<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hi Kevin, in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cannot-ping-inside-interface-via-site-to-site-vpn/m-p/2972308#M150386</link>
    <description>&lt;P&gt;Hi Kevin,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Please add the route-lookup command at the end of your NAT statement as per below:&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="color: #0000ff;"&gt;&lt;STRONG&gt;&lt;EM&gt;nat (inside,outside) source static Branch_Segment Branch_Segment destination static HQ_Segment HQ_Segment route-lookup&lt;/EM&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;http://packetpushers.net/understanding-when-a-cisco-asa-nat-rule-can-override-the-asa-routing-table/&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;HTH.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Please rate helpful post.&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Terence&lt;/P&gt;</description>
    <pubDate>Tue, 30 Aug 2016 10:10:59 GMT</pubDate>
    <dc:creator>Terence Payet</dc:creator>
    <dc:date>2016-08-30T10:10:59Z</dc:date>
    <item>
      <title>Cannot ping inside interface via site-to-site VPN</title>
      <link>https://community.cisco.com/t5/network-security/cannot-ping-inside-interface-via-site-to-site-vpn/m-p/2972307#M150385</link>
      <description>&lt;P&gt;Hi ALL,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I have setup a site-to-site VPN between HQ and branch.&lt;/P&gt;
&lt;P&gt;I am able to ping those segment behind Cisco ASA 5506-X (branch) from segment behind SonicWALL (HQ).&lt;/P&gt;
&lt;P&gt;But cannot ping inside interface (192.168.101.2) in Cisco ASA.&lt;/P&gt;
&lt;P&gt;Need your advise.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;branch# sh run&lt;BR /&gt;&lt;BR /&gt;hostname branch&lt;BR /&gt;enable password 0e53SZdxezxawxDG encrypted&lt;BR /&gt;xlate per-session deny tcp any4 any4&lt;BR /&gt;xlate per-session deny tcp any4 any6&lt;BR /&gt;xlate per-session deny tcp any6 any4&lt;BR /&gt;xlate per-session deny tcp any6 any6&lt;BR /&gt;xlate per-session deny udp any4 any4 eq domain&lt;BR /&gt;xlate per-session deny udp any4 any6 eq domain&lt;BR /&gt;xlate per-session deny udp any6 any4 eq domain&lt;BR /&gt;xlate per-session deny udp any6 any6 eq domain&lt;BR /&gt;names&lt;BR /&gt;name 192.168.14.0 Guest_Wifi description Guest Wifi&lt;BR /&gt;name 172.28.4.0 Office_Wifi description Office Wifi&lt;BR /&gt;name 172.16.4.0 Wifi_Mgmt description Wifi Mgmt&lt;BR /&gt;name 172.27.4.0 Xentry_Wifi description Xentry Wifi&lt;BR /&gt;name 172.16.1.0 HQ_Mgmt description HQ_Mgmt&lt;BR /&gt;name 10.12.1.0 Office_LAN description Office LAN&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet1/1&lt;BR /&gt;&amp;nbsp;no nameif&lt;BR /&gt;&amp;nbsp;no security-level&lt;BR /&gt;&amp;nbsp;no ip address&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet1/1.100&lt;BR /&gt;&amp;nbsp;description Unifi 50Mbps&lt;BR /&gt;&amp;nbsp;vlan 100&lt;BR /&gt;&amp;nbsp;nameif outside&lt;BR /&gt;&amp;nbsp;security-level 0&lt;BR /&gt;&amp;nbsp;ip address 175.140.195.166 255.255.255.0 &lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet1/1.101&lt;BR /&gt;&amp;nbsp;vlan 101&lt;BR /&gt;&amp;nbsp;nameif inside&lt;BR /&gt;&amp;nbsp;security-level 100&lt;BR /&gt;&amp;nbsp;ip address 192.168.101.2 255.255.255.252 &lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet1/2&lt;BR /&gt;&amp;nbsp;description Guest&lt;BR /&gt;&amp;nbsp;no nameif&lt;BR /&gt;&amp;nbsp;security-level 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;BR /&gt;&amp;nbsp;no ip address&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet1/3&lt;BR /&gt;&amp;nbsp;no nameif&lt;BR /&gt;&amp;nbsp;no security-level&lt;BR /&gt;&amp;nbsp;no ip address&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet1/4&lt;BR /&gt;&amp;nbsp;shutdown&lt;BR /&gt;&amp;nbsp;no nameif&lt;BR /&gt;&amp;nbsp;no security-level&amp;nbsp;&amp;nbsp; &lt;BR /&gt;&amp;nbsp;no ip address&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet1/5&lt;BR /&gt;&amp;nbsp;shutdown&lt;BR /&gt;&amp;nbsp;no nameif&lt;BR /&gt;&amp;nbsp;no security-level&lt;BR /&gt;&amp;nbsp;no ip address&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet1/6&lt;BR /&gt;&amp;nbsp;shutdown&lt;BR /&gt;&amp;nbsp;no nameif&lt;BR /&gt;&amp;nbsp;no security-level&lt;BR /&gt;&amp;nbsp;no ip address&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet1/7&lt;BR /&gt;&amp;nbsp;shutdown&lt;BR /&gt;&amp;nbsp;no nameif&lt;BR /&gt;&amp;nbsp;no security-level&lt;BR /&gt;&amp;nbsp;no ip address&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet1/8&lt;BR /&gt;&amp;nbsp;shutdown&lt;BR /&gt;&amp;nbsp;no nameif&lt;BR /&gt;&amp;nbsp;no security-level&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;BR /&gt;&amp;nbsp;no ip address&lt;BR /&gt;!&lt;BR /&gt;interface Management1/1&lt;BR /&gt;&amp;nbsp;management-only&lt;BR /&gt;&amp;nbsp;no nameif&lt;BR /&gt;&amp;nbsp;no security-level&lt;BR /&gt;&amp;nbsp;no ip address&lt;BR /&gt;!&lt;BR /&gt;boot system disk0:/asa961-lfbff-k8.SPA&lt;BR /&gt;ftp mode passive&lt;BR /&gt;clock timezone MYT 8&lt;BR /&gt;object network obj_any&lt;BR /&gt;&amp;nbsp;subnet 0.0.0.0 0.0.0.0&lt;BR /&gt;object network NETWORK_OBJ_10.3.96.0_24&lt;BR /&gt;&amp;nbsp;subnet 10.3.96.0 255.255.255.0&lt;BR /&gt;object network Facing_FW&lt;BR /&gt;&amp;nbsp;range 192.168.101.1 192.168.101.2&lt;BR /&gt;&amp;nbsp;description Facing FW Segment&lt;BR /&gt;object network Office_LAN&lt;BR /&gt;&amp;nbsp;subnet 10.12.1.0 255.255.255.0&lt;BR /&gt;&amp;nbsp;description Branch Office LAN&lt;BR /&gt;object network Wifi_Mgmt&lt;BR /&gt;&amp;nbsp;subnet 172.16.4.0 255.255.255.0&lt;BR /&gt;&amp;nbsp;description Wifi Management Segment&lt;BR /&gt;object network Office_Wifi&lt;BR /&gt;&amp;nbsp;subnet 172.28.4.0 255.255.255.0&lt;BR /&gt;&amp;nbsp;description Office Wifi Segment&lt;BR /&gt;object network Server_Segment&lt;BR /&gt;&amp;nbsp;subnet 10.1.1.0 255.255.255.0&lt;BR /&gt;&amp;nbsp;description HQ Server Segment&lt;BR /&gt;object network HQ_2nd_Floor&lt;BR /&gt;&amp;nbsp;subnet 10.3.66.0 255.255.255.0&lt;BR /&gt;&amp;nbsp;description HQ 2nd Floor Users&lt;BR /&gt;object network NETWORK_OBJ_10.1.1.0_24&lt;BR /&gt;&amp;nbsp;subnet 10.1.1.0 255.255.255.0&lt;BR /&gt;object network NETWORK_OBJ_10.12.1.0_24&lt;BR /&gt;&amp;nbsp;subnet 10.12.1.0 255.255.255.0&lt;BR /&gt;object-group network Branch_Segment&lt;BR /&gt;&amp;nbsp;description Local VPN Segment&lt;BR /&gt;&amp;nbsp;network-object object Office_LAN&lt;BR /&gt;&amp;nbsp;network-object object Office_Wifi&lt;BR /&gt;&amp;nbsp;network-object object Wifi_Mgmt&lt;BR /&gt;&amp;nbsp;network-object object Facing_FW&lt;BR /&gt;object-group network HQ_Segment&lt;BR /&gt;&amp;nbsp;description HQ VPN Segment&lt;BR /&gt;&amp;nbsp;network-object object HQ_2nd_Floor&lt;BR /&gt;&amp;nbsp;network-object object Server_Segment&lt;BR /&gt;&amp;nbsp;network-object 10.3.65.0 255.255.255.0&lt;BR /&gt;&lt;BR /&gt;access-list inside_access_in extended permit ip any any &lt;BR /&gt;access-list outside_cryptomap extended permit ip object-group&amp;nbsp; Branch_Segment object-group HQ_Segment &lt;BR /&gt;pager lines 24&lt;BR /&gt;logging enable&lt;BR /&gt;logging timestamp&lt;BR /&gt;logging buffer-size 512000&lt;BR /&gt;logging console informational&lt;BR /&gt;logging buffered debugging&lt;BR /&gt;logging asdm informational&lt;BR /&gt;mtu outside 1500&lt;BR /&gt;mtu inside 1500&lt;BR /&gt;mtu guest 1500&lt;BR /&gt;mtu outside2 1492&lt;BR /&gt;no failover&lt;BR /&gt;no monitor-interface service-module &lt;BR /&gt;icmp unreachable rate-limit 1 burst-size 1&lt;BR /&gt;icmp permit any inside&lt;BR /&gt;asdm image disk0:/asdm-761.bin&lt;BR /&gt;no asdm history enable&lt;BR /&gt;arp timeout 14400&lt;BR /&gt;no arp permit-nonconnected&lt;BR /&gt;nat (inside,outside) source static Branch_Segment Branch_Segment destination static HQ_Segment HQ_Segment no-proxy-arp route-lookup&lt;BR /&gt;nat (inside,outside) source dynamic any interface&lt;BR /&gt;route outside 0.0.0.0 0.0.0.0 175.140.195.165 1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;BR /&gt;route inside Office_LAN 255.255.255.0 192.168.101.1 1&lt;BR /&gt;route inside Wifi_Mgmt 255.255.255.0 192.168.101.1 1&lt;BR /&gt;route inside Xentry_Wifi 255.255.255.0 192.168.101.1 1&lt;BR /&gt;route inside Office_Wifi 255.255.255.0 192.168.101.1 1&lt;BR /&gt;timeout xlate 3:00:00&lt;BR /&gt;timeout pat-xlate 0:00:30&lt;BR /&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 sctp 0:02:00 icmp 0:00:02&lt;BR /&gt;timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00&lt;BR /&gt;timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00&lt;BR /&gt;timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute&lt;BR /&gt;timeout tcp-proxy-reassembly 0:01:00&lt;BR /&gt;timeout floating-conn 0:00:00&lt;BR /&gt;user-identity default-domain LOCAL&lt;BR /&gt;aaa authentication ssh console LOCAL &lt;BR /&gt;aaa authentication http console LOCAL &lt;BR /&gt;http server enable&lt;BR /&gt;http Office_LAN 255.255.255.0 inside&lt;BR /&gt;http 0.0.0.0 0.0.0.0 outside&lt;BR /&gt;http 10.1.1.0 255.255.255.0 inside&lt;BR /&gt;no snmp-server location&lt;BR /&gt;no snmp-server contact&lt;BR /&gt;service sw-reset-button&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-3DES-MD5 esp-3des esp-md5-hmac &lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-128-SHA esp-aes esp-sha-hmac &lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-128-MD5 esp-aes esp-md5-hmac &lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-192-SHA esp-aes-192 esp-sha-hmac &lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-192-MD5 esp-aes-192 esp-md5-hmac &lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-256-SHA esp-aes-256 esp-sha-hmac &lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-256-MD5 esp-aes-256 esp-md5-hmac &lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-128-SHA-TRANS esp-aes esp-sha-hmac &lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-128-SHA-TRANS mode transport&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-128-MD5-TRANS esp-aes esp-md5-hmac &lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-128-MD5-TRANS mode transport&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-192-SHA-TRANS esp-aes-192 esp-sha-hmac &lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-192-SHA-TRANS mode transport&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-192-MD5-TRANS esp-aes-192 esp-md5-hmac &lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-192-MD5-TRANS mode transport&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-256-SHA-TRANS esp-aes-256 esp-sha-hmac &lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-256-SHA-TRANS mode transport&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-256-MD5-TRANS esp-aes-256 esp-md5-hmac &lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-256-MD5-TRANS mode transport&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-3DES-SHA esp-3des esp-sha-hmac &lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-3DES-SHA-TRANS esp-3des esp-sha-hmac &lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-3DES-SHA-TRANS mode transport&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-3DES-MD5-TRANS esp-3des esp-md5-hmac &lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-3DES-MD5-TRANS mode transport&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-DES-SHA esp-des esp-sha-hmac &lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-DES-MD5 