<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Try adding this command: in VPN</title>
    <link>https://community.cisco.com/t5/vpn/cannot-ping-remote-site-over-remote-access-vpn/m-p/2911984#M110313</link>
    <description>&lt;P&gt;Try adding this command:&lt;/P&gt;
&lt;PRE class="prettyprint"&gt;same-security-traffic permit intra-interface&lt;/PRE&gt;</description>
    <pubDate>Thu, 14 Jul 2016 21:07:09 GMT</pubDate>
    <dc:creator>Philip D'Ath</dc:creator>
    <dc:date>2016-07-14T21:07:09Z</dc:date>
    <item>
      <title>Cannot ping remote site over Remote Access VPN</title>
      <link>https://community.cisco.com/t5/vpn/cannot-ping-remote-site-over-remote-access-vpn/m-p/2911981#M110310</link>
      <description>&lt;P&gt;Hi I've a Site to Site tunnel running between a ASA 5520 (8.2 (2) ) and ASA 5510 (8.2(2)) code.&lt;/P&gt;
&lt;P&gt;The tunnels works fine and i can ping both ways.&lt;/P&gt;
&lt;P&gt;I've a remote Access VPN terminating to the 5520. Now i can ping anything within 5520 but not across ie nothing on 5540.&lt;/P&gt;
&lt;P&gt;Similarly if i connect to 5540 i can ping 5540 but not 5520.&lt;/P&gt;
&lt;P&gt;I had done split tunnel previously but now i pushed a default route and it still the same.&lt;/P&gt;
&lt;P&gt;when i do a debug icmp trace on 5520 i see debugs when i ping the 5520 but no icmp debugs when i ping the 5510.&lt;/P&gt;
&lt;P&gt;Checked all configuration but it i did not found anything.&lt;/P&gt;
&lt;P&gt;Please help.&lt;/P&gt;
&lt;P&gt;Config files are attached.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Okay after huge debugging i found this in asp drop&lt;/P&gt;
&lt;P&gt;8: 13:22:07.610350 10.10.80.201 &amp;gt; 10.10.60.1: icmp: echo request Drop-reason: (unable-to-create-flow) Flow denied due to resource limitation&lt;BR /&gt;&amp;nbsp; 11: 13:22:10.992441 10.10.80.201 &amp;gt; 10.10.60.1: icmp: echo request Drop-reason: (unable-to-create-flow) Flow denied due to resource limitation&lt;BR /&gt;&amp;nbsp; 18: 13:22:15.719521 10.10.80.201 &amp;gt; 10.10.60.1: icmp: echo request Drop-reason: (unable-to-create-flow) Flow denied due to resource limitation&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I checked on the firewall and there is no resource or connection crunch&lt;/P&gt;
&lt;P&gt;privatis(config)# sh mem&lt;BR /&gt;Free memory:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 348097056 bytes (65%)&lt;BR /&gt;Used memory:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 188773856 bytes (35%)&lt;BR /&gt;-------------&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ----------------&lt;BR /&gt;Total memory:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 536870912 bytes (100%)&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;privatis(config)# sh resource usage&lt;BR /&gt;Resource&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Current&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Peak&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Limit&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Denied Context&lt;BR /&gt;SSH&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 4&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 5&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0 System&lt;BR /&gt;Conns&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 6&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 325&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 280000&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0 System&lt;BR /&gt;Xlates&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 579&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; N/A&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0 System&lt;BR /&gt;Hosts&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 12&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 202&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; N/A&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0 System&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Not sure if this is a bug or something.&lt;/P&gt;</description>
      <pubDate>Sat, 22 Feb 2020 04:53:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/vpn/cannot-ping-remote-site-over-remote-access-vpn/m-p/2911981#M110310</guid>
