<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA is not encapsulating from IPSEC in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-is-not-encapsulating-from-ipsec/m-p/4592772#M1089239</link>
    <description>&lt;P&gt;Can we see asa config?&lt;/P&gt;</description>
    <pubDate>Thu, 14 Apr 2022 17:18:27 GMT</pubDate>
    <dc:creator>MHM Cisco World</dc:creator>
    <dc:date>2022-04-14T17:18:27Z</dc:date>
    <item>
      <title>ASA is not encapsulating from IPSEC</title>
      <link>https://community.cisco.com/t5/network-security/asa-is-not-encapsulating-from-ipsec/m-p/4592760#M1089237</link>
      <description>&lt;P&gt;I have a tunnel (ASA &amp;lt;&amp;gt; Meraki) tunnel is up and I can verify both ends.&lt;BR /&gt;&lt;BR /&gt;Problem is that, IPSEC from ASA can't encapsulate any packets but can decapsulate.&lt;/P&gt;</description>
      <pubDate>Thu, 14 Apr 2022 17:05:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-is-not-encapsulating-from-ipsec/m-p/4592760#M1089237</guid>
      <dc:creator>baroncse</dc:creator>
      <dc:date>2022-04-14T17:05:04Z</dc:date>
    </item>
    <item>
      <title>Re: ASA is not encapsulating from IPSEC</title>
      <link>https://community.cisco.com/t5/network-security/asa-is-not-encapsulating-from-ipsec/m-p/4592763#M1089238</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1254272"&gt;@baroncse&lt;/a&gt; so it's probably a NAT or routing issue on the ASA. Do you have a NAT exemption rule on the ASA to ensure traffic between your local network to the remote network(s) is not unintentially translated?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Example:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE&gt;object network LOCAL&lt;BR /&gt;&amp;nbsp;subnet 192.168.10.0 255.255.255.0&lt;BR /&gt;object network REMOTE&lt;BR /&gt;&amp;nbsp;subnet 192.168.20.0 255.255.255.0&lt;BR /&gt;nat (INSIDE,OUTSIDE) source static LOCAL LOCAL destination static REMOTE REMOTE no-proxy-arp &lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Apr 2022 17:08:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-is-not-encapsulating-from-ipsec/m-p/4592763#M1089238</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2022-04-14T17:08:52Z</dc:date>
    </item>
    <item>
      <title>Re: ASA is not encapsulating from IPSEC</title>
      <link>https://community.cisco.com/t5/network-security/asa-is-not-encapsulating-from-ipsec/m-p/4592772#M1089239</link>
      <description>&lt;P&gt;Can we see asa config?&lt;/P&gt;</description>
      <pubDate>Thu, 14 Apr 2022 17:18:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-is-not-encapsulating-from-ipsec/m-p/4592772#M1089239</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2022-04-14T17:18:27Z</dc:date>
    </item>
    <item>
      <title>Re: ASA is not encapsulating from IPSEC</title>
      <link>https://community.cisco.com/t5/network-security/asa-is-not-encapsulating-from-ipsec/m-p/4592834#M1089243</link>
      <description>&lt;P&gt;I do have this. This ASA is on default so far, I only have 2 NAT, 1 for Anyconnect and this Tunnel.