esp-des esp-md5-hmac &lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-DES-SHA-TRANS esp-des esp-sha-hmac &lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-DES-SHA-TRANS mode transport&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-DES-MD5-TRANS esp-des esp-md5-hmac &lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-DES-MD5-TRANS mode transport&lt;BR /&gt;crypto ipsec ikev2 ipsec-proposal DES&lt;BR /&gt;&amp;nbsp;protocol esp encryption des&lt;BR /&gt;&amp;nbsp;protocol esp integrity sha-1 md5&lt;BR /&gt;crypto ipsec ikev2 ipsec-proposal 3DES&lt;BR /&gt;&amp;nbsp;protocol esp encryption 3des&lt;BR /&gt;&amp;nbsp;protocol esp integrity sha-1 md5&lt;BR /&gt;crypto ipsec ikev2 ipsec-proposal AES&lt;BR /&gt;&amp;nbsp;protocol esp encryption aes&lt;BR /&gt;&amp;nbsp;protocol esp integrity sha-1 md5&lt;BR /&gt;crypto ipsec ikev2 ipsec-proposal AES192&lt;BR /&gt;&amp;nbsp;protocol esp encryption aes-192&lt;BR /&gt;&amp;nbsp;protocol esp integrity sha-1 md5&lt;BR /&gt;crypto ipsec ikev2 ipsec-proposal AES256&lt;BR /&gt;&amp;nbsp;protocol esp encryption aes-256&lt;BR /&gt;&amp;nbsp;protocol esp integrity sha-1 md5&lt;BR /&gt;crypto ipsec security-association pmtu-aging infinite&lt;BR /&gt;crypto map outside_map 1 match address outside_cryptomap&lt;BR /&gt;crypto map outside_map 1 set peer 175.140.233.162 210.20.180.26 &lt;BR /&gt;crypto map outside_map 1 set ikev1 transform-set ESP-3DES-MD5&lt;BR /&gt;crypto map outside_map 1 set ikev2 ipsec-proposal AES256 AES192 AES 3DES DES&lt;BR /&gt;crypto map outside_map interface outside&lt;BR /&gt;crypto ca trustpoint ASDM_Launcher_Access_TrustPoint_0&lt;BR /&gt;&amp;nbsp;enrollment self&lt;BR /&gt;&amp;nbsp;fqdn none&lt;BR /&gt;&amp;nbsp;subject-name CN=192.168.101.2,CN=ccbcherasfw&lt;BR /&gt;&amp;nbsp;keypair ASDM_LAUNCHER&lt;BR /&gt;&amp;nbsp;crl configure&lt;BR /&gt;crypto ca trustpoint ASDM_Launcher_Access_TrustPoint_1&lt;BR /&gt;&amp;nbsp;enrollment self&lt;BR /&gt;&amp;nbsp;fqdn none&lt;BR /&gt;&amp;nbsp;subject-name CN=192.168.101.2,CN=ccbcherasfw&lt;BR /&gt;&amp;nbsp;keypair ASDM_LAUNCHER&lt;BR /&gt;&amp;nbsp;crl configure&lt;BR /&gt;crypto ca trustpoint ASDM_Launcher_Access_TrustPoint_2&lt;BR /&gt;&amp;nbsp;enrollment self&lt;BR /&gt;&amp;nbsp;fqdn none&lt;BR /&gt;&amp;nbsp;subject-name CN=192.168.101.2,CN=ccbcherasfw&lt;BR /&gt;&amp;nbsp;keypair ASDM_LAUNCHER&lt;BR /&gt;&amp;nbsp;crl configure&lt;BR /&gt;crypto ca trustpool policy&lt;BR /&gt;crypto ca certificate chain ASDM_Launcher_Access_TrustPoint_0&lt;BR /&gt;&amp;nbsp;certificate 0e69bd57&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 308202d8 308201c0 a0030201 0202040e 69bd5730 0d06092a 864886f7 0d010105 &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0500302e 31143012 06035504 03130b63 63626368 65726173 66773116 30140603 &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 55040313 0d313932 2e313638 2e313031 2e32301e 170d3136 30383235 30333036 &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 35395a17 0d323630 38323330 33303635 395a302e 31143012 06035504 03130b63 &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 63626368 65726173 66773116 30140603 55040313 0d313932 2e313638 2e313031 &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2e323082 0122300d 06092a86 4886f70d 01010105 00038201 0f003082 010a0282 &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 01010097 6a3ba16e 512af40c f7b38862 fc9ffa01 26d5eacd e2357e73 26fe31e0 &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 997a3efa 75cbc816 431cb475 3b04b72b d086b154 d4d61c79 5cb5d870 dd6834cd &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 5f315471 43a47f05 f8f89fb8 27e50b90 ef86769a 1cea217c 98ade46f 98b817af &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 4281fc5e c9a2ba31 a67a28b3 f3d19220 fa7132cf 4c01d5f3 