<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IPSEC Tunnel Traffic in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ipsec-tunnel-traffic/m-p/3220486#M1017331</link>
    <description>&lt;P&gt;You can't simulate it from outside. And&amp;nbsp;only looking at the result of the inside packet-tracer is not enough. Is NAT doing something unexpected like changing the traffic that it doesn't match any more the crypto-definition?&amp;nbsp;Based on the screenshot it could be something like that.&lt;/P&gt;</description>
    <pubDate>Tue, 21 Nov 2017 21:34:16 GMT</pubDate>
    <dc:creator>Karsten Iwen</dc:creator>
    <dc:date>2017-11-21T21:34:16Z</dc:date>
    <item>
      <title>IPSEC Tunnel Traffic</title>
      <link>https://community.cisco.com/t5/network-security/ipsec-tunnel-traffic/m-p/3219806#M1017319</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp;I haven't had much luck on responses to this however here goes. I have an IPSEC VPN tunnel up and connected. I can ping a remote IP address from a local address however I cannot Telnet to Port 55019 of the same remote IP Address. It seems that the Telnet traffic does not get sent to the IPSEC Tunnel. When I run ping I can see that the &lt;STRONG&gt;Bytes Tx&amp;nbsp;&lt;/STRONG&gt; and &lt;STRONG&gt;Bytes Rx&lt;/STRONG&gt; byte count in the result of the&amp;nbsp;&lt;STRONG&gt;show vpn-sessiondb l2l&amp;nbsp;&lt;/STRONG&gt;. When I run the Telnet command from the same PC the count does not change which means that the Telnet traffic is not entering the VPN.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp;Would appreciate any assistance forthcoming.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 14:47:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ipsec-tunnel-traffic/m-p/3219806#M1017319</guid>
      <dc:creator>rsatjharman</dc:creator>
      <dc:date>2020-02-21T14:47:59Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC Tunnel Traffic</title>
      <link>https://community.cisco.com/t5/network-security/ipsec-tunnel-traffic/m-p/3219932#M1017321</link>
      <description>&lt;P&gt;Hi there,&lt;/P&gt;
&lt;P&gt;What is the output of:&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;sh crypto map&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you have more that one crypto map entry, please tell us which index number it is.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;cheers,&lt;/P&gt;
&lt;P&gt;Seb.&lt;/P&gt;</description>
      <pubDate>Tue, 21 Nov 2017 08:02:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ipsec-tunnel-traffic/m-p/3219932#M1017321</guid>
      <dc:creator>Seb Rupik</dc:creator>
      <dc:date>2017-11-21T08:02:39Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC Tunnel Traffic</title>
      <link>https://community.cisco.com/t5/network-security/ipsec-tunnel-traffic/m-p/3219955#M1017324</link>
      <description>&lt;P&gt;Unless you have a really strange NAT-setup, it's likely that it is related to access-control (on your ASA or a device between the client&amp;nbsp;and the ASA). Simulate the traffic with the packet-tracer and observe the output.&lt;/P&gt;</description>
      <pubDate>Tue, 21 Nov 2017 08:20:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ipsec-tunnel-traffic/m-p/3219955#M1017324</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2017-11-21T08:20:15Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC Tunnel Traffic</title>
      <link>https://community.cisco.com/t5/network-security/ipsec-tunnel-traffic/m-p/3220331#M1017325</link>
      <description>Hi,&lt;BR /&gt;   Not really sure which command to run from the CLI however please find&lt;BR /&gt;attached a screenshot from the menu&lt;BR /&gt;</description>
      <pubDate>Tue, 21 Nov 2017 18:41:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ipsec-tunnel-traffic/m-p/3220331#M1017325</guid>
