<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA 55810 remote access VPN problem in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-5580-remote-access-vpn-problem/m-p/3180737#M1066411</link>
    <description>&lt;P&gt;Hi&amp;nbsp; gasparmenendez,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you post the ASA 5580 config related to VPN with NAT exemption you have configured ?&lt;/P&gt;</description>
    <pubDate>Wed, 06 Sep 2017 17:08:50 GMT</pubDate>
    <dc:creator>Spooster IT Services</dc:creator>
    <dc:date>2017-09-06T17:08:50Z</dc:date>
    <item>
      <title>ASA 5580 remote access VPN problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-5580-remote-access-vpn-problem/m-p/3180715#M1066408</link>
      <description>&lt;DIV class="lia-message-body lia-component-body-signature-highlight-escalation"&gt;&lt;DIV class="lia-message-body-content"&gt;&lt;P&gt;Hi friends, I already configured a VPN connection between a PC (with public ip address) and my ASA 5580 for testing purposes. The problem is that I need to ping a subnet (192.168.199.0/24) behind the ASA from the PC connected through VPN but I can't, I've been trying a lot of things but is nearly impossible. I really need every help I can get in order to solve this issue. When I run a packet-tracer on the ASA I get:&lt;/P&gt;&lt;P&gt;ASA5580# packet-trace input outside icmp 192.168.239.2 8 0 192.168.199.33&lt;BR /&gt;&lt;BR /&gt;Phase: 1&lt;BR /&gt;Type: ACCESS-LIST&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Implicit Rule&lt;BR /&gt;Additional Information:&lt;BR /&gt;MAC Access list&lt;BR /&gt;&lt;BR /&gt;Phase: 2&lt;BR /&gt;Type: UN-NAT&lt;BR /&gt;Subtype: static&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;nat (INSIDE_Prueba,OUTSIDE) source static redvpn redvpn destination static NETWORK_OBJ_192.168.239.0_25 NETWORK_OBJ_192.168.239.0_25 no-proxy-arp&lt;BR /&gt;Additional Information:&lt;BR /&gt;NAT divert to egress interface INSIDE_Prueba&lt;BR /&gt;Untranslate 192.168.199.33/0 to 192.168.199.33/0&lt;BR /&gt;&lt;BR /&gt;Phase: 3&lt;BR /&gt;Type: ACCESS-LIST&lt;BR /&gt;Subtype: log&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;access-group OUTSIDE_access_in in interface OUTSIDE&lt;BR /&gt;access-list OUTSIDE_access_in extended permit ip any any&lt;BR /&gt;Additional Information:&lt;BR /&gt;&lt;BR /&gt;Phase: 4&lt;BR /&gt;Type: IP-OPTIONS&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;&lt;BR /&gt;Phase: 5&lt;BR /&gt;Type: CP-PUNT&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;&lt;BR /&gt;Phase: 6&lt;BR /&gt;Type: INSPECT&lt;BR /&gt;Subtype: np-inspect&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;class-map inspection_default&lt;BR /&gt;&amp;nbsp;match default-inspection-traffic&lt;BR /&gt;policy-map global_policy&lt;BR /&gt;&amp;nbsp;class inspection_default&lt;BR /&gt;&amp;nbsp; inspect icmp&lt;BR /&gt;service-policy global_policy global&lt;BR /&gt;Additional Information:&lt;BR /&gt;&lt;BR /&gt;Phase: 7&lt;BR /&gt;Type: INSPECT&lt;BR /&gt;Subtype: np-inspect&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;&lt;BR /&gt;Phase: 8&lt;BR /&gt;Type: VPN&lt;BR /&gt;Subtype: ipsec-tunnel-flow&lt;BR /&gt;Result: DROP&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;&lt;BR /&gt;Result:&lt;BR /&gt;input-interface: OUTSIDE&lt;BR /&gt;input-status: up&lt;BR /&gt;input-line-status: up&lt;BR /&gt;output-interface: INSIDE_Prueba&lt;BR /&gt;output-status: up&lt;BR /&gt;output-line-status: up&lt;BR /&gt;Action: drop&lt;BR /&gt;Drop-reason: (acl-drop) Flow is denied by configured rule&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Obviously PC connected to LAN behind ASA has ip address 192.168.199.33 and the other one with public ip address gets 192.168.239.2 when VPN comes up. Can anybody help me please???&lt;/P&gt;&lt;P&gt;Thanks in advance. BR.&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Fri, 21 Feb 2020 14:16:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5580-remote-access-vpn-problem/m-p/3180715#M1066408</guid>
      <dc:creator>gasparmenendez</dc:creator>
      <dc:date>2020-02-21T14:16:30Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 55810 remote access VPN problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-5580-remote-access-vpn-problem/m-p/3180737#M1066411</link>
      <description>&lt;P&gt;Hi&amp;nbsp; gasparmenendez,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you post the ASA 5580 config related to VPN with NAT exemption you have configured ?&lt;/P&gt;</description>
      <pubDate>Wed, 06 Sep 2017 17:08:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5580-remote-access-vpn-problem/m-p/3180737#M1066411</guid>
      <dc:creator>Spooster IT Services</dc:creator>
      <dc:date>2017-09-06T17:08:50Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 55810 remote access VPN problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-5580-remote-access-vpn-problem/m-p/3180756#M1066413</link>
      <description>&lt;P&gt;Here it is:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;object network 192.168.239.0&lt;BR /&gt;&amp;nbsp;subnet 192.168.239.0 255.255.255.128&lt;BR /&gt;&amp;nbsp;description 192.168.239.0&lt;BR /&gt;object network NETWORK_OBJ_192.168.239.0_25&lt;BR /&gt;&amp;nbsp;subnet 192.168.239.0 255.255.255.128&lt;BR /&gt;object network pool-vpn-prueba&lt;BR /&gt;&amp;nbsp;subnet 192.168.239.0 255.255.255.128&lt;BR /&gt;object-group network redvpn&lt;BR /&gt;&amp;nbsp;network-object object 192.168.199.0&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp;&lt;BR /&gt;access-list INSIDE_Prueba_access_in extended permit ip object 192.168.199.0 any&lt;BR /&gt;&lt;BR /&gt;access-list ACL-tunel-vpn-prueba standard permit 192.168.239.0 255.255.255.0&lt;BR /&gt;access-list ACL-tunel-vpn-prueba standard permit 192.168.199.0 255.255.255.0&lt;BR /&gt;&lt;BR /&gt;access-list INSIDE_Prueba_access_out extended permit ip 192.168.199.0 255.255.255.0 any&lt;BR /&gt;&lt;BR /&gt;ip local pool pool-vpn-prueba 192.168.239.1-192.168.239.100 mask 255.255.255.0&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;nat (INSIDE_Prueba,OUTSIDE) source static redvpn redvpn destination static NETWORK_OBJ_192.168.239.0_25 NETWORK_OBJ_192.168.239.0_25 no-proxy-arp&lt;BR /&gt;&lt;BR /&gt;nat (CARRIERS,OUTSIDE) after-auto source dynamic any interface&lt;BR /&gt;nat (INSIDE_Prueba,OUTSIDE) after-auto source dynamic any interface&lt;BR /&gt;&lt;BR /&gt;nat (OUTSIDE,OUTSIDE) after-auto source static pool-vpn-prueba interface no-proxy-arp&lt;BR /&gt;access-group OUTSIDE_access_in in interface OUTSIDE&lt;BR /&gt;access-group CARRIERS_access_in in interface CARRIERS&lt;BR /&gt;access-group CARRIERS_access_out out interface CARRIERS&lt;BR /&gt;access-group INSIDE_Prueba_access_in in interface INSIDE_Prueba&lt;BR /&gt;access-group INSIDE_Prueba_access_out out interface INSIDE_Prueba&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-3DES-MD5 esp-3des esp-md5-hmac&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-DES-MD5 esp-des esp-md5-hmac&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-3DES-SHA esp-3des esp-sha-hmac&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-128-SHA esp-aes esp-sha-hmac&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-192-SHA esp-aes-192 esp-sha-hmac&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-128-MD5 esp-aes esp-md5-hmac&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-192-MD5 esp-aes-192 esp-md5-hmac&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-256-SHA esp-aes-256 esp-sha-hmac&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-256-MD5 esp-aes-256 esp-md5-hmac&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-DES-SHA esp-des esp-sha-hmac&lt;BR /&gt;crypto dynamic-map SYSTEM_DEFAULT_CRYPTO_MAP 65535 set ikev1 transform-set ESP-AES-128-SHA ESP-AES-128-MD5 ESP-AES-192-SHA ESP-AES-192-MD5 ESP-AES-256-SHA ESP-AES-256-MD5 ESP-3DES-SHA ESP-3DES-MD5 ESP-DES-SHA ESP-DES-MD5&lt;BR /&gt;crypto map INSIDE_Prueba_map 65535 ipsec-isakmp dynamic SYSTEM_DEFAULT_CRYPTO_MAP&lt;BR /&gt;crypto map INSIDE_Prueba_map interface INSIDE_Prueba&lt;BR /&gt;crypto map OUTSIDE_map 65535 ipsec-isakmp dynamic SYSTEM_DEFAULT_CRYPTO_MAP&lt;BR /&gt;crypto map OUTSIDE_map interface OUTSIDE&lt;BR /&gt;crypto ikev1 enable OUTSIDE&lt;BR /&gt;crypto ikev1 enable INSIDE_Prueba&lt;BR /&gt;crypto ikev1 policy 10&lt;BR /&gt;&amp;nbsp;authentication crack&lt;BR /&gt;&amp;nbsp;encryption aes-256&lt;BR /&gt;&amp;nbsp;hash sha&lt;BR /&gt;&amp;nbsp;group 2&lt;BR /&gt;&amp;nbsp;lifetime 86400&lt;BR /&gt;crypto ikev1 policy 20&lt;BR /&gt;&amp;nbsp;authentication rsa-sig&lt;BR /&gt;&amp;nbsp;encryption aes-256&lt;BR /&gt;&amp;nbsp;hash sha&lt;BR /&gt;&amp;nbsp;group 2&lt;BR /&gt;&amp;nbsp;lifetime 86400&lt;BR /&gt;crypto ikev1 policy 30&lt;BR /&gt;&amp;nbsp;authentication pre-share&lt;BR /&gt;&amp;nbsp;encryption aes-256&lt;BR /&gt;&amp;nbsp;hash sha&lt;BR /&gt;&amp;nbsp;group 2&lt;BR /&gt;&amp;nbsp;lifetime 86400&lt;BR /&gt;crypto ikev1 policy 40&lt;BR /&gt;&amp;nbsp;authentication crack&lt;BR /&gt;&amp;nbsp;encryption aes-192&lt;BR /&gt;&amp;nbsp;hash sha&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&lt;BR /&gt;&amp;nbsp;group 2&lt;BR /&gt;&amp;nbsp;lifetime 86400&lt;BR /&gt;crypto ikev1 policy 50&lt;BR /&gt;&amp;nbsp;authentication rsa-sig&lt;BR /&gt;&amp;nbsp;encryption aes-192&lt;BR /&gt;&amp;nbsp;hash sha&lt;BR /&gt;&amp;nbsp;group 2&lt;BR /&gt;&amp;nbsp;lifetime 86400&lt;BR /&gt;crypto ikev1 policy 60&lt;BR /&gt;&amp;nbsp;authentication pre-share&lt;BR /&gt;&amp;nbsp;encryption aes-192&lt;BR /&gt;&amp;nbsp;hash sha&lt;BR /&gt;&amp;nbsp;group 2&lt;BR /&gt;&amp;nbsp;lifetime 86400&lt;BR /&gt;crypto ikev1 policy 70&lt;BR /&gt;&amp;nbsp;authentication crack&lt;BR /&gt;&amp;nbsp;encryption aes&lt;BR /&gt;&amp;nbsp;hash sha&lt;BR /&gt;&amp;nbsp;group 2&lt;BR /&gt;&amp;nbsp;lifetime 86400&lt;BR /&gt;crypto ikev1 policy 80&lt;BR /&gt;&amp;nbsp;authentication rsa-sig&lt;BR /&gt;&amp;nbsp;encryption aes&lt;BR /&gt;&amp;nbsp;hash sha&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&lt;BR /&gt;&amp;nbsp;group 2&lt;BR /&gt;&amp;nbsp;lifetime 86400&lt;BR /&gt;crypto ikev1 policy 90&lt;BR /&gt;&amp;nbsp;authentication pre-share&lt;BR /&gt;&amp;nbsp;encryption aes&lt;BR /&gt;&amp;nbsp;hash sha&lt;BR /&gt;&amp;nbsp;group 2&lt;BR /&gt;&amp;nbsp;lifetime 86400&lt;BR /&gt;crypto ikev1 policy 100&lt;BR /&gt;&amp;nbsp;authentication crack&lt;BR /&gt;&amp;nbsp;encryption 3des&lt;BR /&gt;&amp;nbsp;hash sha&lt;BR /&gt;&amp;nbsp;group 2&lt;BR /&gt;&amp;nbsp;lifetime 86400&lt;BR /&gt;crypto ikev1 policy 110&lt;BR /&gt;&amp;nbsp;authentication rsa-sig&lt;BR /&gt;&amp;nbsp;encryption 3des&lt;BR /&gt;&amp;nbsp;hash sha&lt;BR /&gt;&amp;nbsp;group 2&lt;BR /&gt;&amp;nbsp;lifetime 86400&lt;BR /&gt;crypto ikev1 policy 120&lt;BR /&gt;&amp;nbsp;authentication pre-share&lt;BR /&gt;&amp;nbsp;encryption 3des&lt;BR /&gt;&amp;nbsp;hash sha&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&lt;BR /&gt;&amp;nbsp;group 2&lt;BR /&gt;&amp;nbsp;lifetime 86400&lt;BR /&gt;crypto ikev1 policy 130&lt;BR /&gt;&amp;nbsp;authentication crack&lt;BR /&gt;&amp;nbsp;encryption des&lt;BR /&gt;&amp;nbsp;hash sha&lt;BR /&gt;&amp;nbsp;group 2&lt;BR /&gt;&amp;nbsp;lifetime 86400&lt;BR /&gt;crypto ikev1 policy 140&lt;BR /&gt;&amp;nbsp;authentication rsa-sig&lt;BR /&gt;&amp;nbsp;encryption des&lt;BR /&gt;&amp;nbsp;hash sha&lt;BR /&gt;&amp;nbsp;group 2&lt;BR /&gt;&amp;nbsp;lifetime 86400&lt;BR /&gt;crypto ikev1 policy 150&lt;BR /&gt;&amp;nbsp;authentication pre-share&lt;BR /&gt;&amp;nbsp;encryption des&lt;BR /&gt;&amp;nbsp;hash sha&lt;BR /&gt;&amp;nbsp;group 2&lt;BR /&gt;&amp;nbsp;lifetime 86400&lt;BR /&gt;telnet timeout 5&lt;BR /&gt;ssh 192.168.0.0 255.255.255.0 management&lt;BR /&gt;ssh timeout 5&lt;BR /&gt;ssh key-exchange group dh-group1-sha1&lt;BR /&gt;console timeout 0&lt;BR /&gt;management-access INSIDE_Prueba&lt;BR /&gt;!&lt;BR /&gt;tls-proxy maximum-session 1000&lt;BR /&gt;!&lt;BR /&gt;threat-detection basic-threat&lt;BR /&gt;threat-detection statistics access-list&lt;BR /&gt;no threat-detection statistics tcp-intercept&lt;BR /&gt;webvpn&lt;BR /&gt;group-policy DfltGrpPolicy attributes&lt;BR /&gt;&amp;nbsp;vpn-tunnel-protocol ikev1 ikev2 ssl-clientless&lt;BR /&gt;group-policy policiy-tunel-vpn-prueba-all internal&lt;BR /&gt;group-policy policiy-tunel-vpn-prueba-all attributes&lt;BR /&gt;&amp;nbsp;dns-server value 209.244.0.3 209.244.0.4&lt;BR /&gt;&amp;nbsp;vpn-tunnel-protocol ikev1 ssl-clientless&lt;BR /&gt;&amp;nbsp;split-tunnel-policy tunnelall&lt;BR /&gt;group-policy policiy-tunel-vpn-prueba-split internal&lt;BR /&gt;group-policy policiy-tunel-vpn-prueba-split attributes&lt;BR /&gt;&amp;nbsp;vpn-tunnel-protocol ikev1&lt;BR /&gt;&amp;nbsp;split-tunnel-policy tunnelspecified&lt;BR /&gt;&amp;nbsp;split-tunnel-network-list value ACL-tunel-vpn-prueba&lt;BR /&gt;&lt;BR /&gt;tunnel-group tunel-vpn-prueba type remote-access&lt;BR /&gt;tunnel-group tunel-vpn-prueba general-attributes&lt;BR /&gt;&amp;nbsp;address-pool pool-vpn-prueba&lt;BR /&gt;&amp;nbsp;default-group-policy policiy-tunel-vpn-prueba-split&lt;BR /&gt;tunnel-group tunel-vpn-prueba ipsec-attributes&lt;BR /&gt;&amp;nbsp;ikev1 pre-shared-key *****&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I think that would be all but maybe I miss some lines related to what you ask. If you need anything else please let me know.&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Wed, 06 Sep 2017 18:26:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5580-remote-access-vpn-problem/m-p/3180756#M1066413</guid>
      <dc:creator>gasparmenendez</dc:creator>
      <dc:date>2017-09-06T18:26:11Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 55810 remote access VPN problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-5580-remote-access-vpn-problem/m-p/3180775#M1066416</link>
      <description>&lt;P&gt;1) What happen when you try to ping from remote PC (&lt;SPAN&gt;192.168.239.x&lt;/SPAN&gt;) to LAN server/PC (&lt;SPAN&gt;192.168.199.x&lt;/SPAN&gt;) &amp;nbsp;instead of packet tracer command?&lt;/P&gt;&lt;P&gt;2) Are to able to setup VPN session successfully or getting some error while to connect?&lt;/P&gt;&lt;P&gt;3) Are you inspecting the ICMP traffic?&lt;/P&gt;&lt;P&gt;4) You need to allow the traffic in outbound ACL &lt;SPAN&gt;INSIDE_Prueba_access_out&lt;/SPAN&gt;. Following is the command.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;access-list INSIDE_Prueba_access_out extended permit ip&amp;nbsp;192.168.239.0 255.255.255.128 &amp;nbsp;192.168.199.0 255.255.255.0&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 06 Sep 2017 19:35:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5580-remote-access-vpn-problem/m-p/3180775#M1066416</guid>
      <dc:creator>Spooster IT Services</dc:creator>
      <dc:date>2017-09-06T19:35:39Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 55810 remote access VPN problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-5580-remote-access-vpn-problem/m-p/3180830#M1066418</link>
      <description>&lt;P&gt;first of all the command you refer in 4) made no difference, and about tyour other questions:&lt;/P&gt;&lt;P&gt;1) nothing happens&lt;/P&gt;&lt;P&gt;2) VPN comes up fast and without any errors&lt;/P&gt;&lt;P&gt;3) how and where can I inspect ICMP traffic??&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Wed, 06 Sep 2017 22:13:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5580-remote-access-vpn-problem/m-p/3180830#M1066418</guid>
      <dc:creator>gasparmenendez</dc:creator>
      <dc:date>2017-09-06T22:13:06Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 55810 remote access VPN problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-5580-remote-access-vpn-problem/m-p/3181849#M1066419</link>