dda2d856 a2f2c8b6 &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 9d7dea22 5c4fe371 2f5b473b 2a8809af 952ea8e9 a0d81fe7 03515ef7 a5d4ae54 &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2545a7e2 330c45fb eb6c4752 9b4b6733 20290a39 c9ea5c6f a44a5d7b 55c4a067 &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 8bdfae7b 318e7672 1d788f73 910b8b1d 3523f633 e0b3642f ee5e652a 09400413 &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 00b62c79 a4dbd70d bc7a1020 930b14bb 954f69a3 d3337772 43ad9d56 d41bf3f3 &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; fc2fc102 03010001 300d0609 2a864886 f70d0101 05050003 82010100 53a07cda &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; db8fa823 bbd23c7f 5696a785 66156510 84befb60 f1e03b02 2dd702ca 9b829f1a &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 5c8e3cd9 6bf0109f 99637c7f 48e075fb a7658fc4 88b0d48f ebba6cb6 5d6dfcbc &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 4aca5697 43587ff5 6a1db1ed f5e84298 be5c52d7 83ab0319 f35be837 2c2aa1ca &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 70cd5303 582ad585 d1e6e106 d003c014 982bdf9f b0b4bd05 e7734584 75bafbc8 &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 31c1c36e 9aaa7dd7 88cb6da1 418ef816 47ca3f4f 75bbf823 8742669c d3e43068 &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; b2655c75 f4ec9fea 4e238b02 7108af54 dedd7b33 f06a0757 84c4d413 dc9e5f2f &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 66bf2c36 a8e7b082 adcb65f2 a038115a cd09eecd 2a87c577 a013fd9c 0f094e81 &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; a5521f72 9a18d683 62a5bdd5 a3d0864a aa8c6f80 6da96f41 2fd69164&lt;BR /&gt;&amp;nbsp; quit&lt;BR /&gt;crypto ca certificate chain ASDM_Launcher_Access_TrustPoint_1&lt;BR /&gt;&amp;nbsp;certificate 0f69bd57&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 308202d8 308201c0 a0030201 0202040f 69bd5730 0d06092a 864886f7 0d010105 &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0500302e 31143012 06035504 03130b63 63626368 65726173 66773116 30140603 &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 55040313 0d313932 2e313638 2e313031 2e32301e 170d3136 30383235 30343234 &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 33375a17 0d323630 38323330 34323433 375a302e 31143012 06035504 03130b63 &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 63626368 65726173 66773116 30140603 55040313 0d313932 2e313638 2e313031 &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2e323082 0122300d 06092a86 4886f70d 01010105 00038201 0f003082 010a0282 &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 01010097 6a3ba16e 512af40c f7b38862 fc9ffa01 26d5eacd e2357e73 26fe31e0 &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 997a3efa 75cbc816 431cb475 3b04b72b d086b154 d4d61c79 5cb5d870 dd6834cd &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 5f315471 43a47f05 f8f89fb8 27e50b90 ef86769a 1cea217c 98ade46f 98b817af &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 4281fc5e c9a2ba31 a67a28b3 f3d19220 fa7132cf 4c01d5f3 dda2d856 a2f2c8b6 &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 9d7dea22 5c4fe371 2f5b473b 2a8809af 952ea8e9 a0d81fe7 03515ef7 a5d4ae54 &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2545a7e2 330c45fb eb6c4752 9b4b6733 20290a39 c9ea5c6f a44a5d7b 55c4a067 &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 8bdfae7b 318e7672 1d788f73 910b8b1d 3523f633 e0b3642f ee5e652a 09400413 &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 00b62c79 a4dbd70d bc7a1020 930b14bb 954f69a3 d3337772 43ad9d56 d41bf3f3 &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; fc2fc102 03010001 300d0609 2a864886 f70d0101 05050003 82010100 4c55dd09 &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; f9f7a6eb 54ae5ae2 c28c7e11 93dec140 abc0c9a9 710b2ae3 d0e1ea9f