENT-extended permitted tcp 172.18.0.32 255.255.255.240 host 10.10.10.11 eq ssh
    access-list MANAGEMENT-extended permitted tcp 172.18.0.32 255.255.255.240 host 10.10.10.10 eq ssh
    access-list MANAGEMENT-extended permitted tcp 172.18.0.32 255.255.255.240 host 10.10.10.13 eq 3389

    access-list 101 extended allow ip 10.10.10.0 255.255.255.0 172.18.0.32 255.255.255.240

    NAT 0 access-list (MANAGEMENT) No.-NAT-DU-MGMT
    access-list no.-NAT-DU-MGMT scope ip 10.10.10.0 allow 255.255.255.0 172.18.0.32 255.255.255.240

    CorpVPN to access extended list ip 10.10.10.0 allow 255.255.255.0 172.18.0.32 255.255.255.240
    Access extensive list ip 172.18.0.32 CorpVPN allow 255.255.255.240 all

    internal CorpVPN group strategy
    attributes of Group Policy CorpVPN
    value of server DNS 203.23.23.23
    VPN - connections 8
    VPN-idle-timeout 720
    Protocol-tunnel-VPN IPSec l2tp ipsec
    Split-tunnel-policy tunnelspecified
    value of Split-tunnel-network-list CorpVPN
    the address value CorpVPN pools

    type tunnel-group CorpVPN remote access
    attributes global-tunnel-group CorpVPN
    address pool CorpVPN
    Group Policy - by default-CorpVPN
    IPSec-attributes tunnel-group CorpVPN
    pre-shared key

    First of all, there is overlap crypto ACL with the VPN static L2L:

    crypto ASA1MAP 10 card matches the address 101

    access-list 101 extended allow ip 10.10.10.0 255.255.255.0 172.18.0.32 255.255.255.240
    access-list 101 extended allow ip 172.18.0.32 255.255.255.240 10.10.10.0 255.255.255.0

    I would remove the 2 lines of ACL 101 above because it is incorrect.

    Secondly, from the output of ' cry ipsec to show his ", you seem to be getting the ip address of the"jdv1.australis.net.au", not"CorpVPN"pool pool. Therefore, the No. NAT ACL on the management interface is incorrect. I would just add a greater variety of education no. NAT so that it covers all your ip pool:

    access-list no.-NAT-DU-MGMT scope ip 10.10.10.0 allow 255.255.255.0 172.18.0.0 255.255.255.0

    Thirdly, even with your dynamic ACL 'OUTSIDE_cryptomap_65535.65535' crypto map, it only covers the 172.18.0.32/28, so I just want to add a wider range since it seems you get the ip address of the different pool:

    OUTSIDE_cryptomap_65535.65535 list of allowed ip extended access all 172.18.0.0 255.255.255.0

    Then I would disable the following group of access for purposes of test first:

    no access-group MANAGEMENT - OUT Interface MANAGEMENT

    Finally, please clear all the SA on your ASA and xlate, then reconnect to your vpn client and test it again:

    delete the ipsec cry his

    clear the isa cry his

    clear xlate

    Please let us know how it goes after the changes. If it still doesn't work, please please send again the last configuration and also to send the output of the following:

    See the isa scream his

    See the ipsec scream his

    and a screenshot of the page of statistics on your vpn client. Thank you.

  • I can't view attachments in my Yahoo email account since I upgraded to Firefox 8. The only option is to download all attachments. There used miniatures at the end of the email to view them. I checked with Internet Explorer and it works properly.

    I can no longer view attachments in my Yahoo email account, since I upgraded to Firefox 8. The only option is to download all attachments. There used miniatures at the end of the email to view them without having to download. I checked my email in Internet Explorer and it's the proper functioning and the thumbnail display. What can I do to solve this problem in Firefox?

    OK, now, they show. I restarted my computer again and they are showing now.