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;object network LOCAL&lt;BR /&gt;subnet 10.10.10.0 255.255.255.0&lt;BR /&gt;object-group network REMOTE&lt;BR /&gt;network-object 10.17.2.0 255.255.255.0&lt;BR /&gt;network-object 10.17.1.0 255.255.255.0&lt;BR /&gt;&lt;BR /&gt;access-list acl_cryptomap extended permit ip object LOCAL object-group REMOTE&lt;/P&gt;&lt;P&gt;nat (inside,outside) source static LOCAL LOCAL destination static REMOTE REMOTE no-proxy-arp route-lookup&lt;/P&gt;&lt;P&gt;crypto ikev1 policy 10&lt;BR /&gt;authentication pre-share&lt;BR /&gt;encryption aes-256&lt;BR /&gt;hash sha&lt;BR /&gt;group 2&lt;BR /&gt;lifetime 86400&lt;/P&gt;&lt;P&gt;tunnel-group 1.1.1.1 type ipsec-l2l&lt;BR /&gt;tunnel-group 1.1.1.1 ipsec-attributes&lt;BR /&gt;ikev1 pre-shared-key ********&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-256-SHA_REMOTE esp-aes-256 esp-sha-hmac&lt;/P&gt;&lt;P&gt;crypto map outside_map 50 match address acl_cryptomap&lt;BR /&gt;crypto map outside_map 50 set peer 1.1.1.1&lt;BR /&gt;crypto map outside_map 50 set ikev1 transform-set ESP-AES-256-SHA_REMOTE&lt;BR /&gt;crypto map outside_map 50 set security-association lifetime kilobytes unlimited&lt;/P&gt;</description>
      <pubDate>Thu, 14 Apr 2022 18:47:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-is-not-encapsulating-from-ipsec/m-p/4592834#M1089243</guid>
      <dc:creator>baroncse</dc:creator>
      <dc:date>2022-04-14T18:47:33Z</dc:date>
    </item>
    <item>
      <title>Re: ASA is not encapsulating from IPSEC</title>
      <link>https://community.cisco.com/t5/network-security/asa-is-not-encapsulating-from-ipsec/m-p/4592838#M1089244</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1254272"&gt;@baroncse&lt;/a&gt; is traffic routed to the ASA and out the via the outside interface?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Run packet-tracer twice and provide the output of the second, example:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE&gt;packet-tracer input inside tcp 10.10.10.5 3000 10.10.17.5 80&lt;/PRE&gt;
&lt;P&gt;Provide the output of "show nat detail" and "show crypto ipsec sa" &lt;/P&gt;</description>
      <pubDate>Thu, 14 Apr 2022 18:51:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-is-not-encapsulating-from-ipsec/m-p/4592838#M1089244</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2022-04-14T18:51:52Z</dc:date>
    </item>
    <item>
      <title>Re: ASA is not encapsulating from IPSEC</title>
      <link>https://community.cisco.com/t5/network-security/asa-is-not-encapsulating-from-ipsec/m-p/4592848#M1089246</link>
      <description>&lt;P&gt;Weird when I sent this:&lt;/P&gt;&lt;PRE&gt;packet-tracer input inside tcp 10.10.10.5 3000 10.10.17.5 80&lt;/PRE&gt;&lt;P&gt;Packets got encapsulated and I can ping from local to remote now.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;pcap second:&lt;/P&gt;&lt;P&gt;Phase: 1&lt;BR /&gt;Type: FLOW-LOOKUP&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;Found flow with id 3857, using existing flow&lt;/P&gt;&lt;P&gt;Result:&lt;BR /&gt;input-interface: inside&lt;BR /&gt;input-status: up&lt;BR /&gt;input-line-status: up&lt;BR /&gt;Action: allow&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;sh nat det:&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;1 (inside) to (outside) source static LOCAL LOCAL destination static Anyconnect_Users Anyconnect_Users no-proxy-arp route-lookup&lt;BR /&gt;translate_hits = 0, untranslate_hits = 0&lt;BR /&gt;Source - Origin: 10.10.10.0/24, Translated: 10.10.10.0/24&lt;BR /&gt;Destination - Origin: 172.0.0.0/24, Translated: 172.0.0.0/24&lt;BR /&gt;&lt;BR /&gt;2 (inside) to (outside) source static LOCAL LOCAL destination static REMOTE REMOTE no-proxy-arp route-lookup&lt;BR /&gt;translate_hits = 203, untranslate_hits = 206&lt;BR /&gt;Source - Origin: 10.10.10.0/24, Translated: 10.10.10.0/24&lt;BR /&gt;Destination - Origin: 10.17.2.0/24, 10.17.1.0/24, Translated: 10.17.2.0/24, 10.17.1.0/24&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Auto