eada312b &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 59618735 07188e0f 0cd64c02 acf22f99 cb768fd6 0fcb0215 4d1be479 668ddd59 &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 7a9bc35f d971b1a8 179fd353 fb4ef5e2 5e07c2b3 37eceb28 dac9fdcb 3190a81a &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 15c90c37 4127f4eb ee818636 949b0c46 968076bd 16aa79b9 fce97a6d bcbdf1da &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 6a71ddc0 8021ecdc b8f4359c 0d4a61bd a33515bc ecf9a489 b110a73f 0756bc4b &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; f8719ae7 2a540f79 6865cddf 45beee12 aeba78f5 7c836432 38e95dc2 5ce94e92 &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 37f1faca 7a0d34e5 bc119c21 e72b0fe7 a45e7dcc dd19afe3 2a33cce8 af11806b &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; fd6503df eb7e624c 5fbd599e e86b2715 8e5058fe 1e20d7de a912327b&lt;BR /&gt;&amp;nbsp; quit&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&lt;BR /&gt;crypto ca certificate chain ASDM_Launcher_Access_TrustPoint_2&lt;BR /&gt;&amp;nbsp;certificate 1069bd57&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 308202d8 308201c0 a0030201 02020410 69bd5730 0d06092a 864886f7 0d010105 &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0500302e 31143012 06035504 03130b63 63626368 65726173 66773116 30140603 &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 55040313 0d313932 2e313638 2e313031 2e32301e 170d3136 30383235 30343538 &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 30315a17 0d323630 38323330 34353830 315a302e 31143012 06035504 03130b63 &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 63626368 65726173 66773116 30140603 55040313 0d313932 2e313638 2e313031 &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2e323082 0122300d 06092a86 4886f70d 01010105 00038201 0f003082 010a0282 &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 01010097 6a3ba16e 512af40c f7b38862 fc9ffa01 26d5eacd e2357e73 26fe31e0 &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 997a3efa 75cbc816 431cb475 3b04b72b d086b154 d4d61c79 5cb5d870 dd6834cd &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 5f315471 43a47f05 f8f89fb8 27e50b90 ef86769a 1cea217c 98ade46f 98b817af &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 4281fc5e c9a2ba31 a67a28b3 f3d19220 fa7132cf 4c01d5f3 dda2d856 a2f2c8b6 &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 9d7dea22 5c4fe371 2f5b473b 2a8809af 952ea8e9 a0d81fe7 03515ef7 a5d4ae54 &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2545a7e2 330c45fb eb6c4752 9b4b6733 20290a39 c9ea5c6f a44a5d7b 55c4a067 &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 8bdfae7b 318e7672 1d788f73 910b8b1d 3523f633 e0b3642f ee5e652a 09400413 &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 00b62c79 a4dbd70d bc7a1020 930b14bb 954f69a3 d3337772 43ad9d56 d41bf3f3 &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; fc2fc102 03010001 300d0609 2a864886 f70d0101 05050003 82010100 93665a10 &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ad512846 01f32086 65ca8325 79bee6f6 54490e20 286efc0e 9b4104e6 38f7e430 &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 16906354 39efd45a 72ebad1f ddd611ef 100b1612 0b596afe c87bcc9a b9e44ecc &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 17e7783e b5d05836 4dbe3a7e 489b29ff 86322c0d 0c8c1254 6f750dba 7a224b3f &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2ca41e02 5d68c7b9 9a9f845a a781bdd7 a22ed9a4 3aa636e1 00c2c2dd 09595d12 &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 740923df 9127f8e8 8f36899a 2fbaa82c 92393fb0 ab9d99cf d6aa44cb d443793f &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 7b9d0700 10b2f116 8df3392a e4eabf92 7d3bd574 273ec214 f4622f70 28074a87 &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 91556f0a 50774ddd 2c1ffe28 