  • My names Contact list for Windows Live "disappeared". My ISP says it still resides in my computer, but only Microsoft can allow retrieving the list. What must I do to get these names?

    My names Contact list for Windows Live "disappeared". My ISP says it still resides in my computer, but only Microsoft can allow retrieving the list. What must I do to get these names?

    Hello

    The question you have posted is related to Windows Live; This is why it would be better suited in the Windows Live community. Please visit the link below to find a community that will provide the best support.

    http://windowslivehelp.com/forums.aspx?ForumID=28aff142-9106-4d74-BE08-9b5d9fc0efea

  • VPN; list of access on the external interface allowing encrypted traffic

    Hi, I have a question about the access list on the external interface of a router 836. We have several routers on our clients site, some are lan2lan, some are client2router vpn.

    My question is; Why should I explicitly put the ip addresses of the client vpn or tunnel lan to the access list. Because the encrypted traffic to already allowing ESPs & isakmp.

    The access list is set to the outgoing interface with: ip access-group 102 to

    Note access-list 102 incoming Internet via ATM0.1

    Note access-list 102 permit IP VPN range

    access-list 102 permit ip 192.123.32.0 0.0.0.255 192.123.33.0 0.0.0.255

    access-list 102 permit ip 14.1.1.0 0.0.0.255 any

    access-list 102 permit esp a whole

    Note access-list 102 Open VPN Ports and other

    access-list 102 permit udp any host x.x.x.x eq isakmp newspaper

    I have to explicitly allow 192.123.32.0 (range of lan on the other side) & 14.1.1.0 (range of vpn client) because if I'm not I won't be able to reach the network.

    The vpn connection is not the problem, all traffic going through it.

    As far as I know, allowing ESPs & isakmp should be sufficient.

    Can anyone clarify this for me please?

    TNX

    Sebastian

    This has been previously answered on this forum. See http://forums.cisco.com/eforum/servlet/NetProf?page=netprof&CommCmd=MB%3Fcmd%3Dpass_through%26location%3Doutline%40%5E1%40.ee9f970/0#selected_message for more details.

  • This allows the customer Cisco VPN through PIX

    Hello. I seeks to allow the client VPN Cisco of LAN of the company to remote resources.

    It's put PAT in place on the PIX and I'll add the following lines to the ACL in the inside interface to allow access to the customer:

    permit tcp x.x.x.x y.y.y.y eq 50

    permit tcp x.x.x.x y.y.y.y eq 51

    permit udp x.x.x.x y.y.y.y eq 500

    permit udp x.x.x.x y.y.y.y eq 4500

    I have not done something like this before so I don't know if that will be enough to allow the connection of the client to remote resources.

    I have to do something else to make it work?

    That should be good for the local pix, but make sure that nat-traversal is enabled on the remote device.

    ESP and ah protocols, not ports. 50 and 51.

    esp x.x.x.x y.y.y.y permit

    allowed ah x.x.x.x y.y.y.y

    permit udp x.x.x.x y.y.y.y eq 500

    permit udp x.x.x.x y.y.y.y eq 4500

  • My computer will not allow the installation of the Adobe Air software, a message informs you that I must refer to the administrator. I am the only user on this machine

    My computer will not allow the installation of the Adobe Air software, a message informs you that I must refer to the administrator, I'm the only user on this computer.   Help please.

    Thank you, Nicholas Cooper.

    Here you go:

    1. Right click on the installer.
    2. Click on "Run as Administrator".
  • Hi, I have bought LR6 and installed cloud creative ok, but when you go to installation of Lr, it allows only one installation of the trial version, the other options are to buy. I expect that when I pay 129 euros for the LR I can install it easily and not

    I bought LR6 and installed cloud creative ok, but when you go to installation of Lr, it allows only one installation of the trial version, the other options are to buy.

    Serialize Lightroom trial to activate like Lightroom 6 CC

    https://helpx.Adobe.com/Lightroom/KB/serialize-Lightroom-CC-trial-to-activate-as-Lightroom - 6.html

  • Help! Illustrator crashed unexpected when I work with her. Only a reboot allows, after abandoning the preferences. Who knows what bug this is?

