<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Unable to establish VPN tunnel (ASA &amp;lt;&amp;gt; CSR1000) in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/unable-to-establish-vpn-tunnel-asa-lt-gt-csr1000/m-p/4003181#M30697</link>
    <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="topology1.png" style="width: 970px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/63932iF789FEF83CE93D1E/image-size/large?v=v2&amp;amp;px=999" role="button" title="topology1.png" alt="topology1.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;On EVE-NG, I am trying to establish an IKEv1 Site to Site VPN tunnel between CSR1 and ASA.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;CSR version : CSR1000V Software (X86_64_LINUX_IOSD-UNIVERSALK9-M), Version 15.6(1)S3,&lt;/P&gt;&lt;P&gt;ASA Version: ASA5520 Version 9.1(5)16&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have attached the configs and debug message, ASA always complains 'no matching SA found', this is not correct AFAIK.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If I configure exact same config using two CSRs, everything is working.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What am I doing wrong?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;EDIT: Even if I remove everything and just connect ASA&amp;nbsp; to CSR1, the exact same error occurs.&lt;/P&gt;</description>
    <pubDate>Tue, 24 Dec 2019 15:45:19 GMT</pubDate>
    <dc:creator>InTheJuniverse</dc:creator>
    <dc:date>2019-12-24T15:45:19Z</dc:date>
    <item>
      <title>Unable to establish VPN tunnel (ASA &lt;&gt; CSR1000)</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-establish-vpn-tunnel-asa-lt-gt-csr1000/m-p/4003181#M30697</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="topology1.png" style="width: 970px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/63932iF789FEF83CE93D1E/image-size/large?v=v2&amp;amp;px=999" role="button" title="topology1.png" alt="topology1.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;On EVE-NG, I am trying to establish an IKEv1 Site to Site VPN tunnel between CSR1 and ASA.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;CSR version : CSR1000V Software (X86_64_LINUX_IOSD-UNIVERSALK9-M), Version 15.6(1)S3,&lt;/P&gt;&lt;P&gt;ASA Version: ASA5520 Version 9.1(5)16&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have attached the configs and debug message, ASA always complains 'no matching SA found', this is not correct AFAIK.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If I configure exact same config using two CSRs, everything is working.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What am I doing wrong?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;EDIT: Even if I remove everything and just connect ASA&amp;nbsp; to CSR1, the exact same error occurs.&lt;/P&gt;</description>
      <pubDate>Tue, 24 Dec 2019 15:45:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-establish-vpn-tunnel-asa-lt-gt-csr1000/m-p/4003181#M30697</guid>
      <dc:creator>InTheJuniverse</dc:creator>
      <dc:date>2019-12-24T15:45:19Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to establish VPN tunnel (ASA &lt;&gt; CSR1000)</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-establish-vpn-tunnel-asa-lt-gt-csr1000/m-p/4003196#M30709</link>
      <description>Hi,&lt;BR /&gt;I don't see anything obviously wrong in the configuration. &lt;BR /&gt;Can you confirm are you just observing errors in the debug logs or is the IKEv1 SA and IPSec SAs not being established?&lt;BR /&gt;The timestamps are not the same, were the debugs logs generated on the ASA and CSR at the sametime?</description>
      <pubDate>Tue, 24 Dec 2019 16:01:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-establish-vpn-tunnel-asa-lt-gt-csr1000/m-p/4003196#M30709</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2019-12-24T16:01:34Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to establish VPN tunnel (ASA &lt;&gt; CSR1000)</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-establish-vpn-tunnel-asa-lt-gt-csr1000/m-p/4003216#M30714</link>
      <description>&lt;P&gt;Thank you for your response.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Phase 1 establishes just fine, Phase 2 moans about "Received encrypted packet with no matching SA, dropping" error if i debug.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I could have taken logs differently, but they are similar all the time.&lt;/P&gt;</description>
      <pubDate>Tue, 24 Dec 2019 16:51:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-establish-vpn-tunnel-asa-lt-gt-csr1000/m-p/4003216#M30714</guid>
