<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA 5505 ssl work ipsec does not in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-5505-ssl-work-ipsec-does-not/m-p/2144287#M359778</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Problem nearly fixed, I rebooted the firewall and I am now able to log in&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However traffic is only flowing one way lots of encrypted packets but 0 decrypted &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also my split tunnel does not seem to be working. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I will get the config into this post soon&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Roger&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 20 Mar 2013 23:00:12 GMT</pubDate>
    <dc:creator>roger perkin</dc:creator>
    <dc:date>2013-03-20T23:00:12Z</dc:date>
    <item>
      <title>ASA 5505 ssl work ipsec does not</title>
      <link>https://community.cisco.com/t5/network-security/asa-5505-ssl-work-ipsec-does-not/m-p/2144283#M359774</link>
      <description>&lt;P&gt;I am trying to configure an IPSEC vpn on an ASA5505&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I setup an SSL vpn and it works fine, I can browse to the https: address log in and connnect to servers&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However when I try to setup the ipsec client access vpn it will not connect and I am getting the errors below &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I used the wizard for the initial configuration &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Looks like the inital IKE is being blocked or dropped?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;%ASA-7-710005: UDP request discarded from my external IP/35781 to external:ASA-external/500&lt;/P&gt;&lt;P&gt;%ASA-7-710005: UDP request discarded from my external IP/35781 to external:ASA-external/137&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Roger&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 01:17:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5505-ssl-work-ipsec-does-not/m-p/2144283#M359774</guid>
      <dc:creator>roger perkin</dc:creator>
      <dc:date>2019-03-12T01:17:04Z</dc:date>
    </item>
    <item>
      <title>ASA 5505 ssl work ipsec does not</title>
      <link>https://community.cisco.com/t5/network-security/asa-5505-ssl-work-ipsec-does-not/m-p/2144284#M359775</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;do you have the&lt;/P&gt;&lt;P&gt;crypto isakamp enable&amp;nbsp; outside configured?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What version are you running?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 Mar 2013 19:38:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5505-ssl-work-ipsec-does-not/m-p/2144284#M359775</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2013-03-20T19:38:00Z</dc:date>
    </item>
    <item>
      <title>ASA 5505 ssl work ipsec does not</title>
      <link>https://community.cisco.com/t5/network-security/asa-5505-ssl-work-ipsec-does-not/m-p/2144285#M359776</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;crypto ikev2 enable external&lt;/P&gt;&lt;P&gt;crypto ikev1 enable external&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Running version 8.4(1)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The ssl works perfectly &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I then configured the IPSEC using the wizard and it wont' connect?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Scratching my head a bit&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Roger&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 Mar 2013 19:54:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5505-ssl-work-ipsec-does-not/m-p/2144285#M359776</guid>
      <dc:creator>roger perkin</dc:creator>
      <dc:date>2013-03-20T19:54:36Z</dc:date>
    </item>
    <item>
      <title>ASA 5505 ssl work ipsec does not</title>
      <link>https://community.cisco.com/t5/network-security/asa-5505-ssl-work-ipsec-does-not/m-p/2144286#M359777</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Roger,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you share the configuration so I can take a quick look at it&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 Mar 2013 20:29:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5505-ssl-work-ipsec-does-not/m-p/2144286#M359777</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2013-03-20T20:29:41Z</dc:date>
    </item>
    <item>
      <title>ASA 5505 ssl work ipsec does not</title>