      <description>&lt;P&gt;I ran a tcpdump in the internal PC while ping it from PC connected through VPN and internal PC receive and reply packets...I think ASA is not permiting traffic in both directions.Here's tcpdump:&lt;/P&gt;&lt;P&gt;gaspar@gaspar-Lenovo-ideapad-310-15ISK ~ $ sudo tcpdump -i enp1s0 | grep 192.168.239.3&lt;BR /&gt;[sudo] password for gaspar:&lt;BR /&gt;tcpdump: verbose output suppressed, use -v or -vv for full protocol decode&lt;BR /&gt;listening on enp1s0, link-type EN10MB (Ethernet), capture size 262144 bytes&lt;BR /&gt;13:23:17.968146 IP 192.168.239.3 &amp;gt; 192.168.199.30: ICMP echo request, id 1, seq 843, length 40&lt;BR /&gt;13:23:17.968170 IP 192.168.199.30 &amp;gt; 192.168.239.3: ICMP echo reply, id 1, seq 843, length 40&lt;BR /&gt;13:23:22.946540 IP 192.168.239.3 &amp;gt; 192.168.199.30: ICMP echo request, id 1, seq 844, length 40&lt;BR /&gt;13:23:22.946573 IP 192.168.199.30 &amp;gt; 192.168.239.3: ICMP echo reply, id 1, seq 844, length 40&lt;BR /&gt;13:23:27.958995 IP 192.168.239.3 &amp;gt; 192.168.199.30: ICMP echo request, id 1, seq 845, length 40&lt;BR /&gt;13:23:27.959013 IP 192.168.199.30 &amp;gt; 192.168.239.3: ICMP echo reply, id 1, seq 845, length 40&lt;BR /&gt;13:23:32.946256 IP 192.168.239.3 &amp;gt; 192.168.199.30: ICMP echo request, id 1, seq 846, length 40&lt;BR /&gt;13:23:32.946275 IP 192.168.199.30 &amp;gt; 192.168.239.3: ICMP echo reply, id 1, seq 846, length 40&lt;BR /&gt;13:23:37.954738 IP 192.168.239.3 &amp;gt; 192.168.199.30: ICMP echo request, id 1, seq 847, length 40&lt;BR /&gt;13:23:37.954762 IP 192.168.199.30 &amp;gt; 192.168.239.3: ICMP echo reply, id 1, seq 847, length 40&lt;BR /&gt;13:23:42.953934 IP 192.168.239.3 &amp;gt; 192.168.199.30: ICMP echo request, id 1, seq 848, length 40&lt;BR /&gt;13:23:42.953967 IP 192.168.199.30 &amp;gt; 192.168.239.3: ICMP echo reply, id 1, seq 848, length 40&lt;BR /&gt;13:23:47.973584 IP 192.168.239.3 &amp;gt; 192.168.199.30: ICMP echo request, id 1, seq 849, length 40&lt;BR /&gt;13:23:47.973605 IP 192.168.199.30 &amp;gt; 192.168.239.3: ICMP echo reply, id 1, seq 849, length 40&lt;BR /&gt;13:23:52.953619 IP 192.168.239.3 &amp;gt; 192.168.199.30: ICMP echo request, id 1, seq 850, length 40&lt;BR /&gt;13:23:52.953646 IP 192.168.199.30 &amp;gt; 192.168.239.3: ICMP echo reply, id 1, seq 850, length 40&lt;BR /&gt;13:23:57.964301 IP 192.168.239.3 &amp;gt; 192.168.199.30: ICMP echo request, id 1, seq 851, length 40&lt;BR /&gt;13:23:57.964323 IP 192.168.199.30 &amp;gt; 192.168.239.3: ICMP echo reply, id 1, seq 851, length 40&lt;BR /&gt;13:24:02.945082 IP 192.168.239.3 &amp;gt; 192.168.199.30: ICMP echo request, id 1, seq 852, length 40&lt;BR /&gt;13:24:02.945104 IP 192.168.199.30 &amp;gt; 192.168.239.3: ICMP echo reply, id 1, seq 852, length 40&lt;BR /&gt;13:24:07.957750 IP 192.168.239.3 &amp;gt; 192.168.199.30: ICMP echo request, id 1, seq 853, length 40&lt;BR /&gt;13:24:07.957770 IP 192.168.199.30 &amp;gt; 192.168.239.3: ICMP echo reply, id 1, seq 853, length 40&lt;BR /&gt;13:24:12.950293 IP 192.168.239.3 &amp;gt; 192.168.199.30: ICMP echo request, id 1, seq 854, length 40&lt;BR /&gt;13:24:12.950342 IP 192.168.199.30 &amp;gt; 192.168.239.3: ICMP echo reply, id 1, seq 854, length 40&lt;BR /&gt;13:24:17.946094 IP 192.168.239.3 &amp;gt; 192.168.199.30: ICMP echo request, id 1, seq 855, length 40&lt;BR /&gt;13:24:17.946115 IP 192.168.199.30 &amp;gt; 192.168.239.3: ICMP echo reply, id 1, seq 855, length 40&lt;BR /&gt;13:24:22.958903 IP 192.168.239.3 &amp;gt; 192.168.199.30: ICMP echo request, id 1, seq 856, length 40&lt;BR /&gt;13:24:22.958924 IP 192.168.199.30 &amp;gt; 192.168.239.3: ICMP echo reply, id 1, seq 856, length 40&lt;BR /&gt;13:24:27.954405 IP 192.168.239.3 &amp;gt; 192.168.199.30: ICMP echo request, id 1, seq 857, length 40&lt;BR /&gt;13:24:27.954426 IP 192.168.199.30 &amp;gt; 192.168.239.3: ICMP echo reply, id 1, seq 857, length 40&lt;BR /&gt;^C14559 packets captured&lt;BR /&gt;14576 packets received by filter&lt;BR /&gt;0 packets dropped by kernel&lt;BR /&gt;38 packets dropped by interface&lt;/P&gt;&lt;P&gt;no more help?????&lt;/P&gt;</description>
      <pubDate>Fri, 08 Sep 2017 19:03:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5580-remote-access-vpn-problem/m-p/3181849#M1066419</guid>
      <dc:creator>gasparmenendez</dc:creator>
      <dc:date>2017-09-08T19:03:17Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 55810 remote access VPN problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-5580-remote-access-vpn-problem/m-p/3181859#M1066420</link>
      <description>&lt;P&gt;Try to add the following command:-&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;access-list INSIDE_Prueba_access_in extended permit ip 192.168.199.0 255.255.255.0&amp;nbsp;192.168.239.0 255.255.255.128&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Establish a VPN session between ASA and VPN client. Setup captures at ASA. Following are commands to setup capture&lt;BR /&gt;access-list TEST&amp;nbsp;extended permit ip 192.168.199.0 255.255.255.0 192.168.239.0 255.255.255.128&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;access-list&amp;nbsp;TEST&amp;nbsp;extended permit ip&amp;nbsp;192.168.239.0 255.255.255.128 192.168.199.0 255.255.255.0&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;capture CAP interface&amp;nbsp;INSIDE_Prueba access-list TEST buffer 100000&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;and post the following outputs:-&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;1)&amp;nbsp;show capture CAP&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;2) sh conn | in&amp;nbsp;192.168.239.&lt;BR /&gt;3) sh xlate | in&amp;nbsp;192.168.239.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 08 Sep 2017 19:15:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5580-remote-access-vpn-problem/m-p/3181859#M1066420</guid>
      <dc:creator>Spooster IT Services</dc:creator>
      <dc:date>2017-09-08T19:15:31Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 55810 remote access VPN problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-5580-remote-access-vpn-problem/m-p/3181908#M1066423</link>
      <description>&lt;P&gt;After did what you said:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ASA5580# show capture CAP&lt;BR /&gt;&lt;BR /&gt;14 packets captured&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp; 1: 16:08:46.154761 192.168.239.3 &amp;gt; 192.168.199.33: icmp: echo request&lt;BR /&gt;&amp;nbsp;&amp;nbsp; 2: 16:08:51.163581 192.168.239.3 &amp;gt; 192.168.199.33: icmp: echo request&lt;BR /&gt;&amp;nbsp;&amp;nbsp; 3: 16:08:56.157538 192.168.239.3 &amp;gt; 192.168.199.33: icmp: echo request&lt;BR /&gt;&amp;nbsp;&amp;nbsp; 4: 16:09:01.151466 192.168.239.3 &amp;gt; 192.168.199.33: icmp: echo request&lt;BR /&gt;&amp;nbsp;&amp;nbsp; 5: 16:09:06.160025 192.168.239.3 &amp;gt; 192.168.199.33: icmp: echo request&lt;BR /&gt;&amp;nbsp;&amp;nbsp; 6: 16:09:11.153083 192.168.239.3 &amp;gt; 192.168.199.33: icmp: echo request&lt;BR /&gt;&amp;nbsp;&amp;nbsp; 7: 16:09:16.152442 192.168.239.3 &amp;gt; 192.168.199.33: icmp: echo request&lt;BR /&gt;&amp;nbsp;&amp;nbsp; 8: 16:09:21.147285 192.168.239.3 &amp;gt; 192.168.199.33: icmp: echo request&lt;BR /&gt;&amp;nbsp;&amp;nbsp; 9: 16:09:26.154044 192.168.239.3 &amp;gt; 192.168.199.33: icmp: echo request&lt;BR /&gt;&amp;nbsp; 10: 16:09:31.170050 192.168.239.3 &amp;gt; 192.168.199.33: icmp: echo request&lt;BR /&gt;&amp;nbsp; 11: 16:09:36.157401 192.168.239.3 &amp;gt; 192.168.199.33: icmp: echo request&lt;BR /&gt;&amp;nbsp; 12: 16:09:41.177358 192.168.239.3 &amp;gt; 192.168.199.33: icmp: echo request&lt;BR /&gt;&amp;nbsp; 13: 16:09:46.171698 192.168.239.3 &amp;gt; 192.168.199.33: icmp: echo request&lt;BR /&gt;&amp;nbsp; 14: 16:09:51.165473 192.168.239.3 &amp;gt; 192.168.199.33: icmp: echo request&lt;BR /&gt;14 packets shown&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ASA5580# sh conn | in 192.168.239. shows nothing, but:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ASA5580# sh conn | in 192.168.239.3&lt;BR /&gt;ICMP OUTSIDE 192.168.239.3:1 INSIDE_Prueba 192.168.199.33:0, idle 0:00:01, bytes 32&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;and:&lt;/P&gt;&lt;P&gt;ASA5580# sh xlate | in 192.168.239.&lt;BR /&gt;NAT from OUTSIDE:192.168.239.0/25 to INSIDE_Prueba:192.168.239.0/25&lt;BR /&gt;NAT from OUTSIDE:192.168.239.0/25 to OUTSIDE:170.80.240.2&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;forgive me for asking but, is it so hard what I want to do???&lt;BR /&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Fri, 08 Sep 2017 21:11:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5580-remote-access-vpn-problem/m-p/3181908#M1066423</guid>
