VPN site to Site with ASA 5520 * please help *.

I am using two ASA 5520, and try to put up a site to site VPN.  This seems to be pretty simple, but I'm on my third day of train this is up and running. Both 5520's are running the latest 9.1 (5) IOS.

Please note: I replaced it with [#1-WAN IP] and [#2-WAN IP] for WAN IP of the ASA addresses.

Thanks in advance for any help you may have.

-------------------------------------------------------------------------------------------------------------------------------------------------

ASA 5520 # 1:

Crypto ikev1 allow outside

the local object of net network
10.0.0.0 subnet 255.255.255.0

net remote object network
172.20.0.0 subnet 255.255.255.0

outside_1_cryptomap list of allowed ip object local net net access / remote

tunnel-group [IP #2-WAN] type ipsec-l2l

IPSec-attributes tunnel-group [#2-WAN IP]
pre-shared-key cisco123

IKEv1 crypto policy 10
preshared authentication
3des encryption
sha hash
Group 2
life 86400

Crypto ipsec transform-set ikev1 SHA-ESP-3DES esp-3des esp-sha-hmac

card crypto oustide_map 1 match address outside_1_cryptomap
card crypto oustide_map 1 set transform-set ESP-3DES-SHA ikev1
card crypto outside_map 1 set pfs Group1
map 1 set outside_map crypto peer [#2-WAN IP]
outside_map interface card crypto outside

NAT (inside, outside) 1 local static source net net-local destination static remote net net / remote

-------------------------------------------------------------------------------------------------------------------------------------------------

ASA 5520 #2:

Crypto ikev1 allow outside

the local object of net network
172.20.0.0 subnet 255.255.255.0

net remote object network
10.0.0.0 subnet 255.255.255.0

outside_1_cryptomap list of allowed ip object local net net access / remote

tunnel-group [#1-WAN IP] type ipsec-l2l

IPSec-attributes tunnel-group [#1-WAN IP]
pre-shared-key cisco123

IKEv1 crypto policy 10
preshared authentication
3des encryption
sha hash
Group 2
life 86400

Crypto ipsec transform-set ikev1 SHA-ESP-3DES esp-3des esp-sha-hmac

card crypto oustide_map 1 match address outside_1_cryptomap
card crypto oustide_map 1 set transform-set ESP-3DES-SHA ikev1
card crypto outside_map 1 set pfs Group1
map 1 set outside_map crypto peer [#1-WAN IP]
outside_map interface card crypto outside

NAT (inside, outside) 1 local static source net net-local destination static remote net net / remote

Try to correct the mistakes in the two configs.

In some places, you have 'oustide_map' where you need "outside_map".

Tags: Cisco Security

Similar Questions

  • Unable to connect to creative cloud but can connect to the adobe site... Please help

    Unable to connect to creative cloud but can connect to the adobe site... Please help

    already done. without success. now chat with adobe helpdesk. Thank you

  • I use xport 360 and I can't put my save game back on the program profile it shows a circle with a cross please help me

    I use xport 360 and I can't put my save game back on the program profile it shows a circle with a cross please help me

    Hello

    If you try to recover the gamer tag, then I suggest you follow the steps from the link below: http://support.xbox.com/en-us/pages/xbox-live/how-to/xbox-live-account-management/gamer-profile.aspx

    If this does not work then I recommend you to ask your question here: http://forums.xbox.com/xbox_forums/xbox_support/default.aspx

    Hope this information is useful.

  • master password bios for hp mini 1151 with code 2MC92472WZ please help. THX

    master password bios for hp mini 1151 with code 2MC92472WZ please help. THX

    Hello

    Try to enter: 74eo7vx7d0

    Kind regards

    DP - K

  • Site to Site with ASA and FortiGate

    I have setup a VPN site-to site between my ASA and FortiGate customers. The tunnel rises with success, but we can not pass traffic. When I do a packet capture on my ASA, I see traffic on the port of entry as usual, but on the output port, the source address gets NAT had I checked all statements of NAT, and there is a statement NAT exempted from the entry port to the port of exit and in the VPN configuration.

    Then your oder of NAT statements in probably wrong. The dynamic NAT for outgoing traffic must be at the end (I put them always in article 3), while the Exemption must be at the beginning of Section 1.

  • Cisco Anyconnect VPN and IPSEC coexist on ASA 5520?

    Can a Cisco ASA 5520 which has been configured as IPSEC VPN gateway and also be configured as a gateway ANYCONNECT VPN and vpn IPSEC service anyconnect vpn clients clients maintenance at the same time? Any negative impact on the performance or any other problem that everyone knows?

    I guess that by 2 connection limit, you are referring to the 2 licenses for anyconnect?  You should consider using the anyconnect essentials license, which is relatively cheap (100-200 dollars I think) and will take you to the edge of the platform with anyocnnect.