NAT Policies (Section 2)&lt;BR /&gt;1 (inside) to (outside) source dynamic inside-nat interface&lt;BR /&gt;translate_hits = 2778, untranslate_hits = 19&lt;BR /&gt;Source - Origin: 10.10.10.0/24, Translated: ********** (outside int ip)&lt;BR /&gt;&lt;BR /&gt;2 (outside) to (outside) source dynamic Anyconnect-NAT interface&lt;BR /&gt;translate_hits = 0, untranslate_hits = 0&lt;BR /&gt;Source - Origin: 172.0.0.0/24, Translated: ************ (outside int ip)&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Apr 2022 19:00:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-is-not-encapsulating-from-ipsec/m-p/4592848#M1089246</guid>
      <dc:creator>baroncse</dc:creator>
      <dc:date>2022-04-14T19:00:53Z</dc:date>
    </item>
    <item>
      <title>Re: ASA is not encapsulating from IPSEC</title>
      <link>https://community.cisco.com/t5/network-security/asa-is-not-encapsulating-from-ipsec/m-p/4592852#M1089247</link>
      <description>&lt;P&gt;from LOCAL device connected to ASA I can ping and RDP but from REMOTE device end I can't ping ASA and the device. Looks like one way comms.&lt;/P&gt;</description>
      <pubDate>Thu, 14 Apr 2022 19:11:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-is-not-encapsulating-from-ipsec/m-p/4592852#M1089247</guid>
      <dc:creator>baroncse</dc:creator>
      <dc:date>2022-04-14T19:11:17Z</dc:date>
    </item>
    <item>
      <title>Re: ASA is not encapsulating from IPSEC</title>
      <link>https://community.cisco.com/t5/network-security/asa-is-not-encapsulating-from-ipsec/m-p/4592912#M1089249</link>
      <description>&lt;P&gt;&lt;SPAN&gt;object-group network &lt;STRONG&gt;REMOTE&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;network-object &lt;FONT color="#FF0000"&gt;&lt;U&gt;10.17.2.0&lt;/U&gt;&lt;/FONT&gt; 255.255.255.0&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;network-object &lt;U&gt;&lt;FONT color="#FF0000"&gt;10.17.1.0&lt;/FONT&gt;&lt;/U&gt; 255.255.255.0&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;packet-tracer input inside tcp 10.10.10.5 3000 &lt;U&gt;&lt;FONT color="#FF0000"&gt;10.10.17.5&lt;/FONT&gt;&lt;/U&gt; 80&lt;/PRE&gt;&lt;P&gt;&lt;BR /&gt;just note:- packet-tracer destination is different than ACL and NAT?&lt;BR /&gt;&lt;BR /&gt;are you sure the traffic is pass ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Apr 2022 21:52:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-is-not-encapsulating-from-ipsec/m-p/4592912#M1089249</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2022-04-14T21:52:12Z</dc:date>
    </item>
    <item>
      <title>Re: ASA is not encapsulating from IPSEC</title>
      <link>https://community.cisco.com/t5/network-security/asa-is-not-encapsulating-from-ipsec/m-p/4593548#M1089266</link>
      <description>&lt;P&gt;he provided this one&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;packet-tracer input inside tcp 10.10.10.5 3000 &lt;U&gt;&lt;FONT color="#FF0000"&gt;10.10.17.5&lt;/FONT&gt;&lt;/U&gt; 80&lt;/PRE&gt;&lt;P&gt;but I used this one&lt;/P&gt;&lt;PRE&gt;packet-tracer input inside tcp 10.10.10.10 3000 &lt;U&gt;&lt;FONT color="#FF0000"&gt;10.17.1.5&lt;/FONT&gt;&lt;/U&gt; 80&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;All set now.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 15 Apr 2022 14:02:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-is-not-encapsulating-from-ipsec/m-p/4593548#M1089266</guid>
      <dc:creator>baroncse</dc:creator>
      <dc:date>2022-04-15T14:02:14Z</dc:date>
    </item>
  </channel>
</rss>