      <dc:creator>sabyasachi161</dc:creator>
      <dc:date>2020-02-22T04:53:18Z</dc:date>
    </item>
    <item>
      <title>You'll need to extended your</title>
      <link>https://community.cisco.com/t5/vpn/cannot-ping-remote-site-over-remote-access-vpn/m-p/2911982#M110311</link>
      <description>&lt;P&gt;You'll need to extended your site to site VPN to also include the pool of IP addresses used for the remote access VPN. &amp;nbsp;Then you'll need to check your NAT rules.&lt;/P&gt;</description>
      <pubDate>Sun, 10 Jul 2016 21:15:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/vpn/cannot-ping-remote-site-over-remote-access-vpn/m-p/2911982#M110311</guid>
      <dc:creator>Philip D'Ath</dc:creator>
      <dc:date>2016-07-10T21:15:47Z</dc:date>
    </item>
    <item>
      <title>Hi Philip,</title>
      <link>https://community.cisco.com/t5/vpn/cannot-ping-remote-site-over-remote-access-vpn/m-p/2911983#M110312</link>
      <description>&lt;P&gt;Hi Philip,&lt;/P&gt;
&lt;P&gt;Thanks for looking into this. I'm not sure if you have looked into the config yet.&lt;/P&gt;
&lt;P&gt;Here are the snippets&lt;/P&gt;
&lt;P&gt;nat (inside) 0 access-list vpn-nat0&lt;/P&gt;
&lt;P&gt;access-list vpn-nat0 extended permit ip 10.10.80.0 255.255.254.0 10.10.60.0 255.255.254.0&lt;/P&gt;
&lt;P&gt;ip local pool ra-pool 10.10.80.200-10.10.80.250 mask 255.255.254.0&lt;/P&gt;
&lt;P&gt;This is the crypto map&lt;/P&gt;
&lt;P&gt;crypto map cybertron 20 match address decepticons2&lt;BR /&gt;crypto map cybertron 20 set peer 207.166.133.2&lt;/P&gt;
&lt;P&gt;access-list decepticons2 extended permit ip 10.10.80.0 255.255.254.0 10.10.60.0 255.255.254.0&lt;/P&gt;
&lt;P&gt;Please note that both sites can access each other and the tunnel is up&lt;/P&gt;
&lt;P&gt;However the Remote users cannot ping remote site but can ping local site.&lt;/P&gt;
&lt;P&gt;I still see the same errors&lt;/P&gt;</description>
      <pubDate>Thu, 14 Jul 2016 16:10:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/vpn/cannot-ping-remote-site-over-remote-access-vpn/m-p/2911983#M110312</guid>
      <dc:creator>sabyasachi161</dc:creator>
      <dc:date>2016-07-14T16:10:44Z</dc:date>
    </item>
    <item>
      <title>Try adding this command:</title>
      <link>https://community.cisco.com/t5/vpn/cannot-ping-remote-site-over-remote-access-vpn/m-p/2911984#M110313</link>
      <description>&lt;P&gt;Try adding this command:&lt;/P&gt;
&lt;PRE class="prettyprint"&gt;same-security-traffic permit intra-interface&lt;/PRE&gt;</description>
      <pubDate>Thu, 14 Jul 2016 21:07:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/vpn/cannot-ping-remote-site-over-remote-access-vpn/m-p/2911984#M110313</guid>
      <dc:creator>Philip D'Ath</dc:creator>
      <dc:date>2016-07-14T21:07:09Z</dc:date>
    </item>
    <item>
      <title>Its already added</title>
      <link>https://community.cisco.com/t5/vpn/cannot-ping-remote-site-over-remote-access-vpn/m-p/2911985#M110314</link>
      <description>&lt;P&gt;Its already added&lt;/P&gt;
&lt;P&gt;boot system disk0:/asa804-k8.bin&lt;BR /&gt;ftp mode passive&lt;BR /&gt;&amp;lt;--- More ---&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&lt;BR /&gt;same-security-traffic permit inter-interface&lt;/P&gt;</description>
      <pubDate>Fri, 15 Jul 2016 11:00:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/vpn/cannot-ping-remote-site-over-remote-access-vpn/m-p/2911985#M110314</guid>
      <dc:creator>sabyasachi161</dc:creator>
      <dc:date>2016-07-15T11:00:25Z</dc:date>
    </item>
    <item>
      <title>Hi, </title>
      <link>https://community.cisco.com/t5/vpn/cannot-ping-remote-site-over-remote-access-vpn/m-p/2911986#M110315</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I checked the config you did and so far, they are fine on ASA5520. To you have a dynamic site to site between the two ASAs or static site to site ?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 15 Jul 2016 16:34:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/vpn/cannot-ping-remote-site-over-remote-access-vpn/m-p/2911986#M110315</guid>
      <dc:creator>Dina Odeh</dc:creator>