    You shouldn't have any problem using IPSEC with LDAP client.  It is quite common - my company is IPSEC as Anyconnect off the coast of the same interface using authentication ldap (even same-group policy) for the two.

    -Jason

  • How to fix a navigation bar for site version phone. Please help me!

    Hello World! Please help me!
    For some time working on my new Web site in Adobe Muse.
    We finished version for desktop and now I try to create version for phones. I want to le site to stay the main menu in the upper part of the page.
    I do not know How I can get stuck here because PIN button does not work in Adobe phone version Muse.
    I saw this on other sites so it is possible.

    Please, how do this.


    Thank you very much for your help!

    You can try to use the effect of scrolling Panel by setting the element you want to move during scrolling at all zeros.

    If you use this static menu on the master page, and then create a top layer and put these static elements on this layer, so the rest of the Captain and normal pages will have their content well sliding under the menu.

  • Card problems or video driver with a N200, please help!

    I have a lenovo 3000 N200, that's really cool, works even at games very well, including the most recent.

    But, is it normal that the pilot program display for freeze-out in Warcraft 3? He always does that when you access the list of cards in the game and after 3-5 minutes during a real game. It defines the resolution up to 640 X 480 (from 1280 X 800) and in 16 colors. I have to reset it to get it to work. Also, it does the same thing in Spore - if after seeing the pilot written for Spore installed, (that I downloaded from the lenovo site) I have not encountered this problem far. In addition, Second Life stops - Fortunately it does not freeze the drivers. I understand that the model I have is not designed for the game, but if it can run Warhammer 40 k: Soulstorm with graphics settings meduim (on the widescreen) without a lagg I do not understand why it would not be able to manage warcraft 3 - even a m200 express ATi can manage. I mean that a X 3100 to Intel must be much more powerful. (ATi said card lagg with older games like Unreal Tournament)

    I have the latest version of the - official - driver and a Win Xp pro Sp2. I always keep my system updated - register for Essilor, but until this driver has not need sp3 - and cleaned viruses.

    Please help me?

    Ooh, it seems that I was right, my problems stems from the incompatibility of the software.

    Namely the based opengl driver (this igfx something of the file that is in the rror reports I receive).

    I solved the problem with Warcraft 3, you have to click with the right button on the icon of warcraft 3 and type the destination line (just after the second "")-opengl or - swtnl. (or - d3d, nota bene, who has not worked for me)

    Although even now it's not as pretty as on my table top pc, it works fine and farily good graphics.

    I think your problem is similar to mine and is amplified - sort of - by Vista somehow, it seems to cause a more severe software incompatibility.

  • MuseJSAssert:Error calls the function selection: TypeError: cannot get the "init" reference to undefined property or no, I am a beginner and not able to solve this problem with my website, please help...

    Everytime I open my site I get this error "MuseJSAssert: Errot calling function selection: TypeError: cannot get the"init"reference to undefined property or null" and I was a newbie am not able to solve this problem.

    error.png

    I did take all measures please help.

    Hello

    Can try you it on another browser that the problem does not come up on top of our end.?

    Kind regards

    Akshay

  • weird problem with new screen, please help

    Hello people,

    I hope someone can help. I am using windows 7 Home premium and I hope it is a simple solution that someone has met before. It's just that I don't know how to describe it so can't type into google to find an answer.

    This happens in all programs, Firefox, ms word Opera, basically any window I opened. The bar menu at the top of the screen is a transparent white color and everything works well, but after 50 or 60 seconds, it turns into a transparent, I can still read the Word editing, display etc. file. This is where the scroll wheel on the mouse and what I'm typing stops working. When I type something with the mounted volume, all I hear is a single beep whenever I tap on a button, but nothing is actually typed. Now, all I have to do is click anywhere in the window and it works again, but only for 50-60 seconds. I had to click on the screen twice since I started typing this because when I look at the screen, everything I typed is not there because the menu bar's transparent again while I was typing. Its driving me crazy.

    I don't remember what is a problem before, if it was I would have surely noticed. The only thing that has changed is I had been using my 32 LCD TV as a screen for a long time, but I moved and did not bring my TV with me, so I use the PC came with the computer screen. It's a PC I bought my sister a few years ago so I never used the PC screen that comes with it so don't know if it happened when she or what, she has, she can remember either. I have a updated driver, did not work. Changes the settings in customize and cannot do it helped either.

    Monitor: monitor LCD Compaq CQ1859

    Do I something pressed or clicked on something by accident?

    Is there a setting some part that I forgot?

    I plan to cast the spell by the window, its really annoying.

    Please help guys and ladies.

    Hello salamander.

    Please contact Microsoft Community.

    I can understand the inconvenience caused, be assured that we are here to help with your concern.