5b46f1fb bd99ea0c 8c7ba7c9 7ff1b51d 052b677b &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; e434fe6b 2cb83ba0 71fd487c 0ed2ae36 e3c145e1 14cac8bb 64fba468&lt;BR /&gt;&amp;nbsp; quit&lt;BR /&gt;crypto ikev2 policy 1&lt;BR /&gt;&amp;nbsp;encryption aes-256&lt;BR /&gt;&amp;nbsp;integrity sha&lt;BR /&gt;&amp;nbsp;group 5 2&lt;BR /&gt;&amp;nbsp;prf sha&lt;BR /&gt;&amp;nbsp;lifetime seconds 86400&lt;BR /&gt;crypto ikev2 policy 10&lt;BR /&gt;&amp;nbsp;encryption aes-192&lt;BR /&gt;&amp;nbsp;integrity sha&lt;BR /&gt;&amp;nbsp;group 5 2&lt;BR /&gt;&amp;nbsp;prf sha&lt;BR /&gt;&amp;nbsp;lifetime seconds 86400&lt;BR /&gt;crypto ikev2 policy 20&lt;BR /&gt;&amp;nbsp;encryption aes&lt;BR /&gt;&amp;nbsp;integrity sha&lt;BR /&gt;&amp;nbsp;group 5 2&lt;BR /&gt;&amp;nbsp;prf sha&lt;BR /&gt;&amp;nbsp;lifetime seconds 86400&lt;BR /&gt;crypto ikev2 policy 30&lt;BR /&gt;&amp;nbsp;encryption 3des&lt;BR /&gt;&amp;nbsp;integrity sha&lt;BR /&gt;&amp;nbsp;group 5 2&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;BR /&gt;&amp;nbsp;prf sha&lt;BR /&gt;&amp;nbsp;lifetime seconds 86400&lt;BR /&gt;crypto ikev2 policy 40&lt;BR /&gt;&amp;nbsp;encryption des&lt;BR /&gt;&amp;nbsp;integrity sha&lt;BR /&gt;&amp;nbsp;group 5 2&lt;BR /&gt;&amp;nbsp;prf sha&lt;BR /&gt;&amp;nbsp;lifetime seconds 86400&lt;BR /&gt;crypto ikev2 enable outside&lt;BR /&gt;crypto ikev1 enable outside&lt;BR /&gt;crypto ikev1 policy 160&lt;BR /&gt;&amp;nbsp;authentication pre-share&lt;BR /&gt;&amp;nbsp;encryption 3des&lt;BR /&gt;&amp;nbsp;hash md5&lt;BR /&gt;&amp;nbsp;group 5&lt;BR /&gt;&amp;nbsp;lifetime 86400&lt;BR /&gt;telnet timeout 5&lt;BR /&gt;no ssh stricthostkeycheck&lt;BR /&gt;ssh 0.0.0.0 0.0.0.0 outside&lt;BR /&gt;ssh 0.0.0.0 0.0.0.0 inside&lt;BR /&gt;ssh timeout 60&lt;BR /&gt;ssh version 2&lt;BR /&gt;ssh key-exchange group dh-group1-sha1&lt;BR /&gt;console timeout 0&lt;BR /&gt;&lt;BR /&gt;management-access inside&lt;BR /&gt;!&lt;BR /&gt;ntp server 10.12.1.2 prefer&lt;BR /&gt;ssl trust-point ASDM_Launcher_Access_TrustPoint_2 inside&lt;BR /&gt;ssl trust-point ASDM_Launcher_Access_TrustPoint_2 inside vpnlb-ip&lt;BR /&gt;group-policy GroupPolicy_175.140.233.162 internal&lt;BR /&gt;group-policy GroupPolicy_175.140.233.162 attributes&lt;BR /&gt;&amp;nbsp;vpn-tunnel-protocol ikev1 ikev2 &lt;BR /&gt;dynamic-access-policy-record DfltAccessPolicy&lt;BR /&gt;username misadminservice password 6Pee0pMhMPokimu4 encrypted privilege 15&lt;BR /&gt;tunnel-group 175.140.233.162 type ipsec-l2l&lt;BR /&gt;tunnel-group 175.140.233.162 general-attributes&lt;BR /&gt;&amp;nbsp;default-group-policy GroupPolicy_175.140.233.162&lt;BR /&gt;tunnel-group 175.140.233.162 ipsec-attributes&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp;ikev1 pre-shared-key *****&lt;BR /&gt;&amp;nbsp;ikev2 remote-authentication pre-shared-key *****&lt;BR /&gt;&amp;nbsp;ikev2 local-authentication pre-shared-key *****&lt;BR /&gt;!&lt;BR /&gt;class-map inspection_default&lt;BR /&gt;&amp;nbsp;match default-inspection-traffic&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;policy-map type inspect dns preset_dns_map&lt;BR /&gt;&amp;nbsp;parameters&lt;BR /&gt;&amp;nbsp; message-length maximum client auto&lt;BR /&gt;&amp;nbsp; message-length maximum 512&lt;BR /&gt;policy-map global_policy&lt;BR /&gt;&amp;nbsp;class inspection_default&lt;BR /&gt;&amp;nbsp; inspect ftp &lt;BR /&gt;&amp;nbsp; inspect h323 h225 &lt;BR /&gt;&amp;nbsp; inspect h323 ras &lt;BR /&gt;&amp;nbsp; inspect ip-options &lt;BR /&gt;&amp;nbsp; inspect netbios &lt;BR /&gt;&amp;nbsp; inspect rsh &lt;BR /&gt;&amp;nbsp; inspect rtsp &lt;BR /&gt;&amp;nbsp; inspect skinny &amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect esmtp &lt;BR /&gt;&amp;nbsp; inspect sqlnet &lt;BR /&gt;&amp;nbsp; inspect sunrpc &lt;BR /&gt;&amp;nbsp; inspect tftp &lt;BR /&gt;&amp;nbsp; inspect sip &amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect xdmcp &lt;BR /&gt;&amp;nbsp; inspect dns preset_dns_map &lt;BR /&gt;&amp;nbsp; inspect icmp &lt;BR /&gt;policy-map type inspect dns migrated_dns_map_1&lt;BR /&gt;&amp;nbsp;parameters&lt;BR /&gt;&amp;nbsp; message-length maximum client auto&lt;BR /&gt;&amp;nbsp; message-length maximum 512&lt;BR /&gt;!