      <dc:creator>gasparmenendez</dc:creator>
      <dc:date>2017-09-08T21:11:48Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 55810 remote access VPN problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-5580-remote-access-vpn-problem/m-p/3181917#M1066424</link>
      <description>&lt;P&gt;There is one way traffic in ASA captures. This means either inbound ACL is dropping the return traffic or Server has wrong default gateway settings or wrong route for&amp;nbsp;192.168.239.0/24 subnet.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Verify the following:-&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1) ASA's &amp;nbsp;INSIDE_Prueba interface ACL. (Post the output of "show access-list &lt;SPAN&gt;INSIDE_Prueba_access_in" and "show access-list&amp;nbsp;INSIDE_Prueba_access_out"&lt;/SPAN&gt;).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2) Default Gateway of server&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;3) Route entries at server (Post the output of cmd "route print" command).&lt;/P&gt;</description>
      <pubDate>Fri, 08 Sep 2017 21:25:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5580-remote-access-vpn-problem/m-p/3181917#M1066424</guid>
      <dc:creator>Spooster IT Services</dc:creator>
      <dc:date>2017-09-08T21:25:39Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 55810 remote access VPN problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-5580-remote-access-vpn-problem/m-p/3181926#M1066426</link>
      <description>&lt;P&gt;ASA5580# show access-list INSIDE_Prueba_access_in&lt;BR /&gt;access-list INSIDE_Prueba_access_in; 6 elements; name hash: 0xafbf4ce6&lt;BR /&gt;access-list INSIDE_Prueba_access_in line 1 extended permit ip 192.168.62.0 255.255.255.0 any (hitcnt=39561) 0x716f37f7&lt;BR /&gt;access-list INSIDE_Prueba_access_in line 2 extended permit ip object 172.16.99.0 any (hitcnt=90342246) 0x4427b2ed&lt;BR /&gt;&amp;nbsp; access-list INSIDE_Prueba_access_in line 2 extended permit ip 172.16.99.0 255.255.255.0 any (hitcnt=90342246) 0x4427b2ed&lt;BR /&gt;access-list INSIDE_Prueba_access_in line 3 extended permit ip object 192.168.199.0 any (hitcnt=155560) 0x168ba1f4&lt;BR /&gt;&amp;nbsp; access-list INSIDE_Prueba_access_in line 3 extended permit ip 192.168.199.0 255.255.255.0 any (hitcnt=155560) 0x168ba1f4&lt;BR /&gt;access-list INSIDE_Prueba_access_in line 4 extended permit ip object 10.228.0.0 any (hitcnt=1599026) 0xa793330c&lt;BR /&gt;&amp;nbsp; access-list INSIDE_Prueba_access_in line 4 extended permit ip 10.228.0.0 255.255.240.0 any (hitcnt=1599026) 0xa793330c&lt;BR /&gt;access-list INSIDE_Prueba_access_in line 5 extended permit ip 10.227.224.0 255.255.252.0 192.168.199.0 255.255.255.0 (hitcnt=0) 0xa4d41a0d&lt;BR /&gt;access-list INSIDE_Prueba_access_in line 6 extended permit ip 192.168.199.0 255.255.255.0 192.168.239.0 255.255.255.128 (hitcnt=0) 0xc9b601cc&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ASA5580# show access-list INSIDE_Prueba_access_out&lt;BR /&gt;access-list INSIDE_Prueba_access_out; 4 elements; name hash: 0x68c766de&lt;BR /&gt;access-list INSIDE_Prueba_access_out line 1 extended permit ip 10.227.224.0 255.255.252.0 any (hitcnt=7363) 0x6bf6b718&lt;BR /&gt;access-list INSIDE_Prueba_access_out line 2 extended permit ip 192.168.199.0 255.255.255.0 any (hitcnt=0) 0xbde038cd&lt;BR /&gt;access-list INSIDE_Prueba_access_out line 3 extended permit ip any object 172.16.99.0 (hitcnt=0) 0x6622900f&lt;BR /&gt;&amp;nbsp; access-list INSIDE_Prueba_access_out line 3 extended permit ip any 172.16.99.0 255.255.255.0 (hitcnt=669327) 0x6622900f&lt;BR /&gt;access-list INSIDE_Prueba_access_out line 4 extended permit ip 192.168.239.0 255.255.255.128 192.168.199.0 255.255.255.0 (hitcnt=0) 0x9aa43cbf&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Pic attached with Default Gateway of server and Route entries&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Fri, 08 Sep 2017 21:47:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5580-remote-access-vpn-problem/m-p/3181926#M1066426</guid>
      <dc:creator>gasparmenendez</dc:creator>
      <dc:date>2017-09-08T21:47:10Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 55810 remote access VPN problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-5580-remote-access-vpn-problem/m-p/3181932#M1066430</link>
      <description>&lt;P&gt;Whose IP is 192.168.199.254?&lt;/P&gt;&lt;P&gt;It seems that something wrong with ASA configuration. Can you post the ASA 's full config? Please remember to remove the &amp;nbsp;sensitive information before posting (like public IP, Passwords etc.)&lt;/P&gt;</description>
      <pubDate>Fri, 08 Sep 2017 21:56:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5580-remote-access-vpn-problem/m-p/3181932#M1066430</guid>
      <dc:creator>Spooster IT Services</dc:creator>
      <dc:date>2017-09-08T21:56:18Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 55810 remote access VPN problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-5580-remote-access-vpn-problem/m-p/3181937#M1066433</link>
      <description>&lt;P&gt;&lt;BR /&gt;ASA5580# sh running-config&lt;BR /&gt;: Saved&lt;BR /&gt;:&lt;BR /&gt;ASA Version 8.4(5)&lt;BR /&gt;!&lt;BR /&gt;hostname ASA5580&lt;BR /&gt;enable password TFy5Z encrypted&lt;BR /&gt;passwd 2KFQnbNIdI encrypted&lt;BR /&gt;names&lt;BR /&gt;!&lt;BR /&gt;interface Management0/0&lt;BR /&gt;&amp;nbsp;nameif management&lt;BR /&gt;&amp;nbsp;security-level 0&lt;BR /&gt;&amp;nbsp;ip address 192.168.0.44 255.255.255.0&lt;BR /&gt;!&lt;BR /&gt;interface Management0/1&lt;BR /&gt;&amp;nbsp;shutdown&lt;BR /&gt;&amp;nbsp;no nameif&lt;BR /&gt;&amp;nbsp;no security-level&lt;BR /&gt;&amp;nbsp;no ip address&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet3/0&lt;BR /&gt;&amp;nbsp;no nameif&lt;BR /&gt;&amp;nbsp;no security-level&lt;BR /&gt;&amp;nbsp;no ip address&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet3/1&lt;BR /&gt;&amp;nbsp;shutdown&lt;BR /&gt;&amp;nbsp;no nameif&lt;BR /&gt;&amp;nbsp;no security-level&lt;BR /&gt;&amp;nbsp;no ip address&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet3/2&lt;BR /&gt;&amp;nbsp;nameif CARRIERS&lt;BR /&gt;&amp;nbsp;security-level 30&lt;BR /&gt;&amp;nbsp;ip address 10.227.224.3 255.255.252.0&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet3/3&lt;BR /&gt;&amp;nbsp;nameif INSIDE_Prueba&lt;BR /&gt;&amp;nbsp;security-level 40&lt;BR /&gt;&amp;nbsp;ip address 192.168.62.254 255.255.255.0&lt;BR /&gt;!&lt;BR /&gt;interface TenGigabitEthernet5/0&lt;BR /&gt;&amp;nbsp;nameif CMTS&lt;BR /&gt;&amp;nbsp;security-level 50&lt;BR /&gt;&amp;nbsp;ip address 192.168.61.9 255.255.255.0&lt;BR /&gt;!&lt;BR /&gt;interface TenGigabitEthernet5/1&lt;BR /&gt;&amp;nbsp;shutdown&lt;BR /&gt;&amp;nbsp;no nameif&lt;BR /&gt;&amp;nbsp;no security-level&lt;BR /&gt;&amp;nbsp;no ip address&lt;BR /&gt;!&lt;BR /&gt;interface TenGigabitEthernet7/0&lt;BR /&gt;&amp;nbsp;nameif OUTSIDE&lt;BR /&gt;&amp;nbsp;security-level 0&lt;BR /&gt;&amp;nbsp;ip address 170.X.X.2 255.255.255.240&lt;BR /&gt;!&lt;BR /&gt;interface TenGigabitEthernet7/1&lt;BR /&gt;&amp;nbsp;shutdown&lt;BR /&gt;&amp;nbsp;no nameif&lt;BR /&gt;&amp;nbsp;no security-level&lt;BR /&gt;&amp;nbsp;no ip address&lt;BR /&gt;!