You try to run a Site to site VPN and remote VPN from the same IP remotely
We currently have a site to site VPN configuration between our offices call center and a 3rd party that allows them to access our training to their employees to use environment while being trained on our systems. This tunnel is running between our ASA and their ASA without problem; However, when we have managers come out to the call center, they are unable to use remote VPN to access our office.
Apparently the same IP peer remote that we use for our site to the other tunnel is the same IP that our managers use to access the internet when they are on-site with the customer. When I look at the logs it shows the VPN attempt and then I get treatment Information Exchange has failed. So from what I can understand when our managers are trying to connect to our firewall from the same IP address as the counterpart of site to site it automatically tries to create a tunnel, according to the information of the site to the other tunnel. If our managers are anywhere else, they can connect through remote VPN with no problems.
My question is if anyone knows of a way to make the firewall allow VPN site to site and remote connections with the same remote IP address.
Hi John,.
Basically, in older versions, when you hit a static encryption card and you does not match this static encryption completely map the connection continues until the dynamic encryption card. For this reason, you can connect your IPSec clients before. A bug has been opened on this vulnerability.
CSCuc75090 Details of bug
The crypto IPSec Security Association are created by dynamic crypto map to static peers
Symptom:
When a static VPN peer adds all traffic to the ACL crypto, a surveillance society is based even if the pair IP is not allowed in the acl to the main façade encryption. Are these SA finally put in correspondence and commissioning the dynamic crypto map instance.
Conditions:
It was a planned design since the first day that allowed customers to fall through in the case of static crypto map did not provide a necessary cryptographic services.
The SA must be made from a peer configured statically and a dynamic crypto map instance must be configured on the receiving end.
Workaround solution:
N/A
Some possible workarounds are:
Configure a static nat device when you try to use the remote VPN if the firewall remotely will be hit with a different public IP address. It would be a good solution, but it will depend on how many ip addresses public you have available, if you really want one of these ip addresses for that access.
Also, I thought you could use AnyConnect instead of the IPSec VPN client. I don't know how many users need to connect from your PC to the remote site, but the ASA has 2 licenses SSL available that you could use. Because Anyconnect uses the SSL protocol, it won't have a problem on your environment.
Below some information:
Hope this helps,
Luis.
Tags: Cisco Security
Similar Questions
-
On a five year MAcPro, when you try to open a document, all stored documents seem to open at the same time and any attempt to close results in the MacPRo gel for a long period. Ideas for cause and ideas for a solution?
You have a Mac Pro or a MacBook Pro?
-
debugger found running in your system, please, unload and remove it from the computer
I tried running of malicious software and microsoft security essential, but I always get this message when I try to open certain programs.
Hello
I suggest you check in SafeMode with network.
Method 1:
Step 1:
"A description of the Startup Mode options:
http://support.Microsoft.com/kb/315222
Step 2;
If you are able to start your computer in safe mode, I suggest you perform the clean boot and check.
How to configure Windows XP to start in a "clean boot" State
http://support.Microsoft.com/kb/310353
How to configure Windows to use a Normal startup state
After you have used the boot is a way to solve your problem, you can follow these steps to configure Windows XP to start normally.
1. click on start and then click Run.
2. type msconfig and click OK.
The System Configuration Utility dialog box appears.3. click on the tab general, click Normal Startup - load all services and device drivers and then click OK.
4. When prompted, click on restart to restart the computer.
Method 2:
I suggest to download and install the Microsoft safety scanner and run the scan and check.
http://www.Microsoft.com/security/scanner/en-us/default.aspx
Note: The Microsoft Safety Scanner ends 10 days after being downloaded. To restart a scan with the latest definitions of anti-malware, download and run the Microsoft Safety Scanner again.
Note: The data files that are infected must be cleaned only by removing the file completely, which means that there is a risk of data loss.
-
How to run a window of data acquisition and another pane at the same time
Hello
I have a main window for data acquisition and in front panel there are four Sub Vi. When the main window of data acquisition is running and at the same time if I run the Subvi - main window stops data acquisition and the secondary window starts to run. But I want to launch the window of acquisition of primary data and the pane at the same time. Please give me a solution for this...
Thanking in advance.
Nikhil
Hi Nikhil,
My explanation has answered your question. Take a look at the image as an attachment. Let us know if you have any other questions.
-
This shows up. Also in firefox and chrome. Other sites work fine!
Cannot delete, cannot be changed, can not even connect. I can not wait 30 days...Hello
The url in the error message does not exist in BusinessCatalyst. Did you add the field to any site of BC? Could you please try to connect by using the url of the system. If you continue to get this error message, please join the support team, and they will help you with this
Let me know if you have any question.
-
I have a box that keeps coming back that it has detected a new hardware - peripheral Bluetooth
and it won't go away. If I go through the process of installing software device driver he asks me questions on a disc and if I don't then check the other options and all other options does not work it is in place can not find device driver software. The problem is that's never on the computer as soon as I turn it on it won't go away don't anyone KNOW WHAT I CAN DO?Hello allysoni,
Thank you for using the Microsoft Windows Vista Forums.
I just want to check, your Bluetooth device work? Or it works and you are just be notified? What brand is your Bluetooth device and what type of computer you are on?
Have you went into Device Manager to verify that the drivers are all up to date? Go to start-> Type "Device Manager" in the search field-> select device-> you Manager see no yellow exclamation for one of your drivers? If so, right click and select "Update". If the driver is already updated, and then select uninstall. (You may be prompted to restart)
If you are not prompted to restart, click again on the device and select 'Install' please let us know status. Thank you!
Engineer James Microsoft Support answers visit our Microsoft answers feedback Forum and let us know what you think.
-
I am getting error 150:30 when you try to run Photoshop. What should I do?