      <dc:creator>rsatjharman</dc:creator>
      <dc:date>2017-11-21T18:41:30Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC Tunnel Traffic</title>
      <link>https://community.cisco.com/t5/network-security/ipsec-tunnel-traffic/m-p/3220342#M1017326</link>
      <description>Result of the command: "sh crypto ipsec sa peer 124.240.212.118"&lt;BR /&gt;&lt;BR /&gt;peer address: 124.240.212.118&lt;BR /&gt;    Crypto map tag: SMSC, seq num: 1, local addr: 210.7.26.68&lt;BR /&gt;&lt;BR /&gt;      access-list outside_cryptomap_7 extended permit ip host 192.168.1.10&lt;BR /&gt;host 124.240.212.126&lt;BR /&gt;      local ident (addr/mask/prot/port): (192.168.1.10/255.255.255.255/0/0)&lt;BR /&gt;      remote ident (addr/mask/prot/port): (&lt;BR /&gt;124.240.212.126/255.255.255.255/0/0)&lt;BR /&gt;      current_peer: 124.240.212.118&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;      #pkts encaps: 3, #pkts encrypt: 3, #pkts digest: 3&lt;BR /&gt;      #pkts decaps: 3, #pkts decrypt: 3, #pkts verify: 3&lt;BR /&gt;      #pkts compressed: 0, #pkts decompressed: 0&lt;BR /&gt;      #pkts not compressed: 3, #pkts comp failed: 0, #pkts decomp failed: 0&lt;BR /&gt;      #pre-frag successes: 0, #pre-frag failures: 0, #fragments created: 0&lt;BR /&gt;      #PMTUs sent: 0, #PMTUs rcvd: 0, #decapsulated frgs needing&lt;BR /&gt;reassembly: 0&lt;BR /&gt;      #TFC rcvd: 0, #TFC sent: 0&lt;BR /&gt;      #Valid ICMP Errors rcvd: 0, #Invalid ICMP Errors rcvd: 0&lt;BR /&gt;      #send errors: 0, #recv errors: 0&lt;BR /&gt;&lt;BR /&gt;      local crypto endpt.: 210.7.26.68/0, remote crypto endpt.:&lt;BR /&gt;124.240.212.118/0&lt;BR /&gt;      path mtu 1500, ipsec overhead 74(44), media mtu 1500&lt;BR /&gt;      PMTU time remaining (sec): 0, DF policy: copy-df&lt;BR /&gt;      ICMP error validation: disabled, TFC packets: disabled&lt;BR /&gt;      current outbound spi: CD955D7B&lt;BR /&gt;      current inbound spi : 437B62FD&lt;BR /&gt;&lt;BR /&gt;    inbound esp sas:&lt;BR /&gt;      spi: 0x437B62FD (1132159741)&lt;BR /&gt;         transform: esp-aes-256 esp-sha-hmac no compression&lt;BR /&gt;         in use settings ={L2L, Tunnel, IKEv1, }&lt;BR /&gt;         slot: 0, conn_id: 1150976, crypto-map: SMSC&lt;BR /&gt;         sa timing: remaining key lifetime (sec): 3503&lt;BR /&gt;         IV size: 16 bytes&lt;BR /&gt;         replay detection support: Y&lt;BR /&gt;         Anti replay bitmap:&lt;BR /&gt;          0x00000000 0x0000001D&lt;BR /&gt;    outbound esp sas:&lt;BR /&gt;      spi: 0xCD955D7B (3449118075)&lt;BR /&gt;         transform: esp-aes-256 esp-sha-hmac no compression&lt;BR /&gt;         in use settings ={L2L, Tunnel, IKEv1, }&lt;BR /&gt;         slot: 0, conn_id: 1150976, crypto-map: SMSC&lt;BR /&gt;         sa timing: remaining key lifetime (sec): 3503&lt;BR /&gt;         IV size: 16 bytes&lt;BR /&gt;         replay detection support: Y&lt;BR /&gt;         Anti replay bitmap:&lt;BR /&gt;          0x00000000 0x00000001&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Tue, 21 Nov 2017 18:53:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ipsec-tunnel-traffic/m-p/3220342#M1017326</guid>
      <dc:creator>rsatjharman</dc:creator>
      <dc:date>2017-11-21T18:53:29Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC Tunnel Traffic</title>
      <link>https://community.cisco.com/t5/network-security/ipsec-tunnel-traffic/m-p/3220426#M1017327</link>
      <description>&lt;P&gt;Hi Karsten,&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; As it is at the moment the ACL only allows IP and also in the Crypto Map menu only IP is protected however I need to add TCP from 192.168.1.10/any to 124.240.212.126/55019. Have tried this a few times still did not work maybe I am doing something wrong.&lt;/P&gt;</description>