      <dc:creator>Firepowered</dc:creator>
      <dc:date>2019-12-24T16:51:35Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to establish VPN tunnel (ASA &lt;&gt; CSR1000)</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-establish-vpn-tunnel-asa-lt-gt-csr1000/m-p/4003227#M30719</link>
      <description>Try using a different transform set, use aes and sha and try again. Provide a full ipsec sa debug - "debug crypto ipsec sa" and upload for review.</description>
      <pubDate>Tue, 24 Dec 2019 17:30:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-establish-vpn-tunnel-asa-lt-gt-csr1000/m-p/4003227#M30719</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2019-12-24T17:30:04Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to establish VPN tunnel (ASA &lt;&gt; CSR1000)</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-establish-vpn-tunnel-asa-lt-gt-csr1000/m-p/4003783#M30722</link>
      <description>&lt;P&gt;I lab this up only difference did is i used a this nat uses&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;nat (inside,outside) source static NETWORK_OBJ_10.10.9.0_24 NETWORK_OBJ_10.10.9.0_24 destination static NETWORK_OBJ_10.11.11.0_24 NETWORK_OBJ_10.11.11.0_24 no-proxy-arp route-lookup&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;change into this&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;nat (inside,outside) source static LAN09 LAN09 destin static LAN11 LAN11 no-proxy-arp route-lookup&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 26 Dec 2019 21:35:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-establish-vpn-tunnel-asa-lt-gt-csr1000/m-p/4003783#M30722</guid>
      <dc:creator>Sheraz.Salim</dc:creator>
      <dc:date>2019-12-26T21:35:19Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to establish VPN tunnel (ASA &lt;&gt; CSR1000)</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-establish-vpn-tunnel-asa-lt-gt-csr1000/m-p/4004039#M30726</link>
      <description>&lt;P&gt;Thank you.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I did and I have exact same output.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I removed that asa and used another one (ASAv) and everything is working. So, I am assuming this is some sort of but in EVE or the image.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Alsa, when I do a destination NAT (identity) from CLI, it does not show on ASDM, I have to explicitly click 'NAT Exempt' from connection profile, and it ends up creating two NATs, something that Shiraz also suggested,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So I am definitely doubting the ASA image.&lt;/P&gt;</description>
      <pubDate>Fri, 27 Dec 2019 11:08:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-establish-vpn-tunnel-asa-lt-gt-csr1000/m-p/4004039#M30726</guid>
      <dc:creator>InTheJuniverse</dc:creator>
      <dc:date>2019-12-27T11:08:37Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to establish VPN tunnel (ASA &lt;&gt; CSR1000)</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-establish-vpn-tunnel-asa-lt-gt-csr1000/m-p/4004043#M30729</link>
      <description>&lt;P&gt;Thanks Shiraz&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Good catch. I noticed that even after creating Destination NAT (identity) from CLI, ASDM still does not show it, I have to explicitly click 'Nat Exempt' under connection profile.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;BTW, I changed NAT and it still did not work.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I used another ASA image and it worked, so I am doubting ASA / EVE here&lt;/P&gt;</description>
      <pubDate>Fri, 27 Dec 2019 11:10:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-establish-vpn-tunnel-asa-lt-gt-csr1000/m-p/4004043#M30729</guid>
      <dc:creator>InTheJuniverse</dc:creator>
      <dc:date>2019-12-27T11:10:08Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to establish VPN tunnel (ASA &lt;&gt; CSR1000)</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-establish-vpn-tunnel-asa-lt-gt-csr1000/m-p/4004078#M30734</link>
      <description>&lt;P&gt;Hi mate.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I just double check my ASA version is 9.12. just realize your was on 9.1. I have seen this site-to-site vpn issue with identity nat in production network too. Glad it work out for you. happy labbing &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 27 Dec 2019 12:28:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-establish-vpn-tunnel-asa-lt-gt-csr1000/m-p/4004078#M30734</guid>
      <dc:creator>Sheraz.Salim</dc:creator>
      <dc:date>2019-12-27T12:28:27Z</dc:date>
    </item>
  </channel>
</rss>