When you try to run Photoshop, I get error: 150:30
Thanks for the info!
I reinstalled PS and I'm back to buisiness
Thanks again,
Joe
-
Run 2 Weblogic domains from the same console
Hello
I have a question.
Currently now I have 2 domains, each domain has been installed with the management server and managed servers.
I have 1 nodemanager.
During the installation of the areas I had to provide different ports for weblogic instances, so I have 2 different consoles to access the WL to manage the domains.
The question:
Is there a handy way and admin 2 different domains (which runs on the same machine) from the same console WL?
Thank youWe do not have a way to administer both weblogic from the same console.
But I think you can install Oracle Enterprise Manager to manage your middleware infrastructure.
-
I extracted to the terminal linux firefox in my own repertoire and you try to run the executable file called firefox. But he's saying "command not found".
You seem to have 64-bit Linux because Linux versions served on mozilla.org are 32-bit.
FTP://FTP.Mozilla.org/pub/Firefox/releases/21.0/Linux-x86_64/
-
Error when you try to run an application that worked when built with 8.6
I have a simple program that I wrote in the 8.6 version that I've never had a problem generation and execution of applications built with it to 8.6. Two weeks ago, I got 2009 by mail because we had very recently purchased 8.6 and I get errors when you try to run an application built with the same code using 2009. The error relates to the Mean.vi. He claims that he can't find it. The error I get is as follows:
Error loading VI 'NI_AALBase.lvlib:Mean.vi '. LabVIEW support 3 error code: could not load façade. I don't have access to the front panel of this vi, so I wonder if there is a problem with the runtime and not my code. Please answer as soon as possible because it will quickly start to the impact of my calendar. Thank you.
Hello!
The same problem ?
I talked with my local OR technical support team. The application now works without any problem.
Rule of thumb: when creating a Setup program do not forget that the option "Run Time Engine xxxx" in the category "Other installers" is selected despite the fact that the runtime is already installed.
Best regards.
-
Get "communication error with kernel" message when you try to run a virus scan program
Get "communication error with kernel" message when you try to run a virus scan program
Hello
What antivirus do you use?
Follow the steps in the article mentioned below and check if this solves the problem.
The error message "error communicating with kernel":
http://KB.eset.com/esetkb/index?page=content&ID=SOLN2280 -
I get the following when you try to run programs such as Nero:-"this program requires the file AdvrCntr6.dll, which is not on this system."
Please can you help me?
Original title: AdvrCntr6.dll
Hello.
There is a guide for fixing here:
http://pcsupport.about.com/od/findbyerrormessage/a/advrcntr6-DLL-not-found-missing-error.htm
-
Error when you try to run Quicken 2011: this program is not supported under XP
Win XP pro - Quicken 2011
I am running win XP pro. When you try to run Quicken 2011 I get an error message: this program is not supported under XP. What I do toget Quicken supported?
For help on Quicken, I recommend posting your question in the community live Quicken . The people there can help you better as we can in this forum of Windows. Boulder computer Maven
Most Microsoft Valuable Professional -
Error code 0 x 80248014 when you try to run MSE Update on Vista 64 bit OS
Tomb guard Windows Update crashes when you try to run the Service Pack 1 for Vista 64 even if it seems to have installed service pack when I view installed updates. Update the window continues to show the service pack update according to availability. So far, I ran it three times and he shows as installed three days in a row, but he does not appear in the properties view and continues to show an available update when I check for updates.
It's a little confusing because the error code 0 x 80248014 appears when you try to update to MSE, so there seems to be two issues. The MSE error one and two, the apparent success of the installation of the Service pack 1 for 64 bit Vista Home Premium but not appear in the properties view and always appear when checking for updates, even if each attempt to install appears to be successful.
Hello
Run the system update tool
http://Windows.Microsoft.com/en-us/Windows7/what-is-the-system-update-readiness-tool
Retry the update
Reset the Windows Update components
http://support.Microsoft.com/kb/971058/en-us
Error MSE - which describes the boots s. is what will do the above tools.
-
Original title;
Linksys wmp54g & windows vista
When you try to run Linksys Wireless Network Monitor I get the following errors:
Cannot load ProcNICs.dll
Failed to load Res_dll
Linksys wireless adapter is installed and running properly, but I can't use the application linksys to establish a new network connection.
Any suggestions?
Thank you.
Hello
I suggest you contact Linksys for assistance:
http://home.Cisco.com/en-us/home
Linksys Support link:
http://homesupport.Cisco.com/en-us/support
I hope that helps!
If you need help on Windows, please keep us informed.
We are here to help.
Maybe you are looking for
-
need to remove the search 4loot page you want normal firefox back
I loaded the search for 4loot.com through firefox screen, and now I can't figure out how to delete and return to the normal page of firefox. Search 4loot page is annoying.
-
I have Windows XP with update 3, when I run the software Ad-aware, I get the message they found:MyWebSearch 97\a0223553.dll (918), more it found 4 other items on my C:\System volume information\_restore (more a bucnh of #s ending with .dll extensions
-
Windows Firewall: what does it mean 'private profile '?
I guess that 'Private profile' refers to an IP address that does not perform routing to the Internet, but then, why is not called 'local' or 'LAN '? And why is it called a "profile"? I'm not trying to be semantically *-retentive or being here. In fac
-
Updated blackBerry Smartphones hotmail help!
I am looking for help on a message I received on my Blackberry Curve 8330. It's not to answer required action: message from update to update the password for my hotmail account. When I try to do it won't accept, yet when I try to set up a new account
-
How can I create on my Acer system recovery discs?
I need to store window 7 onDVD (back-up for window 7) for a brand new with Windows 7 operating system already in computer I compurt any new branch (ACER expires), already having Windows 7 installed. They advised me 1st step is to have a back-up for w