    1. What is the model of the computer and do ?
    2. Do you see an error message when the menu bar is transparent?

    Please follow the link below and include a screenshot in your post,

    http://answers.Microsoft.com/en-us/Windows/wiki/windows_other-windows_programs/how-to-include-a-screenshot-in-your-post/2594b08e-32a3-476A-85A6-b021181be7e4

    I suggest you follow the methods below to see if it helps.

    Method 1:

    Clean boot: to help troubleshoot error messages and other issues, you can start Windows by using a minimal set of drivers and startup programs. This type of boot is known as a "clean boot". A clean boot helps eliminate software conflicts.  Here is the link for your reference perform the clean boot.

    http://support.Microsoft.com/kb/929135

    Important: please go through the section: How to reset the computer to start as usual after a clean boot troubleshooting section of Kb to start the computer to a normal startup after you fix the problem.

    Note: If the problem persists, continue with method 2

    Method 2:

    Check the problem by disabling the Aero transparency feature. Please follow the steps below to disable the Aero transparency feature.

    1. Right-click on a vacuum of space on the desktop and click on personalize.
    2. Click on the link to the color of the window at the bottom of the window.
    3. Uncheck the check box enable transparency to disable transparency and check the issue.

    For more information, aero feature please refer to the link below.

    http://Windows.Microsoft.com/en-us/Windows7/what-is-the-Aero-desktop-experience

    Note: If the problem persists, continue with method 3

    Method 3:

    A Malware - scanner The Microsoft Security Scanner is a downloadable security tool for free which allows analysis at the application and helps remove viruses, spyware and other malware. It works with your current antivirus software. Please follow the steps below to use the scan to Microsoft Security.

    • Run the scanner from Microsoft from the link below:

    http://www.Microsoft.com/security/scanner/en-us/default.aspx

    • Click on download now and click Run.
    • Choose complete system scan and wait for the full analysis.

    Important: The data files that are infected must be cleaned only by removing the file completely, which means that there is a risk of data loss.

    The above information was hoping to get useful, please return it to us if you need additional assistance.

  • Slaughter of BG sound with another class please help!

    Hey hope someone can shine a light on this for me, been stuggling with that for awhile now.

    I had a background sound to play, which is in a separate category codes:

    Class: screen_Control

    public function randonizer_SND (): void

    {

    var r: int = Math.floor (Math.random () * 17);

    if (r == 1)

    {

    currentBG_SND = snd1_BG;

    }

    if (r == 2)

    {

    currentBG_SND = snd2_BG;

    }

    if (r == 3)

    {

    currentBG_SND = snd3_BG;

    }

    if (r == 4)

    {

    currentBG_SND = snd4_BG;

    }

    if (r == 5)

    {

    currentBG_SND = snd5_BG;

    }

    if (r == 6)

    {

    currentBG_SND = snd6_BG;

    }

    if (r == 7)

    {

    currentBG_SND = snd7_BG;

    }

    if (r == 8)

    {

    currentBG_SND = snd8_BG;

    }

    if (r == 9)

    {

    currentBG_SND = snd9_BG;

    }

    if (r == 10)

    {

    currentBG_SND = snd10_BG;

    }

    if (r == 11)

    {

    currentBG_SND = snd11_BG;

    }

    if (r == 12)

    {

    currentBG_SND = snd12_BG;

    }

    if (r == 13)

    {

    currentBG_SND = snd13_BG;

    }

    if (r == 14)

    {

    currentBG_SND = snd14_BG;

    }

    if (r == 15)

    {

    currentBG_SND = snd15_BG;

    }

    if (r == 16)

    {

    currentBG_SND = snd16_BG;

    }

    playSND();

    }

    public function playSND (): void

    {

    snd_BG_Channel = currentBG_SND.play (0,1);

    snd_BG_Transform.volume = 1;

    snd_BG_Channel.soundTransform = snd_BG_Transform;

    snd_BG_Channel.addEventListener (Event.SOUND_COMPLETE, nextSnd);

    }

    nextSnd(event:Event):void of the public service

    {

    randonizer_SND();

    }

    Is what I try to achieve this sound to stop playing when a "button" is linked and then start playing again back in the main screen.

    The "button" is controlled in a different category, and when I try to put a stop function there is to the sound I have the following error:

    1119: access of property may be undefined snd_BG_Channel through a reference with static type class.

    This is the code I use to try to stop the channel:

    screen_Control.snd_BG_Channel.stop ();

    If you have an idea of what I'm doing wrong please help!

    THX pavel

    Did you check this line? public var snd_BG_Channel:SoundChannel;

    Must be:

    public static var snd_BG_Channel:SoundChannel;

  • Problem with clips nested, please help!

    Help, please!

    I have a movieclip symbol, let's say, a ball that bounces with a stop(); action on frame 14.

    And I have another movieclip symbol which has a text that cross the screen with a stop(); action on the frame of 10.