      <pubDate>Tue, 21 Nov 2017 20:26:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ipsec-tunnel-traffic/m-p/3220426#M1017327</guid>
      <dc:creator>rsatjharman</dc:creator>
      <dc:date>2017-11-21T20:26:08Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC Tunnel Traffic</title>
      <link>https://community.cisco.com/t5/network-security/ipsec-tunnel-traffic/m-p/3220439#M1017328</link>
      <description>&lt;P&gt;Hi Karsten,&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Ran the packet tracer on the inside and outside interface, packet allowed on the inside interface but disallowed on the outside interface&lt;/P&gt;</description>
      <pubDate>Tue, 21 Nov 2017 20:44:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ipsec-tunnel-traffic/m-p/3220439#M1017328</guid>
      <dc:creator>rsatjharman</dc:creator>
      <dc:date>2017-11-21T20:44:02Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC Tunnel Traffic</title>
      <link>https://community.cisco.com/t5/network-security/ipsec-tunnel-traffic/m-p/3220476#M1017329</link>
      <description>&lt;P&gt;TCP is part of IP, if you have allowed IP there is no need to allow TCP (or UDP or ICMP, ...) in addition.&lt;/P&gt;</description>
      <pubDate>Tue, 21 Nov 2017 21:28:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ipsec-tunnel-traffic/m-p/3220476#M1017329</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2017-11-21T21:28:08Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC Tunnel Traffic</title>
      <link>https://community.cisco.com/t5/network-security/ipsec-tunnel-traffic/m-p/3220478#M1017330</link>
      <description>&lt;P&gt;Okay so when I run the packet tracer it drops the packet on the outside interface there must be something else that I need to look at&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Nov 2017 21:31:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ipsec-tunnel-traffic/m-p/3220478#M1017330</guid>
      <dc:creator>rsatjharman</dc:creator>
      <dc:date>2017-11-21T21:31:09Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC Tunnel Traffic</title>
      <link>https://community.cisco.com/t5/network-security/ipsec-tunnel-traffic/m-p/3220486#M1017331</link>
      <description>&lt;P&gt;You can't simulate it from outside. And&amp;nbsp;only looking at the result of the inside packet-tracer is not enough. Is NAT doing something unexpected like changing the traffic that it doesn't match any more the crypto-definition?&amp;nbsp;Based on the screenshot it could be something like that.&lt;/P&gt;</description>
      <pubDate>Tue, 21 Nov 2017 21:34:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ipsec-tunnel-traffic/m-p/3220486#M1017331</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2017-11-21T21:34:16Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC Tunnel Traffic</title>
      <link>https://community.cisco.com/t5/network-security/ipsec-tunnel-traffic/m-p/3220496#M1017332</link>
      <description>Hi Karsten,&lt;BR /&gt;                 Any idea on where to look perhaps printout the NAT&lt;BR /&gt;settings etc....I'm stuck here everything else looks okay&lt;BR /&gt;</description>
      <pubDate>Tue, 21 Nov 2017 21:47:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ipsec-tunnel-traffic/m-p/3220496#M1017332</guid>
      <dc:creator>rsatjharman</dc:creator>
      <dc:date>2017-11-21T21:47:29Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC Tunnel Traffic</title>
      <link>https://community.cisco.com/t5/network-security/ipsec-tunnel-traffic/m-p/3220510#M1017441</link>
      <description>&lt;P&gt;There are sections for NAT in the packet-tracer. Showing your NAT-config ("show run nat") could also help.&lt;/P&gt;</description>
