<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA Crypto maps and ASDM in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-crypto-maps-and-asdm/m-p/2321008#M345624</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; From the outside ASA, I ran packet tracer on the outside interface, icmp, source 10.255.255.1, dest 192.168.50.10.&amp;nbsp; I receive a packet drop, and the erros is (rpf-violated) Reverse-path verify failed.&amp;nbsp; I remove the line from the config, and now get dropped packet because of ACL, but it still doen't tell me which acl.&lt;/P&gt;&lt;P&gt;I also verified with production system and get same error.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 31 Jul 2013 17:15:18 GMT</pubDate>
    <dc:creator>Tracey Foster</dc:creator>
    <dc:date>2013-07-31T17:15:18Z</dc:date>
    <item>
      <title>ASA Crypto maps and ASDM</title>
      <link>https://community.cisco.com/t5/network-security/asa-crypto-maps-and-asdm/m-p/2321006#M345622</link>
      <description>&lt;P&gt;Hello all,&lt;/P&gt;&lt;P&gt;I have a number of problems.&lt;/P&gt;&lt;P&gt;First, attached are 2 different config files.&amp;nbsp; &lt;/P&gt;&lt;P&gt;First one is from a running system that works, FP1-NNTL, however, the crytpo map for the dynamic are not working properly and if I go to add another site-2-site tunnel group that uses "outside_map" crypto map, it won't work.&amp;nbsp; It won't work because of the crypto map that is assigned to the outside interface is not the "outside_map" it is "Mobile"&amp;nbsp; Mobile is my attempt at getting cellphone with native VPN to work.&amp;nbsp; Additionally, "outside_map" to interface outside verses "Mobile" also drop my ASDM nad telnet connectivity--see below.&lt;/P&gt;&lt;P&gt;This brings me to the second issue, can't seem to get the dynamic crypto map to work propery under the "outside_map".&amp;nbsp; I know that I have to have the dynamic mode set to "transport" for the cell phone VPN's to work at all.&amp;nbsp; Any pointers on how to fix this would be great.&lt;/P&gt;&lt;P&gt;The second attached file is from a tabletop box.&amp;nbsp; Same configuration as the NNTL, but can't seem to get ASDM or telnet to work consistantly.&amp;nbsp; I also know that is is because of the crytpo map to outside interface as when I change it from "outside_map" to "Mobile" it works, but when I switch it, it does not work.&lt;/P&gt;&lt;P&gt;I am fairly new at this ASA stuff and having to deal with a hug configuration that I didn't put together is over-whelming.&lt;/P&gt;&lt;P&gt;Any assistance from anyone is greatly appreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Both boxes are on IOS 9.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Tracey &lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 02:18:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-crypto-maps-and-asdm/m-p/2321006#M345622</guid>
      <dc:creator>Tracey Foster</dc:creator>
      <dc:date>2019-03-12T02:18:35Z</dc:date>
    </item>
    <item>
      <title>ASA Crypto maps and ASDM</title>
      <link>https://community.cisco.com/t5/network-security/asa-crypto-maps-and-asdm/m-p/2321007#M345623</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Additionally, from the CLI I turned on capture for all acl-drop.&amp;nbsp; I have a ping going from one side of the site-2-site VPN to the other side and it is dropping.&amp;nbsp; The capture tells me it is dropping because of an ACL.&amp;nbsp; But doesn't tell me which ACL.&amp;nbsp; &lt;/P&gt;&lt;P&gt;I am using the tunnel-group 65.246.21.12, which uses the group-policy W-NOC for this interface.&amp;nbsp; the policy does not have a vpn-filter assinged to it.&amp;nbsp; So now I am digging to try and figure out which ACL is dropping this connectivity.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 30 Jul 2013 19:38:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-crypto-maps-and-asdm/m-p/2321007#M345623</guid>
      <dc:creator>Tracey Foster</dc:creator>
      <dc:date>2013-07-30T19:38:42Z</dc:date>
    </item>
    <item>
      <title>ASA Crypto maps and ASDM</title>
      <link>https://community.cisco.com/t5/network-security/asa-crypto-maps-and-asdm/m-p/2321008#M345624</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; From the outside ASA, I ran packet tracer on the outside interface, icmp, source 10.255.255.1, dest 192.168.50.10.&amp;nbsp; I receive a packet drop, and the erros is (rpf-violated) Reverse-path verify failed.&amp;nbsp; I remove the line from the config, and now get dropped packet because of ACL, but it still doen't tell me which acl.&lt;/P&gt;&lt;P&gt;I also verified with production system and get same error.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 31 Jul 2013 17:15:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-crypto-maps-and-asdm/m-p/2321008#M345624</guid>
      <dc:creator>Tracey Foster</dc:creator>
      <dc:date>2013-07-31T17:15:18Z</dc:date>
    </item>
    <item>
      <title>ASA Crypto maps and ASDM</title>
      <link>https://community.cisco.com/t5/network-security/asa-crypto-maps-and-asdm/m-p/2321009#M345625</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; I have found to problem.&amp;nbsp; Seems that the VPN filter for a different VPN was interferring with the VPN that I was focused on and the one that I was using to connect to the device.&lt;/P&gt;&lt;P&gt;In the end, object group R-NOC-Inside had a object network 192.168.50.0 with in it.&amp;nbsp; I removed it and sure enough I could connect.&amp;nbsp; &lt;/P&gt;&lt;P&gt;Still working on full testing, but I am pretty sure this is the fix.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 13 Aug 2013 11:45:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-crypto-maps-and-asdm/m-p/2321009#M345625</guid>
      <dc:creator>Tracey Foster</dc:creator>
      <dc:date>2013-08-13T11:45:04Z</dc:date>
    </item>
  </channel>
</rss>