    The main time line, I would like to that ball to start bouncing on frame 2 and stop frame 15, so I placed it on its own layer with a keyframe on frame 2.

    I want, the symbol of the text to start on frame 6 and stop on frame 15 also, so I placed it on its own layer with a keyframe on frame 6.

    It does not work.

    When I play it back, the Visual jump wildly back and forth between the symbols.

    What should I do?

    I work in Adobe Flash CS3. ActionScript 3.0, 30 frames per second, Player 9 (not sure if this is relevant, but just in case).

    Please help me, I'm desperate, I can't understand it.

    Thank you!

    Hello

    I'm so clear with what you're saying...

    You have a movieclip that has its own animation of scenario of a bouncing ball and it stop on chassis 14? Even with text movieclip - he has his own animation of script for simple horizontal interpolation that ends on the frame of 10?
    And you placed these clips on the stage, put them on their own layers and moved the mc of ball to frame 2 and the text in the box 6 mc?

    Are there blank keyframes before the frame 2 on image 6 of the text layer and layer of ball? If not, then select frame 1 layer on the ball and press F7 to make an empty keyframe. Do the same on the text layer but select images 1-5 and click F7 to make them blank keyframes.
    What you don't want to do, is show the movieclip before the beginning of their animation. Therefore, you get the wild flashing.

    Also extended these layers to frame of 15 images? Otherwise, click on frame 15 (for the two layers) and press F5 to add frames.

    And you order stop() on plot of 15? Otherwise, create a new layer, call it actions and put a stop() on frame 15 command.

    Sure that your movie will play correctly now.

    NOTE: Just out of curiosity - why don't simply animate you everything on the main timeline?

  • Error Code 43 with Nvidea GTX650, please help

    Hello, I currently just bought a Nvidea GTX650 graphics card, I installed all the drivers according to the instructions to however I am unable to access all the games. I explored this further and entered my Manager device and found that my Nvidea GTX650 has an error code 43 for him. I tried the uninstall/install/upgrade to update all the drivers but no luck, please help :)), here are my system specs.

    map of mother Foxconn h61mxl-k

    Nvidea EVGA Gtx650 2 GB GPU

    4 gb ddr3 RAM

    650ub ATX powersupply

    Processor Intel Pentium G620 2.60 GHz

    Windows 7 operating system

    any help would be appreciated thanks.

    Hello

    As you have tried all possible steps and still the problem persists, I would say to contact Nvidia support team check what they have to say on this issue.

    You can also view Code 43: Windows has stopped this device because it has reported problems

    It will be useful.

  • Failover of VPN for data/VoIP through ASA 5520 or 7204 VXR

    I would like to install a VPN failover for my remote sites using broadband 3dn/1up.  They are mainly 2800 routers.    I like options for end hub a pair of Cisco ASA active / standby and a 7204 VXR.  Voice and data will travel down the VPN failover and I intend to have QOS/Traffic shaping in place to better meet the needs for VoIP as possible.  I need to do it on about 150 sites. My questions are:

    1. What is the best why the ASA or the 7204

    2 Will VoIP packets pass through the two in the same way

    3 as far as redistributing routes can I use GRE on an ASA or should I keep all static. NH on the SAA is an L3 switch.

    4. an ASA with 100 mg of bandwithd through metro E supports 150 tunnels making VoIP and data. 1 to 3 calls per site max.

    Thank you

    J R

    To answer your questions: -.

    1. who is better for this, the ASA or the 7204 - ASA, is what is designed to do.

    2 packages VoIP Will cross both the same way - Yes

    3 as far as redistributing routes can I use GRE on an ASA or should I keep all static. NH on the SAA is an L3 switch. -l'ASA does not support GRE tunnels.

    4. an ASA with 100 mg of bandwithd through metro E supports 150 tunnels making VoIP and data. 1 to 3 calls per site max. -It depends on the model of the SAA, see the below matrix for thru-put http://www.cisco.com/en/US/products/ps6120/prod_models_comparison.html

    HTH >

  • How to establish a tunnel vpn ipsec using DNS with ASA 5505?

    Hello

    I m get a dynamic IP address public and what I m trying to do is establish a tunnnel remote vpn using IPSec, which I realize my provider but each time resets of sessions or ASA 5505 reset, I get a new public IP and I need to put the new IP address on the remote client, so I can establish the vpn...

    How can I establish a vpn ipsec using DNS?  For this scenario, the remote client vpn is a vpn phone, but it could be any vpn client.

    Private private Public IP IP IP

    PBX - Telephone (LAN) - ASA 5505-(Internet)-(router) Remote Site-(LAN) VPN-

    Kind regards!

    Ah ok I see, Yes in this case there is no that you can do other than request a static IP address from your ISP.

    Kind regards.

    PS: Don't forget to mark this question as answered. Thank you!

Maybe you are looking for