&lt;BR /&gt;ftp mode passive&lt;BR /&gt;clock timezone CST -6&lt;BR /&gt;clock summer-time CDT recurring 1 Sun Apr 2:00 last Sun Oct 2:00&lt;BR /&gt;same-security-traffic permit inter-interface&lt;BR /&gt;same-security-traffic permit intra-interface&lt;BR /&gt;object network 10.19.0.0&lt;BR /&gt;&amp;nbsp;subnet 10.19.0.0 255.255.0.0&lt;BR /&gt;object network 170.X.X.3&lt;BR /&gt;&amp;nbsp;host 170.X.X.3&lt;BR /&gt;object network 170.X.X.4&lt;BR /&gt;&amp;nbsp;host 170.X.X.4&lt;BR /&gt;object network 170.X.X.5&lt;BR /&gt;&amp;nbsp;host 170.X.X.5&lt;BR /&gt;object network 170.X.X.6&lt;BR /&gt;&amp;nbsp;host 170.X.X.6&lt;BR /&gt;object network 170.X.X.7&lt;BR /&gt;&amp;nbsp;host 170.X.X.7&lt;BR /&gt;object network 170.X.X.8&lt;BR /&gt;&amp;nbsp;host 170.X.X.8&lt;BR /&gt;object network 170.X.X.9&lt;BR /&gt;&amp;nbsp;host 170.X.X.9&lt;BR /&gt;object network 170.X.X.10&lt;BR /&gt;&amp;nbsp;host 170.X.X.10&lt;BR /&gt;object network 170.X.X.11&lt;BR /&gt;&amp;nbsp;host 170.X.X.11&lt;BR /&gt;object network 170.X.X.12&lt;BR /&gt;&amp;nbsp;host 170.X.X.12&lt;BR /&gt;object network 170.X.X.13&lt;BR /&gt;&amp;nbsp;host 170.X.X.13&lt;BR /&gt;object network 170.X.X.14&lt;BR /&gt;&amp;nbsp;host 170.X.X.14&lt;BR /&gt;object network 10.27.0.0&lt;BR /&gt;&amp;nbsp;subnet 10.27.0.0 255.255.0.0&lt;BR /&gt;object network 10.25.0.0&lt;BR /&gt;&amp;nbsp;subnet 10.25.0.0 255.255.0.0&lt;BR /&gt;object network 10.9.0.0&lt;BR /&gt;&amp;nbsp;subnet 10.9.0.0 255.255.0.0&lt;BR /&gt;object network 10.39.0.0&lt;BR /&gt;&amp;nbsp;subnet 10.39.0.0 255.255.0.0&lt;BR /&gt;object network 10.11.0.0&lt;BR /&gt;&amp;nbsp;subnet 10.11.0.0 255.255.0.0&lt;BR /&gt;object network 10.35.0.0&lt;BR /&gt;&amp;nbsp;subnet 10.35.0.0 255.255.0.0&lt;BR /&gt;object network 10.33.0.0&lt;BR /&gt;&amp;nbsp;subnet 10.33.0.0 255.255.0.0&lt;BR /&gt;object network 10.13.0.0&lt;BR /&gt;&amp;nbsp;subnet 10.13.0.0 255.255.0.0&lt;BR /&gt;object network 10.17.0.0&lt;BR /&gt;&amp;nbsp;subnet 10.17.0.0 255.255.0.0&lt;BR /&gt;object network 10.37.0.0&lt;BR /&gt;&amp;nbsp;subnet 10.37.0.0 255.255.0.0&lt;BR /&gt;object network 10.41.0.0&lt;BR /&gt;&amp;nbsp;subnet 10.41.0.0 255.255.0.0&lt;BR /&gt;object network 10.45.0.0&lt;BR /&gt;&amp;nbsp;subnet 10.45.0.0 255.255.0.0&lt;BR /&gt;object network 170.X.X.16&lt;BR /&gt;&amp;nbsp;host 170.X.X.16&lt;BR /&gt;object network 170.X.X.17&lt;BR /&gt;&amp;nbsp;host 170.X.X.17&lt;BR /&gt;object network 170.X.X.18&lt;BR /&gt;&amp;nbsp;host 170.X.X.18&lt;BR /&gt;object network 170.X.X.19&lt;BR /&gt;&amp;nbsp;host 170.X.X.19&lt;BR /&gt;object network 170.X.X.20&lt;BR /&gt;&amp;nbsp;host 170.X.X.20&lt;BR /&gt;object network 170.X.X.21&lt;BR /&gt;&amp;nbsp;host 170.X.X.21&lt;BR /&gt;object network 170.X.X.22&lt;BR /&gt;&amp;nbsp;host 170.X.X.22&lt;BR /&gt;object network 170.X.X.23&lt;BR /&gt;&amp;nbsp;host 170.X.X.23&lt;BR /&gt;object network 170.X.X.24&lt;BR /&gt;&amp;nbsp;host 170.X.X.24&lt;BR /&gt;object network 170.X.X.25&lt;BR /&gt;&amp;nbsp;host 170.X.X.25&lt;BR /&gt;object network 10.47.0.0&lt;BR /&gt;&amp;nbsp;subnet 10.47.0.0 255.255.0.0&lt;BR /&gt;object network 170.X.X.26&lt;BR /&gt;&amp;nbsp;host 170.X.X.26&lt;BR /&gt;object network 170.X.X.27&lt;BR /&gt;&amp;nbsp;host 170.X.X.27&lt;BR /&gt;object network 170.X.X.28&lt;BR /&gt;&amp;nbsp;host 170.X.X.28&lt;BR /&gt;object network 170.X.X.29&lt;BR /&gt;&amp;nbsp;host 170.X.X.29&lt;BR /&gt;object network 170.X.X.30&lt;BR /&gt;&amp;nbsp;host 170.X.X.30&lt;BR /&gt;object network 170.X.X.31&lt;BR /&gt;&amp;nbsp;host 170.X.X.31&lt;BR /&gt;object network 10.49.0.0&lt;BR /&gt;&amp;nbsp;subnet 10.49.0.0 255.255.0.0&lt;BR /&gt;object network Prueba-10.227.225.210&lt;BR /&gt;&amp;nbsp;host 10.227.225.210&lt;BR /&gt;object network 10.227.225.210&lt;BR /&gt;&amp;nbsp;host 10.227.225.210&lt;BR /&gt;object network 172.16.99.0&lt;BR /&gt;&amp;nbsp;subnet 172.16.99.0 255.255.255.0&lt;BR /&gt;object network 172.16.99.22&lt;BR /&gt;&amp;nbsp;host 172.16.99.22&lt;BR /&gt;object network 10.50.0.0&lt;BR /&gt;&amp;nbsp;subnet 10.50.0.0 255.255.0.0&lt;BR /&gt;object network 10.51.0.0&lt;BR /&gt;&amp;nbsp;subnet 10.51.0.0 255.255.0.0&lt;BR /&gt;object network 10.227.225.20&lt;BR /&gt;&amp;nbsp;host 10.227.225.20&lt;BR /&gt;object network CentroValle_1930&lt;BR /&gt;&amp;nbsp;host 10.227.225.20&lt;BR /&gt;object network CentroValle_1946&lt;BR /&gt;&amp;nbsp;host 10.227.225.20&lt;BR /&gt;object network 170.X.X.2&lt;BR /&gt;&amp;nbsp;host 170.X.X.2&lt;BR /&gt;object network Stgo4646_3050&lt;BR /&gt;&amp;nbsp;host 10.44.0.130&lt;BR /&gt;object network 10.44.0.130&lt;BR /&gt;&amp;nbsp;host 10.44.0.130&lt;BR /&gt;object network 192.168.199.0&lt;BR /&gt;&amp;nbsp;subnet 192.168.199.0 255.255.255.0&lt;BR /&gt;object network 10.227.225.41&lt;BR /&gt;&amp;nbsp;host 10.227.225.41&lt;BR /&gt;object network Administracion_FTTH_NuevoIdeal&lt;BR /&gt;&amp;nbsp;subnet 10.16.10.0 255.255.255.0&lt;BR /&gt;&amp;nbsp;description Administracion FTTH Nuevo Ideal&lt;BR /&gt;object network 10.228.0.0&lt;BR /&gt;&amp;nbsp;subnet 10.228.0.0 255.255.240.0&lt;BR /&gt;&amp;nbsp;description 10.228.0.0&lt;BR /&gt;object network 192.168.239.0&lt;BR /&gt;&amp;nbsp;subnet 192.168.239.0 255.255.255.128&lt;BR /&gt;&amp;nbsp;description 192.168.239.0&lt;BR /&gt;object network NETWORK_OBJ_192.168.239.0_25&lt;BR /&gt;&amp;nbsp;subnet 192.168.239.0 255.255.255.128&lt;BR /&gt;object network pool-vpn-prueba&lt;BR /&gt;&amp;nbsp;subnet 192.168.239.0 255.255.255.128&lt;BR /&gt;object network Pool_CMTS_Stgo&lt;BR /&gt;&amp;nbsp;range 170.X.X.8 170.X.X.9&lt;BR /&gt;object network 10.227.225.12&lt;BR /&gt;&amp;nbsp;host 10.227.225.12&lt;BR /&gt;object network AutopartesStgo_Suc_NI_81&lt;BR /&gt;&amp;nbsp;host 10.227.225.12&lt;BR /&gt;object network AutopartesStgo_Suc_NI_554&lt;BR /&gt;&amp;nbsp;host 10.227.225.12&lt;BR /&gt;object network AutopartesStgo_Suc_NI_8000&lt;BR /&gt;&amp;nbsp;host 10.227.225.12&lt;BR /&gt;object network 10.227.225.31&lt;BR /&gt;&amp;nbsp;host 10.227.225.31&lt;BR /&gt;object network Ferrepisos_NI_3389&lt;BR /&gt;&amp;nbsp;host 10.227.225.31&lt;BR /&gt;object network Ferrepisos_NI_8081&lt;BR /&gt;&amp;nbsp;host 10.227.225.31&lt;BR /&gt;object network 10.227.225.21&lt;BR /&gt;&amp;nbsp;host 10.227.225.21&lt;BR /&gt;object network 10.227.225.22&lt;BR /&gt;&amp;nbsp;host 10.227.225.22&lt;BR /&gt;object network 170.X.X.80&lt;BR /&gt;&amp;nbsp;host 170.X.X.80&lt;BR /&gt;object network 170.X.X.81&lt;BR /&gt;&amp;nbsp;host 170.X.X.81&lt;BR /&gt;object network 170.X.X.82&lt;BR /&gt;&amp;nbsp;host 170.X.X.82&lt;BR /&gt;object network 10.227.225.29&lt;BR /&gt;&amp;nbsp;host 10.227.225.29&lt;BR /&gt;object network 10.227.225.39&lt;BR /&gt;&amp;nbsp;host 10.227.225.39&lt;BR /&gt;object network 170.X.X.83&lt;BR /&gt;&amp;nbsp;host 170.X.X.83&lt;BR /&gt;object network 170.X.X.84&lt;BR /&gt;&amp;nbsp;host 170.X.X.84&lt;BR /&gt;object network 170.X.X.85&lt;BR /&gt;&amp;nbsp;host 170.X.X.85&lt;BR /&gt;object network 192.168.199.29&lt;BR /&gt;&amp;nbsp;host 192.168.199.29&lt;BR /&gt;&amp;nbsp;description Gaspar&lt;BR /&gt;object network 10.227.224.11&lt;BR /&gt;&amp;nbsp;host 10.227.224.11&lt;BR /&gt;&amp;nbsp;description CACTI_Carrier&lt;BR /&gt;object network CACTI_Carrier&lt;BR /&gt;&amp;nbsp;host 10.227.224.11&lt;BR /&gt;object network 10.227.224.0&lt;BR /&gt;&amp;nbsp;subnet 10.227.224.0 255.255.252.0&lt;BR /&gt;object network ALTAI&lt;BR /&gt;&amp;nbsp;host 172.16.99.22&lt;BR /&gt;object-group network redvpn&lt;BR /&gt;&amp;nbsp;network-object object 192.168.199.0&lt;BR /&gt;access-list CARRIERS_access_in extended permit ip 10.227.224.0 255.255.252.0 any&lt;BR /&gt;access-list CARRIERS_access_out extended permit ip any 10.227.224.0 255.255.252.0&lt;BR /&gt;access-list CARRIERS_access_out extended permit ip 192.168.199.0 255.255.255.0 10.227.224.0 255.255.252.0&lt;BR /&gt;access-list OUTSIDE_access_in remark ALTAI&lt;BR /&gt;access-list OUTSIDE_access_in extended permit ip any object 172.16.99.22&lt;BR /&gt;access-list OUTSIDE_access_in remark Centro Valle&lt;BR /&gt;access-list OUTSIDE_access_in extended permit tcp any object 10.227.225.20 eq 1930&lt;BR /&gt;access-list OUTSIDE_access_in remark Centro Valle&lt;BR /&gt;access-list OUTSIDE_access_in extended permit tcp any object 10.227.225.20 eq 1946&lt;BR /&gt;access-list OUTSIDE_access_in remark Stgo Contrato 4646&lt;BR /&gt;access-list OUTSIDE_access_in extended permit tcp any object 10.44.0.130 eq 3050&lt;BR /&gt;access-list OUTSIDE_access_in remark Prueba&lt;BR /&gt;access-list OUTSIDE_access_in extended permit ip any object 