<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Site to site VPN not working for DMZ in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/site-to-site-vpn-not-working-for-dmz/m-p/2051207#M398903</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;im setting up an ASA 5510 and i have set up a VPN tunnel to our hosting partner. The tunnel is set up exactly as it was on our old firewall and the tunnel works when using the inside network. However when using DMZ1 and DMZ2 networks the tunnel does not work. As far as i see it everything is set up correctly.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Internal:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.42.10.0 255.255.255.0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;DMZ1:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.42.1.0 255.255.255.0&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;DMZ2:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.42.2.0 255.255.255.0&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Source of the tunnel is 10.42.0.0 255.255.0.0&lt;/P&gt;&lt;P&gt;As far as i know this should cover all the networks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any ideas why the tunnel is working fine with Internal but not the other networks?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;/Hilmar&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 23:58:11 GMT</pubDate>
    <dc:creator>IT Asitis</dc:creator>
    <dc:date>2019-03-11T23:58:11Z</dc:date>
    <item>
      <title>Site to site VPN not working for DMZ</title>
      <link>https://community.cisco.com/t5/network-security/site-to-site-vpn-not-working-for-dmz/m-p/2051207#M398903</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;im setting up an ASA 5510 and i have set up a VPN tunnel to our hosting partner. The tunnel is set up exactly as it was on our old firewall and the tunnel works when using the inside network. However when using DMZ1 and DMZ2 networks the tunnel does not work. As far as i see it everything is set up correctly.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Internal:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.42.10.0 255.255.255.0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;DMZ1:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.42.1.0 255.255.255.0&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;DMZ2:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.42.2.0 255.255.255.0&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Source of the tunnel is 10.42.0.0 255.255.0.0&lt;/P&gt;&lt;P&gt;As far as i know this should cover all the networks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any ideas why the tunnel is working fine with Internal but not the other networks?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;/Hilmar&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 23:58:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/site-to-site-vpn-not-working-for-dmz/m-p/2051207#M398903</guid>
      <dc:creator>IT Asitis</dc:creator>
      <dc:date>2019-03-11T23:58:11Z</dc:date>
    </item>
    <item>
      <title>Site to site VPN not working for DMZ</title>
      <link>https://community.cisco.com/t5/network-security/site-to-site-vpn-not-working-for-dmz/m-p/2051208#M398904</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;can you pls post your config so we can look through the configuration.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Perhaps the NAT exemption has not been configured on DMZ1 and DMZ2?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 24 Sep 2012 12:43:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/site-to-site-vpn-not-working-for-dmz/m-p/2051208#M398904</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2012-09-24T12:43:25Z</dc:date>
    </item>
    <item>
      <title>Site to site VPN not working for DMZ</title>
      <link>https://community.cisco.com/t5/network-security/site-to-site-vpn-not-working-for-dmz/m-p/2051209#M398905</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; It is now attached&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;/H&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 24 Sep 2012 13:23:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/site-to-site-vpn-not-working-for-dmz/m-p/2051209#M398905</guid>
      <dc:creator>IT Asitis</dc:creator>
      <dc:date>2012-09-24T13:23:30Z</dc:date>
    </item>
    <item>
      <title>Site to site VPN not working for DMZ</title>
      <link>https://community.cisco.com/t5/network-security/site-to-site-vpn-not-working-for-dmz/m-p/2051210#M398906</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Which site-to-site vpn is affected?&lt;/P&gt;&lt;P&gt;The first one on the list only include 10.42.10.0/24 subnet:&lt;/P&gt;&lt;P&gt;access-list WAN1_cryptomap extended permit ip 10.42.10.0 255.255.255.0 object site-Asitis&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, pls check if your access-list applied to both DMZ1 and 2 has included access to the remote end.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 24 Sep 2012 13:32:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/site-to-site-vpn-not-working-for-dmz/m-p/2051210#M398906</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2012-09-24T13:32:20Z</dc:date>
    </item>
    <item>
      <title>Site to site VPN not working for DMZ</title>
      <link>https://community.cisco.com/t5/network-security/site-to-site-vpn-not-working-for-dmz/m-p/2051211#M398907</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; That i should have mentioned it is the other tunnel we are talking about TDCH_LAN1 and TDCH_LAN2.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The other one is not an issue at the moment.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;/Hilmar&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 24 Sep 2012 13:34:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/site-to-site-vpn-not-working-for-dmz/m-p/2051211#M398907</guid>
      <dc:creator>IT Asitis</dc:creator>
      <dc:date>2012-09-24T13:34:58Z</dc:date>
    </item>
    <item>
      <title>Site to site VPN not working for DMZ</title>
      <link>https://community.cisco.com/t5/network-security/site-to-site-vpn-not-working-for-dmz/m-p/2051212#M398908</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Pls remove the following 2 routes:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;route WAN1 10.91.70.0 255.255.254.0 213.174.91.3 10&lt;/P&gt;&lt;P&gt;route WAN1 10.91.72.0 255.255.254.0 213.174.91.3 10&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;After removing the above 2, pls kindly share the output of"&lt;/P&gt;&lt;P&gt;show cry ipsec sa&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 24 Sep 2012 13:40:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/site-to-site-vpn-not-working-for-dmz/m-p/2051212#M398908</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2012-09-24T13:40:29Z</dc:date>
    </item>
    <item>
      <title>Site to site VPN not working for DMZ</title>
      <link>https://community.cisco.com/t5/network-security/site-to-site-vpn-not-working-for-dmz/m-p/2051213#M398909</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Ok i think i have fixed it. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You said&amp;nbsp; "Perhaps the NAT exemption has not been configured on DMZ1 and DMZ2?" it was only configured for Internal. &lt;/P&gt;&lt;P&gt;I added this for dmz1 and dmz2 and now i am able to talk to servers on the other end. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Great tip by the way &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;One thing i noticed was that there is no access rule for internal ( i think that the tunnel should bypass access rules ) can you confirm that this is not needed at all?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;/H&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 24 Sep 2012 13:47:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/site-to-site-vpn-not-working-for-dmz/m-p/2051213#M398909</guid>
      <dc:creator>IT Asitis</dc:creator>
      <dc:date>2012-09-24T13:47:19Z</dc:date>
    </item>
    <item>
      <title>Site to site VPN not working for DMZ</title>
      <link>https://community.cisco.com/t5/network-security/site-to-site-vpn-not-working-for-dmz/m-p/2051214#M398910</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Correct, if you don't have any access rule configured on internal interface, by default the traffic from internal going outbound will be allowed. And for VPN tunnel, traffic from remote LAN towards internal LAN will also be allowed.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 24 Sep 2012 13:54:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/site-to-site-vpn-not-working-for-dmz/m-p/2051214#M398910</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2012-09-24T13:54:32Z</dc:date>
    </item>
    <item>
      <title>Site to site VPN not working for DMZ</title>
      <link>https://community.cisco.com/t5/network-security/site-to-site-vpn-not-working-for-dmz/m-p/2051215#M398911</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Ok&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your help Jennifer.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;/Hilmar&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 24 Sep 2012 13:57:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/site-to-site-vpn-not-working-for-dmz/m-p/2051215#M398911</guid>
      <dc:creator>IT Asitis</dc:creator>
      <dc:date>2012-09-24T13:57:11Z</dc:date>
    </item>
  </channel>
</rss>