      <link>https://community.cisco.com/t5/network-security/asa-5505-ssl-work-ipsec-does-not/m-p/2144287#M359778</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Problem nearly fixed, I rebooted the firewall and I am now able to log in&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However traffic is only flowing one way lots of encrypted packets but 0 decrypted &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also my split tunnel does not seem to be working. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I will get the config into this post soon&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Roger&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 Mar 2013 23:00:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5505-ssl-work-ipsec-does-not/m-p/2144287#M359778</guid>
      <dc:creator>roger perkin</dc:creator>
      <dc:date>2013-03-20T23:00:12Z</dc:date>
    </item>
    <item>
      <title>ASA 5505 ssl work ipsec does not</title>
      <link>https://community.cisco.com/t5/network-security/asa-5505-ssl-work-ipsec-does-not/m-p/2144288#M359779</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then we will need to check the confi&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 Mar 2013 23:11:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5505-ssl-work-ipsec-does-not/m-p/2144288#M359779</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2013-03-20T23:11:02Z</dc:date>
    </item>
    <item>
      <title>ASA 5505 ssl work ipsec does not</title>
      <link>https://community.cisco.com/t5/network-security/asa-5505-ssl-work-ipsec-does-not/m-p/2144289#M359780</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ok, I am getting this error when pinging an internal host from the connected vpn client &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;VPN client is on 172.16.24.2 internal host is on 192.168.100.37&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;%ASA-5-305013: Asymmetric NAT rules matched for forward and reverse flows; Connection for icmp src external:172.16.24.2 dst internal:192.168.100.37 (type 8, code 0) denied due to NAT reverse path failure&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object network obj-192.168.50.10 &lt;/P&gt;&lt;P&gt; host 192.168.50.10&lt;/P&gt;&lt;P&gt;object network obj-192.168.50.20 &lt;/P&gt;&lt;P&gt; host 192.168.50.20&lt;/P&gt;&lt;P&gt;object network obj-192.168.50.21 &lt;/P&gt;&lt;P&gt; host 192.168.50.21&lt;/P&gt;&lt;P&gt;object network obj_any &lt;/P&gt;&lt;P&gt; subnet 0.0.0.0 0.0.0.0&lt;/P&gt;&lt;P&gt;object network obj_any-01 &lt;/P&gt;&lt;P&gt; subnet 0.0.0.0 0.0.0.0&lt;/P&gt;&lt;P&gt;object network obj-0.0.0.0 &lt;/P&gt;&lt;P&gt; host 0.0.0.0&lt;/P&gt;&lt;P&gt;object network NETWORK_OBJ_10.10.1.0_28 &lt;/P&gt;&lt;P&gt; subnet 10.10.1.0 255.255.255.240&lt;/P&gt;&lt;P&gt;object network vpn_clients &lt;/P&gt;&lt;P&gt; subnet 192.168.199.0 255.255.255.0&lt;/P&gt;&lt;P&gt;object network 192.168.100.0 &lt;/P&gt;&lt;P&gt; subnet 192.168.100.0 255.255.255.0&lt;/P&gt;&lt;P&gt;object network NETWORK_OBJ_192.168.199.0_24 &lt;/P&gt;&lt;P&gt; subnet 192.168.199.0 255.255.255.0&lt;/P&gt;&lt;P&gt;object network VPN_172 &lt;/P&gt;&lt;P&gt; subnet 172.16.24.0 255.255.255.0&lt;/P&gt;&lt;P&gt;object-group service RDP tcp&lt;/P&gt;&lt;P&gt; port-object eq 3389&lt;/P&gt;&lt;P&gt;object-group service SQL tcp&lt;/P&gt;&lt;P&gt; port-object eq 1433&lt;/P&gt;&lt;P&gt;object-group service RDP-SQL tcp&lt;/P&gt;&lt;P&gt; group-object RDP&lt;/P&gt;&lt;P&gt; group-object SQL&lt;/P&gt;&lt;P&gt;access-list outside_in extended permit udp any any log &lt;/P&gt;&lt;P&gt;access-list network_10_access_in extended permit ip interface internal any &lt;/P&gt;&lt;P&gt;access-list external_access_in extended permit ip object NETWORK_OBJ_192.168.199.0_24 interface internal &lt;/P&gt;&lt;P&gt;access-list external_access_in extended permit tcp any any inactive &lt;/P&gt;&lt;P&gt;access-list from_outside extended permit icmp any any log &lt;/P&gt;&lt;P&gt;access-list from_outside extended permit icmp any any echo &lt;/P&gt;&lt;P&gt;access-list split_VPN_Split standard permit 192.168.100.0 255.255.255.0 &lt;/P&gt;&lt;P&gt;access-list external_access_in_1 extended permit ip object NETWORK_OBJ_192.168.199.0_24 192.168.100.0 255.255.255.0 &lt;/P&gt;&lt;P&gt;access-list external_access_in_1 extended permit ip object VPN_172 192.168.100.0 255.255.255.0 &lt;/P&gt;&lt;P&gt;pager lines 24&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (internal,external) source static any any destination static NETWORK_OBJ_10.10.1.0_28 NETWORK_OBJ_10.10.1.0_28&lt;/P&gt;&lt;P&gt;nat (internal,external) source static 192.168.100.0 192.168.100.0 destination static NETWORK_OBJ_192.168.199.0_24 NETWORK_OBJ_192.168.199.0_24&lt;/P&gt;&lt;P&gt;nat (internal,external) source static any any destination static NETWORK_OBJ_192.168.199.0_24 NETWORK_OBJ_192.168.199.0_24&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object network obj-192.168.50.10&lt;/P&gt;&lt;P&gt; nat (internal,external) static 192.168.0.81&lt;/P&gt;&lt;P&gt;object network obj-192.168.50.20&lt;/P&gt;&lt;P&gt; nat (internal,external) static 192.168.0.230&lt;/P&gt;&lt;P&gt;object network obj-192.168.50.21&lt;/P&gt;&lt;P&gt; nat (internal,external) static 192.168.0.231&lt;/P&gt;&lt;P&gt;object network obj_any&lt;/P&gt;&lt;P&gt; nat (internal,external) dynamic interface&lt;/P&gt;&lt;P&gt;object network obj_any-01&lt;/P&gt;&lt;P&gt; nat (internal,external) dynamic obj-0.0.0.0&lt;/P&gt;&lt;P&gt;access-group network_10_access_in in interface internal&lt;/P&gt;&lt;P&gt;access-group external_access_in_1 in interface external&lt;/P&gt;&lt;P&gt;route external 0.0.0.0 0.0.0.0 4.5.6.7.1 1&lt;/P&gt;&lt;P&gt;route internal 10.10.10.0 255.255.255.255 192.168.100.1 1&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 Mar 2013 00:00:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5505-ssl-work-ipsec-does-not/m-p/2144289#M359780</guid>
      <dc:creator>roger perkin</dc:creator>
      <dc:date>2013-03-21T00:00:13Z</dc:date>
    </item>
    <item>
      <title>ASA 5505 ssl work ipsec does not</title>
      <link>https://community.cisco.com/t5/network-security/asa-5505-ssl-work-ipsec-does-not/m-p/2144290#M359781</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Try&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (inside,outside) 1 source static &lt;SPAN style="font-size: 10pt;"&gt;192.168.100.0&amp;nbsp; &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt; 192.168.100.0 destination static&amp;nbsp; &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;VPN_172 &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;VPN_172&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 Mar 2013 05:55:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5505-ssl-work-ipsec-does-not/m-p/2144290#M359781</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2013-03-21T05:55:00Z</dc:date>
    </item>
    <item>
      <title>ASA 5505 ssl work ipsec does not</title>
      <link>https://community.cisco.com/t5/network-security/asa-5505-ssl-work-ipsec-does-not/m-p/2144291#M359782</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for that, we are now one step closer! &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now getting this error &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;%ASA-4-313004: Denied ICMP type=0, from laddr 172.16.24.2 on interface external to 192.168.100.37: no matching session&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 Mar 2013 08:30:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5505-ssl-work-ipsec-does-not/m-p/2144291#M359782</guid>
      <dc:creator>roger perkin</dc:creator>
      <dc:date>2013-03-21T08:30:18Z</dc:date>
    </item>
    <item>
      <title>ASA 5505 ssl work ipsec does not</title>
      <link>https://community.cisco.com/t5/network-security/asa-5505-ssl-work-ipsec-does-not/m-p/2144292#M359783</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for your replies, I have marked the nat as the correct answer, after much head stratching, I have now realised the porblem. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is another firewall added to the network. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The default gateway of the client I am pinging is another firewall so the ping is going in and then going&amp;nbsp; back to the main firewall. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My issue lies on the internal network.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Roger&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 Mar 2013 08:40:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5505-ssl-work-ipsec-does-not/m-p/2144292#M359783</guid>
      <dc:creator>roger perkin</dc:creator>
      <dc:date>2013-03-21T08:40:57Z</dc:date>
    </item>
    <item>
      <title>ASA 5505 ssl work ipsec does not</title>
      <link>https://community.cisco.com/t5/network-security/asa-5505-ssl-work-ipsec-does-not/m-p/2144293#M359784</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Roger,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Glad to know that I could help,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have a great day &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 Mar 2013 15:08:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5505-ssl-work-ipsec-does-not/m-p/2144293#M359784</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2013-03-21T15:08:28Z</dc:date>
    </item>
  </channel>
</rss>