10.227.225.210&lt;BR /&gt;access-list OUTSIDE_access_in remark Gasolinera Holanda&lt;BR /&gt;access-list OUTSIDE_access_in extended permit ip any object 10.227.225.41&lt;BR /&gt;access-list OUTSIDE_access_in remark AutopartesStgo_Suc_NI&lt;BR /&gt;access-list OUTSIDE_access_in extended permit tcp any object 10.227.225.12 eq 81&lt;BR /&gt;access-list OUTSIDE_access_in remark AutopartesStgo_Suc_NI&lt;BR /&gt;access-list OUTSIDE_access_in extended permit tcp any object 10.227.225.12 eq rtsp&lt;BR /&gt;access-list OUTSIDE_access_in remark AutopartesStgo_Suc_NI&lt;BR /&gt;access-list OUTSIDE_access_in extended permit tcp any object 10.227.225.12 eq 8000&lt;BR /&gt;access-list OUTSIDE_access_in remark Ferrepisos_NI&lt;BR /&gt;access-list OUTSIDE_access_in extended permit tcp any object 10.227.225.31 eq 3389&lt;BR /&gt;access-list OUTSIDE_access_in remark Ferrepisos_NI&lt;BR /&gt;access-list OUTSIDE_access_in extended permit tcp any object 10.227.225.31 eq 8081&lt;BR /&gt;access-list OUTSIDE_access_in remark Gasolinera Samantha&lt;BR /&gt;access-list OUTSIDE_access_in extended permit ip any object 10.227.225.21&lt;BR /&gt;access-list OUTSIDE_access_in remark Gasolinera CM&lt;BR /&gt;access-list OUTSIDE_access_in extended permit ip any object 10.227.225.22&lt;BR /&gt;access-list OUTSIDE_access_in remark Farmacia Economica NI&lt;BR /&gt;access-list OUTSIDE_access_in extended permit ip any object 10.227.225.39&lt;BR /&gt;access-list OUTSIDE_access_in remark Caja Hipodromo NI&lt;BR /&gt;access-list OUTSIDE_access_in extended permit ip any object 10.227.225.29&lt;BR /&gt;access-list OUTSIDE_access_in remark CACTI_Carrier&lt;BR /&gt;access-list OUTSIDE_access_in extended permit ip any object 10.227.224.11&lt;BR /&gt;access-list OUTSIDE_access_in extended permit ip any any&lt;BR /&gt;access-list INSIDE_Prueba_access_in extended permit ip 192.168.62.0 255.255.255.0 any&lt;BR /&gt;access-list INSIDE_Prueba_access_in extended permit ip object 172.16.99.0 any&lt;BR /&gt;access-list INSIDE_Prueba_access_in extended permit ip object 192.168.199.0 any&lt;BR /&gt;access-list INSIDE_Prueba_access_in extended permit ip object 10.228.0.0 any&lt;BR /&gt;access-list INSIDE_Prueba_access_in extended permit ip 10.227.224.0 255.255.252.0 192.168.199.0 255.255.255.0&lt;BR /&gt;access-list INSIDE_Prueba_access_in extended permit ip 192.168.199.0 255.255.255.0 192.168.239.0 255.255.255.128&lt;BR /&gt;access-list ACL-tunel-vpn-prueba standard permit 192.168.239.0 255.255.255.0&lt;BR /&gt;access-list ACL-tunel-vpn-prueba standard permit 192.168.199.0 255.255.255.0&lt;BR /&gt;access-list INSIDE_Prueba_access_out extended permit ip 10.227.224.0 255.255.252.0 any&lt;BR /&gt;access-list INSIDE_Prueba_access_out extended permit ip 192.168.199.0 255.255.255.0 any&lt;BR /&gt;access-list INSIDE_Prueba_access_out extended permit ip any object 172.16.99.0&lt;BR /&gt;access-list INSIDE_Prueba_access_out extended permit ip 192.168.239.0 255.255.255.128 192.168.199.0 255.255.255.0&lt;BR /&gt;access-list TEST extended permit ip 192.168.199.0 255.255.255.0 192.168.239.0 255.255.255.128&lt;BR /&gt;access-list TEST extended permit ip 192.168.239.0 255.255.255.128 192.168.199.0 255.255.255.0&lt;BR /&gt;pager lines 24&lt;BR /&gt;logging enable&lt;BR /&gt;logging asdm informational&lt;BR /&gt;mtu management 1500&lt;BR /&gt;mtu OUTSIDE 1500&lt;BR /&gt;mtu CARRIERS 1500&lt;BR /&gt;mtu INSIDE_Prueba 1500&lt;BR /&gt;mtu CMTS 1500&lt;BR /&gt;ip local pool pool-vpn-prueba 192.168.239.1-192.168.239.100 mask 255.255.255.0&lt;BR /&gt;no failover&lt;BR /&gt;icmp unreachable rate-limit 1 burst-size 1&lt;BR /&gt;icmp permit any OUTSIDE&lt;BR /&gt;icmp permit any CARRIERS&lt;BR /&gt;icmp permit any echo CARRIERS&lt;BR /&gt;icmp permit any echo-reply CARRIERS&lt;BR /&gt;no asdm history enable&lt;BR /&gt;arp timeout 14400&lt;BR /&gt;no arp permit-nonconnected&lt;BR /&gt;nat (CMTS,OUTSIDE) source dynamic 10.19.0.0 170.X.X.16&lt;BR /&gt;nat (CMTS,OUTSIDE) source dynamic 10.27.0.0 170.X.X.17&lt;BR /&gt;nat (CMTS,OUTSIDE) source dynamic 10.25.0.0 170.X.X.18&lt;BR /&gt;nat (CMTS,OUTSIDE) source dynamic 10.9.0.0 170.X.X.12&lt;BR /&gt;nat (CMTS,OUTSIDE) source dynamic 10.39.0.0 170.X.X.20&lt;BR /&gt;nat (CMTS,OUTSIDE) source dynamic 10.11.0.0 170.X.X.11&lt;BR /&gt;nat (CMTS,OUTSIDE) source dynamic 10.35.0.0 170.X.X.22&lt;BR /&gt;nat (CMTS,OUTSIDE) source dynamic 10.33.0.0 170.X.X.23&lt;BR /&gt;nat (CMTS,OUTSIDE) source dynamic 10.13.0.0 170.X.X.13&lt;BR /&gt;nat (CMTS,OUTSIDE) source dynamic 10.17.0.0 170.X.X.25&lt;BR /&gt;nat (CMTS,OUTSIDE) source dynamic 10.37.0.0 170.X.X.26&lt;BR /&gt;nat (CMTS,OUTSIDE) source dynamic 10.41.0.0 170.X.X.27&lt;BR /&gt;nat (CMTS,OUTSIDE) source dynamic 10.33.0.0 170.X.X.29&lt;BR /&gt;nat (CMTS,OUTSIDE) source dynamic 10.47.0.0 170.X.X.21&lt;BR /&gt;nat (CMTS,OUTSIDE) source dynamic 10.49.0.0 170.X.X.24&lt;BR /&gt;nat (CARRIERS,OUTSIDE) source static 10.227.225.210 170.X.X.3&lt;BR /&gt;nat (CARRIERS,OUTSIDE) source static 10.227.225.41 170.X.X.82 description Gasolinera Holanda&lt;BR /&gt;nat (INSIDE_Prueba,OUTSIDE) source dynamic 10.228.0.0 170.X.X.10&lt;BR /&gt;nat (CMTS,OUTSIDE) source dynamic 10.51.0.0 pat-pool Pool_CMTS_Stgo&lt;BR /&gt;nat (CARRIERS,OUTSIDE) source static 10.227.225.21 170.X.X.80 description Gasolinera Samantha&lt;BR /&gt;nat (CARRIERS,OUTSIDE) source static 10.227.225.22 170.X.X.81 description Gasolinera CM&lt;BR /&gt;nat (CARRIERS,OUTSIDE) source static 10.227.225.39 170.X.X.83&lt;BR /&gt;nat (CARRIERS,OUTSIDE) source static 10.227.225.29 170.X.X.84&lt;BR /&gt;nat (INSIDE_Prueba,OUTSIDE) source static redvpn redvpn destination static NETWORK_OBJ_192.168.239.0_25 NETWORK_OBJ_192.168.239.0_25 no-proxy-arp&lt;BR /&gt;!&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&lt;BR /&gt;object network CentroValle_1930&lt;BR /&gt;&amp;nbsp;nat (CARRIERS,OUTSIDE) static interface service tcp 1930 11930&lt;BR /&gt;object network CentroValle_1946&lt;BR /&gt;&amp;nbsp;nat (CARRIERS,OUTSIDE) static interface service tcp 1946 11946&lt;BR /&gt;object network Stgo4646_3050&lt;BR /&gt;&amp;nbsp;nat (CMTS,OUTSIDE) static 170.X.X.28 service tcp 3050 13050&lt;BR /&gt;object network AutopartesStgo_Suc_NI_81&lt;BR /&gt;&amp;nbsp;nat (CARRIERS,OUTSIDE) static interface service tcp 81 10081&lt;BR /&gt;object network AutopartesStgo_Suc_NI_554&lt;BR /&gt;&amp;nbsp;nat (CARRIERS,OUTSIDE) static interface service tcp rtsp 10554&lt;BR /&gt;object network AutopartesStgo_Suc_NI_8000&lt;BR /&gt;&amp;nbsp;nat (CARRIERS,OUTSIDE) static interface service tcp 8000 18000&lt;BR /&gt;object network Ferrepisos_NI_3389&lt;BR /&gt;&amp;nbsp;nat (CARRIERS,OUTSIDE) static interface service tcp 3389 13389&lt;BR /&gt;object network Ferrepisos_NI_8081&lt;BR /&gt;&amp;nbsp;nat (CARRIERS,OUTSIDE) static interface service tcp 8081 18081&lt;BR /&gt;object network CACTI_Carrier&lt;BR /&gt;&amp;nbsp;nat (CARRIERS,OUTSIDE) static 170.X.X.6&lt;BR /&gt;object network ALTAI&lt;BR /&gt;&amp;nbsp;nat (INSIDE_Prueba,OUTSIDE) static 170.X.X.4&lt;BR /&gt;!