&lt;BR /&gt;service-policy global_policy global&lt;BR /&gt;prompt hostname context &lt;BR /&gt;no call-home reporting anonymous&lt;BR /&gt;call-home&lt;BR /&gt;&amp;nbsp;profile CiscoTAC-1&lt;BR /&gt;&amp;nbsp; no active&lt;BR /&gt;&amp;nbsp; destination address http &lt;A href="https://tools.cisco.com/its/service/oddce/services/DDCEService" target="_blank"&gt;https://tools.cisco.com/its/service/oddce/services/DDCEService&lt;/A&gt;&lt;BR /&gt;&amp;nbsp; destination address email callhome@cisco.com&lt;BR /&gt;&amp;nbsp; destination transport-method http&lt;BR /&gt;&amp;nbsp; subscribe-to-alert-group diagnostic&lt;BR /&gt;&amp;nbsp; subscribe-to-alert-group environment&lt;BR /&gt;&amp;nbsp; subscribe-to-alert-group inventory periodic monthly&lt;BR /&gt;&amp;nbsp; subscribe-to-alert-group configuration periodic monthly&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;BR /&gt;&amp;nbsp; subscribe-to-alert-group telemetry periodic daily&lt;BR /&gt;Cryptochecksum:6f54aa67bb50471b8738a96120735e26&lt;BR /&gt;: end&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thank you.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Kevin&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 08:12:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-ping-inside-interface-via-site-to-site-vpn/m-p/2972307#M150385</guid>
      <dc:creator>kevinshkong11</dc:creator>
      <dc:date>2019-03-12T08:12:15Z</dc:date>
    </item>
    <item>
      <title>Hi Kevin,</title>
      <link>https://community.cisco.com/t5/network-security/cannot-ping-inside-interface-via-site-to-site-vpn/m-p/2972308#M150386</link>
      <description>&lt;P&gt;Hi Kevin,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Please add the route-lookup command at the end of your NAT statement as per below:&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="color: #0000ff;"&gt;&lt;STRONG&gt;&lt;EM&gt;nat (inside,outside) source static Branch_Segment Branch_Segment destination static HQ_Segment HQ_Segment route-lookup&lt;/EM&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;http://packetpushers.net/understanding-when-a-cisco-asa-nat-rule-can-override-the-asa-routing-table/&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;HTH.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Please rate helpful post.&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Terence&lt;/P&gt;</description>
      <pubDate>Tue, 30 Aug 2016 10:10:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-ping-inside-interface-via-site-to-site-vpn/m-p/2972308#M150386</guid>
      <dc:creator>Terence Payet</dc:creator>
      <dc:date>2016-08-30T10:10:59Z</dc:date>
    </item>
    <item>
      <title>Hi Terrence,</title>
      <link>https://community.cisco.com/t5/network-security/cannot-ping-inside-interface-via-site-to-site-vpn/m-p/2972309#M150387</link>
      <description>&lt;P&gt;Hi Terrence,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Already added previously.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;nat (inside,outside) source static Branch_Segment Branch_Segment destination static HQ_Segment HQ_Segment no-proxy-arp route-lookup&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Tue, 30 Aug 2016 10:31:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-ping-inside-interface-via-site-to-site-vpn/m-p/2972309#M150387</guid>
      <dc:creator>kevinshkong11</dc:creator>
      <dc:date>2016-08-30T10:31:36Z</dc:date>
    </item>
  </channel>
</rss>