      <pubDate>Tue, 21 Nov 2017 22:06:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ipsec-tunnel-traffic/m-p/3220510#M1017441</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2017-11-21T22:06:45Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC Tunnel Traffic</title>
      <link>https://community.cisco.com/t5/network-security/ipsec-tunnel-traffic/m-p/3220521#M1017442</link>
      <description>Result of the command: "sh run nat"&lt;BR /&gt;&lt;BR /&gt;nat (inside,outside) source static PET_WB PET_WB destination static SMSC&lt;BR /&gt;SMSC no-proxy-arp route-lookup&lt;BR /&gt;nat (inside,outside) source static WEB_Server interface service any WEBRDP&lt;BR /&gt;nat (inside,outside) source static WEB_Server interface service any FTP&lt;BR /&gt;nat (inside,outside) source static WEB_Server interface service any HTTP&lt;BR /&gt;nat (inside,outside) source static WEB_Server interface service any HTTPS&lt;BR /&gt;nat (inside,outside) source static WEB_Server interface service any API&lt;BR /&gt;nat (inside,outside) source static WEB_Server interface service any APITEST&lt;BR /&gt;nat (inside,outside) source static POSH interface service any POSHRemote&lt;BR /&gt;nat (inside,outside) source static POSH interface service any poshSETUP&lt;BR /&gt;nat (inside,outside) source static WEB_Server WEB_Server destination static&lt;BR /&gt;TPNG TPNG no-proxy-arp route-lookup&lt;BR /&gt;nat (any,any) source static TPNG TPNG destination static WEB_Server&lt;BR /&gt;WEB_Server no-proxy-arp&lt;BR /&gt;!&lt;BR /&gt;object network LAN&lt;BR /&gt; nat (any,outside) dynamic interface&lt;BR /&gt;</description>
      <pubDate>Tue, 21 Nov 2017 22:18:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ipsec-tunnel-traffic/m-p/3220521#M1017442</guid>
      <dc:creator>rsatjharman</dc:creator>
      <dc:date>2017-11-21T22:18:30Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC Tunnel Traffic</title>
      <link>https://community.cisco.com/t5/network-security/ipsec-tunnel-traffic/m-p/3220535#M1017443</link>
      <description>&lt;P&gt;ok, that's a mess ...&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But it seems that you need a NAT-exemption for that traffic at the top of the NAT rules.&lt;/P&gt;</description>
      <pubDate>Tue, 21 Nov 2017 22:48:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ipsec-tunnel-traffic/m-p/3220535#M1017443</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2017-11-21T22:48:49Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC Tunnel Traffic</title>
      <link>https://community.cisco.com/t5/network-security/ipsec-tunnel-traffic/m-p/3220540#M1017444</link>
      <description>I have cleaned it up as follows -&lt;BR /&gt;nat (inside,outside) source static WEB_Server interface service any WEBRDP&lt;BR /&gt;nat (inside,outside) source static WEB_Server interface service any FTP&lt;BR /&gt;nat (inside,outside) source static WEB_Server interface service any HTTP&lt;BR /&gt;nat (inside,outside) source static WEB_Server interface service any HTTPS&lt;BR /&gt;nat (inside,outside) source static WEB_Server interface service any API&lt;BR /&gt;nat (inside,outside) source static WEB_Server interface service any APITEST&lt;BR /&gt;nat (inside,outside) source static POSH interface service any POSHRemote&lt;BR /&gt;nat (inside,outside) source static POSH interface service any poshSETUP&lt;BR /&gt;&lt;BR /&gt;object network LAN&lt;BR /&gt; nat (any,outside) dynamic interface&lt;BR /&gt;&lt;BR /&gt;What are your suggestions moving forward ????&lt;BR /&gt;</description>
      <pubDate>Tue, 21 Nov 2017 23:01:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ipsec-tunnel-traffic/m-p/3220540#M1017444</guid>
      <dc:creator>rsatjharman</dc:creator>
      <dc:date>2017-11-21T23:01:29Z</dc:date>
    </item>
  </channel>
</rss>