&lt;BR /&gt;nat (CARRIERS,OUTSIDE) after-auto source dynamic any interface&lt;BR /&gt;nat (INSIDE_Prueba,OUTSIDE) after-auto source dynamic any interface&lt;BR /&gt;nat (CMTS,OUTSIDE) after-auto source dynamic 10.45.0.0 170.X.X.28&lt;BR /&gt;nat (OUTSIDE,OUTSIDE) after-auto source static pool-vpn-prueba interface no-proxy-arp&lt;BR /&gt;access-group OUTSIDE_access_in in interface OUTSIDE&lt;BR /&gt;access-group CARRIERS_access_in in interface CARRIERS&lt;BR /&gt;access-group CARRIERS_access_out out interface CARRIERS&lt;BR /&gt;access-group INSIDE_Prueba_access_out out interface INSIDE_Prueba&lt;BR /&gt;route OUTSIDE 0.0.0.0 0.0.0.0 170.X.X.1 1&lt;BR /&gt;route CMTS 10.8.0.0 255.255.0.0 192.168.61.102 1&lt;BR /&gt;route CMTS 10.9.0.0 255.255.0.0 192.168.61.102 1&lt;BR /&gt;route CMTS 10.10.0.0 255.255.0.0 192.168.61.101 1&lt;BR /&gt;route CMTS 10.11.0.0 255.255.0.0 192.168.61.101 1&lt;BR /&gt;route CMTS 10.12.0.0 255.255.0.0 192.168.61.114 1&lt;BR /&gt;route CMTS 10.13.0.0 255.255.0.0 192.168.61.114 1&lt;BR /&gt;route CMTS 10.16.0.0 255.255.0.0 192.168.61.112 1&lt;BR /&gt;route CMTS 10.17.0.0 255.255.0.0 192.168.61.112 1&lt;BR /&gt;route CMTS 10.18.0.0 255.255.0.0 192.168.61.111 1&lt;BR /&gt;route CMTS 10.19.0.0 255.255.0.0 192.168.61.111 1&lt;BR /&gt;route CMTS 10.24.0.0 255.255.0.0 192.168.61.122 1&lt;BR /&gt;route CMTS 10.25.0.0 255.255.0.0 192.168.61.122 1&lt;BR /&gt;route CMTS 10.26.0.0 255.255.0.0 192.168.61.123 1&lt;BR /&gt;route CMTS 10.27.0.0 255.255.0.0 192.168.61.123 1&lt;BR /&gt;route CMTS 10.32.0.0 255.255.0.0 192.168.61.130 1&lt;BR /&gt;route CMTS 10.33.0.0 255.255.0.0 192.168.61.130 1&lt;BR /&gt;route CMTS 10.34.0.0 255.255.0.0 192.168.61.131 1&lt;BR /&gt;route CMTS 10.35.0.0 255.255.0.0 192.168.61.131 1&lt;BR /&gt;route CMTS 10.36.0.0 255.255.0.0 192.168.61.132 1&lt;BR /&gt;route CMTS 10.37.0.0 255.255.0.0 192.168.61.132 1&lt;BR /&gt;route CMTS 10.38.0.0 255.255.0.0 192.168.61.133 1&lt;BR /&gt;route CMTS 10.39.0.0 255.255.0.0 192.168.61.133 1&lt;BR /&gt;route CMTS 10.40.0.0 255.255.0.0 192.168.61.134 1&lt;BR /&gt;route CMTS 10.41.0.0 255.255.0.0 192.168.61.134 1&lt;BR /&gt;route CMTS 10.44.0.0 255.255.0.0 192.168.61.135 1&lt;BR /&gt;route CMTS 10.45.0.0 255.255.0.0 192.168.61.135 1&lt;BR /&gt;route CMTS 10.46.0.0 255.255.0.0 192.168.61.137 1&lt;BR /&gt;route CMTS 10.47.0.0 255.255.0.0 192.168.61.137 1&lt;BR /&gt;route CMTS 10.48.0.0 255.255.0.0 192.168.61.138 1&lt;BR /&gt;route CMTS 10.49.0.0 255.255.0.0 192.168.61.138 1&lt;BR /&gt;route CMTS 10.50.0.0 255.255.0.0 192.168.61.139 1&lt;BR /&gt;route CMTS 10.51.0.0 255.255.0.0 192.168.61.139 1&lt;BR /&gt;route INSIDE_Prueba 10.228.0.0 255.255.0.0 192.168.62.253 1&lt;BR /&gt;route INSIDE_Prueba 172.16.99.0 255.255.255.0 192.168.62.253 1&lt;BR /&gt;route INSIDE_Prueba 192.168.199.0 255.255.255.0 192.168.62.253 1&lt;BR /&gt;timeout xlate 3:00:00&lt;BR /&gt;timeout pat-xlate 0:00:30&lt;BR /&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02&lt;BR /&gt;timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00&lt;BR /&gt;timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00&lt;BR /&gt;timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute&lt;BR /&gt;timeout tcp-proxy-reassembly 0:01:00&lt;BR /&gt;timeout floating-conn 0:00:00&lt;BR /&gt;dynamic-access-policy-record DfltAccessPolicy&lt;BR /&gt;user-identity default-domain LOCAL&lt;BR /&gt;aaa authentication ssh console LOCAL&lt;BR /&gt;aaa authentication enable console LOCAL&lt;BR /&gt;http server enable&lt;BR /&gt;http 192.168.0.0 255.255.255.0 management&lt;BR /&gt;snmp-server host management 192.168.0.2 community ***** udp-port 161&lt;BR /&gt;snmp-server location Site-Dg&lt;BR /&gt;no snmp-server contact&lt;BR /&gt;snmp-server community *****&lt;BR /&gt;snmp-server enable traps snmp authentication linkup linkdown coldstart warmstart&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-3DES-MD5 esp-3des esp-md5-hmac&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-DES-MD5 esp-des esp-md5-hmac&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-3DES-SHA esp-3des esp-sha-hmac&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-128-SHA esp-aes esp-sha-hmac&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-192-SHA esp-aes-192 esp-sha-hmac&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-128-MD5 esp-aes esp-md5-hmac&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-192-MD5 esp-aes-192 esp-md5-hmac&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-256-SHA esp-aes-256 esp-sha-hmac&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-256-MD5 esp-aes-256 esp-md5-hmac&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-DES-SHA esp-des esp-sha-hmac&lt;BR /&gt;crypto dynamic-map SYSTEM_DEFAULT_CRYPTO_MAP 65535 set ikev1 transform-set ESP-AES-128-SHA ESP-AES-128-MD5 ESP-AES-192-SHA ESP-AES-192-MD5 ESP-AES-256-SHA ESP-AES-256-MD5 ESP-3DES-SHA ESP-3DES-MD5 ESP-DES-SHA ESP-DES-MD5&lt;BR /&gt;crypto map INSIDE_Prueba_map 65535 ipsec-isakmp dynamic SYSTEM_DEFAULT_CRYPTO_MAP&lt;BR /&gt;crypto map INSIDE_Prueba_map interface INSIDE_Prueba&lt;BR /&gt;crypto map OUTSIDE_map 65535 ipsec-isakmp dynamic SYSTEM_DEFAULT_CRYPTO_MAP&lt;BR /&gt;crypto map OUTSIDE_map interface OUTSIDE&lt;BR /&gt;crypto ikev1 enable OUTSIDE&lt;BR /&gt;crypto ikev1 enable INSIDE_Prueba&lt;BR /&gt;crypto ikev1 policy 10&lt;BR /&gt;&amp;nbsp;authentication crack&lt;BR /&gt;&amp;nbsp;encryption aes-256&lt;BR /&gt;&amp;nbsp;hash sha&lt;BR /&gt;&amp;nbsp;group 2&lt;BR /&gt;&amp;nbsp;lifetime 86400&lt;BR /&gt;crypto ikev1 policy 20&lt;BR /&gt;&amp;nbsp;authentication rsa-sig&lt;BR /&gt;&amp;nbsp;encryption aes-256&lt;BR /&gt;&amp;nbsp;hash sha&lt;BR /&gt;&amp;nbsp;group 2&lt;BR /&gt;&amp;nbsp;lifetime 86400&lt;BR /&gt;crypto ikev1 policy 30&lt;BR /&gt;&amp;nbsp;authentication pre-share&lt;BR /&gt;&amp;nbsp;encryption aes-256&lt;BR /&gt;&amp;nbsp;hash sha&lt;BR /&gt;&amp;nbsp;group 2&lt;BR /&gt;&amp;nbsp;lifetime 86400&lt;BR /&gt;crypto ikev1 policy 40&lt;BR /&gt;&amp;nbsp;authentication crack&lt;BR /&gt;&amp;nbsp;encryption aes-192&lt;BR /&gt;&amp;nbsp;hash sha&lt;BR /&gt;&amp;nbsp;group 2&lt;BR /&gt;&amp;nbsp;lifetime 86400&lt;BR /&gt;crypto ikev1 policy 50&lt;BR /&gt;&amp;nbsp;authentication rsa-sig&lt;BR /&gt;&amp;nbsp;encryption aes-192&lt;BR /&gt;&amp;nbsp;hash sha&lt;BR /&gt;&amp;nbsp;group 2&lt;BR /&gt;&amp;nbsp;lifetime 86400&lt;BR /&gt;crypto ikev1 policy 60&lt;BR /&gt;&amp;nbsp;authentication pre-share&lt;BR /&gt;&amp;nbsp;encryption aes-192&lt;BR /&gt;&amp;nbsp;hash sha&lt;BR /&gt;&amp;nbsp;group 2&lt;BR /&gt;&amp;nbsp;lifetime 86400&lt;BR /&gt;crypto ikev1 policy 70&lt;BR /&gt;&amp;nbsp;authentication crack&lt;BR /&gt;&amp;nbsp;encryption aes&lt;BR /&gt;&amp;nbsp;hash sha&lt;BR /&gt;&amp;nbsp;group 2&lt;BR /&gt;&amp;nbsp;lifetime 86400&lt;BR /&gt;crypto ikev1 policy 80&lt;BR /&gt;&amp;nbsp;authentication rsa-sig&lt;BR /&gt;&amp;nbsp;encryption aes&lt;BR /&gt;&amp;nbsp;hash sha&lt;BR /&gt;&amp;nbsp;group 2&lt;BR /&gt;&amp;nbsp;lifetime 86400&lt;BR /&gt;crypto ikev1 policy 90&lt;BR /&gt;&amp;nbsp;authentication pre-share&lt;BR /&gt;&amp;nbsp;encryption aes&lt;BR /&gt;&amp;nbsp;hash sha&lt;BR /&gt;&amp;nbsp;group 2&lt;BR /&gt;&amp;nbsp;lifetime 86400&lt;BR /&gt;crypto ikev1 policy 100&lt;BR /&gt;&amp;nbsp;authentication crack&lt;BR /&gt;&amp;nbsp;encryption 3des&lt;BR /&gt;&amp;nbsp;hash sha&lt;BR /&gt;&amp;nbsp;group 2&lt;BR /&gt;&amp;nbsp;lifetime 86400&lt;BR /&gt;crypto ikev1 policy 110&lt;BR /&gt;&amp;nbsp;authentication rsa-sig&lt;BR /&gt;&amp;nbsp;encryption 3des&lt;BR /&gt;&amp;nbsp;hash sha&lt;BR /&gt;&amp;nbsp;group 2&lt;BR /&gt;&amp;nbsp;lifetime 86400&lt;BR /&gt;crypto ikev1 policy 120&lt;BR /&gt;&amp;nbsp;authentication pre-share&lt;BR /&gt;&amp;nbsp;encryption 3des&lt;BR /&gt;&amp;nbsp;hash sha&lt;BR /&gt;&amp;nbsp;group 2&lt;BR /&gt;&amp;nbsp;lifetime 86400&lt;BR /&gt;crypto ikev1 policy 130&lt;BR /&gt;&amp;nbsp;authentication crack&lt;BR /&gt;&amp;nbsp;encryption des&lt;BR /&gt;&amp;nbsp;hash sha&lt;BR /&gt;&amp;nbsp;group 2&lt;BR /&gt;&amp;nbsp;lifetime 86400&lt;BR /&gt;crypto ikev1 policy 140&lt;BR /&gt;&amp;nbsp;authentication rsa-sig&lt;BR /&gt;&amp;nbsp;encryption des&lt;BR /&gt;&amp;nbsp;hash sha&lt;BR /&gt;&amp;nbsp;group 2&lt;BR /&gt;&amp;nbsp;lifetime 86400&lt;BR /&gt;crypto ikev1 policy 150&lt;BR /&gt;&amp;nbsp;authentication pre-share&lt;BR /&gt;&amp;nbsp;encryption des&lt;BR /&gt;&amp;nbsp;hash sha&lt;BR /&gt;&amp;nbsp;group 2&lt;BR /&gt;&amp;nbsp;lifetime 86400&lt;BR /&gt;telnet timeout 5&lt;BR /&gt;ssh 192.168.0.0 255.255.255.0 management&lt;BR /&gt;ssh timeout 5&lt;BR /&gt;ssh key-exchange group dh-group1-sha1&lt;BR /&gt;console timeout 0&lt;BR /&gt;management-access INSIDE_Prueba&lt;BR /&gt;!&lt;BR /&gt;tls-proxy maximum-session 1000&lt;BR /&gt;!