      <dc:date>2016-07-15T16:34:52Z</dc:date>
    </item>
    <item>
      <title>There is nothing dynamic here</title>
      <link>https://community.cisco.com/t5/vpn/cannot-ping-remote-site-over-remote-access-vpn/m-p/2911987#M110316</link>
      <description>&lt;P&gt;There is nothing dynamic here. The Peers has been statically defined on each firewall.&lt;/P&gt;
&lt;P&gt;Any thoughts ?&lt;/P&gt;
&lt;P&gt;NOTE: I added both Same-security command and there is no difference.&lt;/P&gt;</description>
      <pubDate>Sat, 16 Jul 2016 05:31:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/vpn/cannot-ping-remote-site-over-remote-access-vpn/m-p/2911987#M110316</guid>
      <dc:creator>sabyasachi161</dc:creator>
      <dc:date>2016-07-16T05:31:18Z</dc:date>
    </item>
    <item>
      <title>I just read the error more</title>
      <link>https://community.cisco.com/t5/vpn/cannot-ping-remote-site-over-remote-access-vpn/m-p/2911988#M110317</link>
      <description>&lt;P&gt;I just read the error more closely. It is complaining about a resource limitation. &amp;nbsp;As you note, there does not appear to be a resource limitation. &amp;nbsp;So perhaps we have a &amp;nbsp;software bug. &amp;nbsp;Can you upgrade to at least 8.4(7)?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="http://www.cisco.com/c/en/us/td/docs/security/asa/asa82/command/reference/cmd_ref/s2.html"&gt;http://www.cisco.com/c/en/us/td/docs/security/asa/asa82/command/reference/cmd_ref/s2.html&lt;/A&gt;&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;Name: unable-to-create-flow&lt;BR /&gt;Flow denied due to resource limitation:&lt;BR /&gt; This counter is incremented and the packet is dropped when flow creation fails due to &lt;BR /&gt;a system resource limitation. The resource limit may be either:&lt;BR /&gt; 1) system memory&lt;BR /&gt; 2) packet block extension memory&lt;BR /&gt; 3) system connection limit&lt;BR /&gt; Causes 1 and 2 will occur simultaneously with flow drop reason "No memory to complete &lt;BR /&gt;flow".&lt;BR /&gt;Recommendation:&lt;BR /&gt; - Observe if free system memory is low.&lt;BR /&gt; - Observe if flow drop reason "No memory to complete flow" occurs.&lt;BR /&gt; - Observe if connection count reaches the system connection limit with the command &lt;BR /&gt;"show resource usage".&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;</description>
      <pubDate>Sat, 16 Jul 2016 06:54:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/vpn/cannot-ping-remote-site-over-remote-access-vpn/m-p/2911988#M110317</guid>
      <dc:creator>Philip D'Ath</dc:creator>
      <dc:date>2016-07-16T06:54:07Z</dc:date>
    </item>
    <item>
      <title>Hi, </title>
      <link>https://community.cisco.com/t5/vpn/cannot-ping-remote-site-over-remote-access-vpn/m-p/2911989#M110318</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Okay, I checked the config for ASA5510 but I couldn't find any site to site tunnel with 5520, that's why I asked if we have a dynamic there.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Mainly, we need to add in the crypto ACL on the 5510 ASA to permit the traffic to the VPN pool and fix NAT also there.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 16 Jul 2016 08:18:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/vpn/cannot-ping-remote-site-over-remote-access-vpn/m-p/2911989#M110318</guid>
      <dc:creator>Dina Odeh</dc:creator>
      <dc:date>2016-07-16T08:18:01Z</dc:date>
    </item>
    <item>
      <title>I changed the VPn pool ip</title>
      <link>https://community.cisco.com/t5/vpn/cannot-ping-remote-site-over-remote-access-vpn/m-p/2911990#M110319</link>
      <description>&lt;P&gt;I changed the VPn pool ip scope and that seems to have fixed the issue.&lt;/P&gt;
&lt;P&gt;Earlier this pool was overlapping with Inside ip scope which caused the issue.&lt;/P&gt;</description>
      <pubDate>Mon, 06 Mar 2017 08:13:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/vpn/cannot-ping-remote-site-over-remote-access-vpn/m-p/2911990#M110319</guid>
      <dc:creator>sabyasachi161</dc:creator>
      <dc:date>2017-03-06T08:13:47Z</dc:date>
    </item>
  </channel>
</rss>