    Help! Illustrator crashed unexpected when I work with her. Only a reboot allows, after abandoning the preferences. Who knows what bug this is?

    If we could, we could make a lot of money, solve problems.

    But unfortunately, we can not just from your description. Please give us the details.

    What version?

    What system?

    Third-party plug-ins?

    All corrupt fonts?

    What hardware is connected?

    You have a printer installed?

    Font management?

    What exactly were you doing when it crashed?

  • IAM trying to install Adobe In Design CS2 but only allowing the use of 30 days... Do you know how I can get this to run as needed?

    IAM trying to install Adobe In Design CS2 but only allowing the use of 30 days... Do you know how I can get this to run as needed?

    The activation servers have been closed several years ago. See Adobe - CS2 downloads

  • Can I need separate videos to allow a user to 'Play All' (from the beginning to the end) and select certain sequences (ceremony, reception which the sequence chosen start and end at the rest of the video and not the sequence, speech etc.)?

    Hi - I'm obviously new to yet, but that's what I want to do.

    In a wedding video, I want them to be able to:

    1 play the movie from start to finish.

    2. Select a sequence (say speech) who plays since the beginning of the sequence to the END of the whole video.

    So do I need 1 video for the room, as well as 4 sequences - reception, cake, speech, dance?

    Colin

    You can use separate videos or a single video. The only video is easier for your desired navigation. You will find more people asking how to get the 'chapter' or the video scene at the rear to a menu when it ends and also have a game all. So ignore the advice on those.

    Simple video:

    Your single video goes on a timeline. 'Play all' is a button in the timeline, and the timeline has an end action of "last menu."

    Menu of chapter has 4 buttons (plus a fifth to return to the main menu), going to each respective chapter marker. There is no action to end on chapter markers, so when a new chapter is reached, he continues to play as the piece all the.

    Several videos:

    Each video goes on his own script. The end of video action a timeline is timeline two video etc. Play all is a button that goes to the timeline one. The chapter menu also has a button go to chapter one, and it works identical to the play all. Each of the chapter buttons go to their respective chapter deadlines.

    Still may have some problems with a certain time lag, but I do not think that they affect either of these workflows. Don't rely on the preview again; burn a test disc and play on a DVD player.

  • Firefox is refreshing all pages of a Web site only and adding # at the end of the URL - it may be the cause?

    In my workplace, I use Firefox version 5.0.1 on Windows XP. When you access pages on the Web site http://www.sqa.org.uk (it is used the website of my place of work), pages refresh approximately every 30 seconds to a minute, and a sign # is added at the end of the URL in the address bar.

    This does not occur on all other sites, but it occurs also with colleagues who also have the same version of Firefox. I have disabled the extensions, had removed then reinstalled Firefox but the problem just occurred.

    You have any ideas?

    Clear the cache and cookies from sites that cause problems.

    "Clear the Cache":

    • Tools > Options > advanced > network > storage (Cache) offline: 'clear now '.

    'Delete Cookies' sites causing problems:

    • Tools > Options > privacy > Cookies: "show the Cookies".

    Start Firefox in Firefox to solve the issues in Safe Mode to check if one of the extensions of the origin of the problem (switch to the DEFAULT theme: Firefox (Tools) > Add-ons > appearance/themes).

  • allow. for one only if specific status, the current user is the owner

    Hello

    I want that a user can set and save a specific status, only if he is the owner of the account.

    I tried to set up a workflow in the account type field:
    ([< AccountType >] = ValRech ("ACCOUNT_TYPE", "Client approved") AND +...) (current user = account owner) +*.

    I think it's something with session NQ, but I can't find the proper syntax.

    Could you please help me?

    thx a lot

    Jon.

    Hi, use this your validation:

    UserValue ('') = []

    Ady

Maybe you are looking for