&lt;BR /&gt;threat-detection basic-threat&lt;BR /&gt;threat-detection statistics access-list&lt;BR /&gt;no threat-detection statistics tcp-intercept&lt;BR /&gt;webvpn&lt;BR /&gt;group-policy DfltGrpPolicy attributes&lt;BR /&gt;&amp;nbsp;vpn-tunnel-protocol ikev1 ikev2 ssl-clientless&lt;BR /&gt;group-policy policiy-tunel-vpn-prueba-all internal&lt;BR /&gt;group-policy policiy-tunel-vpn-prueba-all attributes&lt;BR /&gt;&amp;nbsp;dns-server value 209.244.0.3 209.244.0.4&lt;BR /&gt;&amp;nbsp;vpn-tunnel-protocol ikev1 ssl-clientless&lt;BR /&gt;&amp;nbsp;split-tunnel-policy tunnelall&lt;BR /&gt;group-policy policiy-tunel-vpn-prueba-split internal&lt;BR /&gt;group-policy policiy-tunel-vpn-prueba-split attributes&lt;BR /&gt;&amp;nbsp;vpn-tunnel-protocol ikev1&lt;BR /&gt;&amp;nbsp;split-tunnel-policy tunnelspecified&lt;BR /&gt;&amp;nbsp;split-tunnel-network-list value ACL-tunel-vpn-prueba&lt;BR /&gt;username fermin password vWzuhgp2s encrypted privilege 15&lt;BR /&gt;username gaspar password uFhUyhgi encrypted privilege 15&lt;BR /&gt;username extra password Mgi9n5u3x encrypted privilege 15&lt;BR /&gt;tunnel-group tunel-vpn-prueba type remote-access&lt;BR /&gt;tunnel-group tunel-vpn-prueba general-attributes&lt;BR /&gt;&amp;nbsp;address-pool pool-vpn-prueba&lt;BR /&gt;&amp;nbsp;default-group-policy policiy-tunel-vpn-prueba-split&lt;BR /&gt;tunnel-group tunel-vpn-prueba ipsec-attributes&lt;BR /&gt;&amp;nbsp;ikev1 pre-shared-key *****&lt;BR /&gt;!&lt;BR /&gt;class-map inspection_default&lt;BR /&gt;&amp;nbsp;match default-inspection-traffic&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;policy-map type inspect dns preset_dns_map&lt;BR /&gt;&amp;nbsp;parameters&lt;BR /&gt;&amp;nbsp; message-length maximum client auto&lt;BR /&gt;&amp;nbsp; message-length maximum 512&lt;BR /&gt;policy-map global_policy&lt;BR /&gt;&amp;nbsp;class inspection_default&lt;BR /&gt;&amp;nbsp; inspect dns preset_dns_map&lt;BR /&gt;&amp;nbsp; inspect ftp&lt;BR /&gt;&amp;nbsp; inspect h323 h225&lt;BR /&gt;&amp;nbsp; inspect h323 ras&lt;BR /&gt;&amp;nbsp; inspect ip-options&lt;BR /&gt;&amp;nbsp; inspect netbios&lt;BR /&gt;&amp;nbsp; inspect rsh&lt;BR /&gt;&amp;nbsp; inspect rtsp&lt;BR /&gt;&amp;nbsp; inspect skinny &amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect esmtp&lt;BR /&gt;&amp;nbsp; inspect sqlnet&lt;BR /&gt;&amp;nbsp; inspect sunrpc&lt;BR /&gt;&amp;nbsp; inspect tftp&lt;BR /&gt;&amp;nbsp; inspect sip &amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect xdmcp&lt;BR /&gt;&amp;nbsp; inspect icmp&lt;BR /&gt;&amp;nbsp; inspect icmp error&lt;BR /&gt;!&lt;BR /&gt;service-policy global_policy global&lt;BR /&gt;prompt hostname context&lt;BR /&gt;no call-home reporting anonymous&lt;BR /&gt;call-home&lt;BR /&gt;&amp;nbsp;profile CiscoTAC-1&lt;BR /&gt;&amp;nbsp; no active&lt;BR /&gt;&amp;nbsp; destination address http &lt;A href="https://tools.cisco.com/its/service/oddce/services/DDCEService" target="_blank"&gt;https://tools.cisco.com/its/service/oddce/services/DDCEService&lt;/A&gt;&lt;BR /&gt;&amp;nbsp; destination address email callhome@cisco.com&lt;BR /&gt;&amp;nbsp; destination transport-method http&lt;BR /&gt;&amp;nbsp; subscribe-to-alert-group diagnostic&lt;BR /&gt;&amp;nbsp; subscribe-to-alert-group environment&lt;BR /&gt;&amp;nbsp; subscribe-to-alert-group inventory periodic monthly 7&lt;BR /&gt;&amp;nbsp; subscribe-to-alert-group configuration periodic monthly 7&lt;BR /&gt;&amp;nbsp; subscribe-to-alert-group telemetry periodic daily&lt;BR /&gt;Cryptochecksum:b209f3af7ae5cf8467a&lt;BR /&gt;: end&lt;/P&gt;</description>
      <pubDate>Fri, 08 Sep 2017 22:03:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5580-remote-access-vpn-problem/m-p/3181937#M1066433</guid>
      <dc:creator>gasparmenendez</dc:creator>
      <dc:date>2017-09-08T22:03:36Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 55810 remote access VPN problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-5580-remote-access-vpn-problem/m-p/3182022#M1066437</link>
      <description>&lt;P&gt;I see that subnet 192.168.199.0 is not directly connected to ASA. It has a route pointing towards 192.168.62.253.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1) whose ip is&amp;nbsp;192.168.62.253 ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In server's route print output i noticed that server has a default gateway 192.168.199.254.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2) &amp;nbsp;whose ip&amp;nbsp;192.168.199.254 ?&lt;/P&gt;</description>
      <pubDate>Sat, 09 Sep 2017 10:31:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5580-remote-access-vpn-problem/m-p/3182022#M1066437</guid>
      <dc:creator>Spooster IT Services</dc:creator>
      <dc:date>2017-09-09T10:31:43Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 55810 remote access VPN problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-5580-remote-access-vpn-problem/m-p/3182518#M1066440</link>
      <description>&lt;P&gt;sorry about the delay mi friend....&lt;/P&gt;&lt;P&gt;192.168.62.253 and 192.168.199.254 are vlan's ip addresses in the Sw 3750 connected directly to ASA. Here from my Sw 3750:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;interface GigabitEthernet1/0/5&lt;BR /&gt;&amp;nbsp;description *** Interfaz prueba ASA5580 ***&lt;BR /&gt;&amp;nbsp;switchport access vlan 62&lt;BR /&gt;&amp;nbsp;switchport mode access&lt;BR /&gt;&amp;nbsp;switchport nonegotiate&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;interface Vlan62&lt;BR /&gt;&amp;nbsp;description *** Prueba CMTS 2 ***&lt;BR /&gt;&amp;nbsp;ip address 192.168.62.253 255.255.255.0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;interface Vlan199&lt;BR /&gt;&amp;nbsp;description *** Pruebas Level3 ***&lt;BR /&gt;&amp;nbsp;ip address 192.168.199.254 255.255.255.0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ip route 0.0.0.0 0.0.0.0 192.168.62.254&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;please let me know if you need anything else.&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Sep 2017 15:30:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5580-remote-access-vpn-problem/m-p/3182518#M1066440</guid>
      <dc:creator>gasparmenendez</dc:creator>
      <dc:date>2017-09-11T15:30:09Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 55810 remote access VPN problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-5580-remote-access-vpn-problem/m-p/3183165#M1066441</link>
      <description>&lt;P&gt;hi my friend,&lt;/P&gt;&lt;P&gt;did you see my last post??&lt;/P&gt;&lt;P&gt;thanks.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Sep 2017 17:36:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5580-remote-access-vpn-problem/m-p/3183165#M1066441</guid>
      <dc:creator>gasparmenendez</dc:creator>
      <dc:date>2017-09-12T17:36:21Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 55810 remote access VPN problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-5580-remote-access-vpn-problem/m-p/3183186#M1066442</link>
      <description>&lt;P&gt;From your last two posts everything looks good in between server and ASA. Try the following commands&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;no&amp;nbsp;&lt;SPAN&gt;nat (INSIDE_Prueba,OUTSIDE) source static redvpn redvpn destination static NETWORK_OBJ_192.168.239.0_25 NETWORK_OBJ_192.168.239.0_25 no-proxy-arp&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;nat (INSIDE_Prueba,OUTSIDE) source static redvpn redvpn destination static NETWORK_OBJ_192.168.239.0_25 NETWORK_OBJ_192.168.239.0_25&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Sep 2017 18:00:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5580-remote-access-vpn-problem/m-p/3183186#M1066442</guid>
      <dc:creator>Spooster IT Services</dc:creator>
      <dc:date>2017-09-12T18:00:34Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 55810 remote access VPN problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-5580-remote-access-vpn-problem/m-p/3183276#M1066443</link>
      <description>&lt;P&gt;tried that already without luck my friend....&lt;/P&gt;</description>
      <pubDate>Tue, 12 Sep 2017 21:57:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5580-remote-access-vpn-problem/m-p/3183276#M1066443</guid>
      <dc:creator>gasparmenendez</dc:creator>
      <dc:date>2017-09-12T21:57:42Z</dc:date>
    </item>
  </channel>
</rss>

