<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re:Adding new network to IPsec VPN in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/adding-new-network-to-ipsec-vpn/m-p/1951436#M435068</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are you able to ping from your LAN to the remote host? What exactly stopped working?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sent from Cisco Technical Support Android App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sat, 02 Jun 2012 16:26:06 GMT</pubDate>
    <dc:creator>Javier Portuguez</dc:creator>
    <dc:date>2012-06-02T16:26:06Z</dc:date>
    <item>
      <title>Adding new network to IPsec VPN</title>
      <link>https://community.cisco.com/t5/network-security/adding-new-network-to-ipsec-vpn/m-p/1951435#M435067</link>
      <description>&lt;P&gt;Hi &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are having a IPsec VPN Tunnel setup with client.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The far site gave access to a new range (a website basically hosting on their site)-10.40.36.173:8085&lt;/P&gt;&lt;P&gt;They allowed traffic across the tunnel from:&lt;STRONG&gt; 10.40.36.173:8085&lt;/STRONG&gt;&amp;nbsp; to&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;STRONG&gt;10.20.42.0/23, 10.21.42.0/23, 192.168.42.0/24&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From my end we are using 3 IP Ranges when sending traffic to farsite:&lt;/P&gt;&lt;P&gt;10.20.42.0/23&lt;/P&gt;&lt;P&gt;10.21.42.0/23&lt;BR /&gt; 192.168.42.0/24&lt;BR /&gt;&amp;nbsp; &lt;BR /&gt;&lt;/P&gt;&lt;P&gt;To make sure the traffic that is sent between both end points is sent&amp;nbsp; across the tunnel encrypted and not via another channel the I want to&amp;nbsp; write Crypto ACL configured on my side which was already mirrored on&amp;nbsp; far end.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So I just logged on ASA CLI and went to global mode and added the ACL and no nat to access the destination point from all of our IP Ranges as below, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list nonat&amp;nbsp; extended permit ip 192.168.42.0 255.255.255.0 host 10.40.36.173 &lt;/P&gt;&lt;P&gt;access-list nonat line 11 extended permit ip 10.40.42.0 255.255.254.0 host 10.40.36.173&lt;/P&gt;&lt;P&gt;access-list nonat line 11 extended permit ip 10.41.42.0 255.255.254.0 host 10.40.36.173 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list xx line 4 extended permit ip 192.168.42.0 255.255.255.0 host 10.40.36.173 (hitcnt=30) 0x30941176&lt;/P&gt;&lt;P&gt;access-list xx line 4 extended permit ip 10.40.42.0 255.255.254.0 host 10.40.36.173 (hitcnt=0) 0x30941176&lt;/P&gt;&lt;P&gt;access-list xx line 4 extended permit ip 10.41.42.0 255.255.254.0 host 10.40.36.173 (hitcnt=0) 0x30941176&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I cant access though from any of the range but can access all previous configured tools, basically newbee to firewall any help much appreciated&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope I have not confused anyone, if anyone has any questions please let me know, I look forward for your valuable response,&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 23:14:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/adding-new-network-to-ipsec-vpn/m-p/1951435#M435067</guid>
      <dc:creator>Ven Diesel</dc:creator>
      <dc:date>2019-03-11T23:14:49Z</dc:date>
    </item>
    <item>
      <title>Re:Adding new network to IPsec VPN</title>
      <link>https://community.cisco.com/t5/network-security/adding-new-network-to-ipsec-vpn/m-p/1951436#M435068</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are you able to ping from your LAN to the remote host? What exactly stopped working?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sent from Cisco Technical Support Android App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 02 Jun 2012 16:26:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/adding-new-network-to-ipsec-vpn/m-p/1951436#M435068</guid>
      <dc:creator>Javier Portuguez</dc:creator>
      <dc:date>2012-06-02T16:26:06Z</dc:date>
    </item>
    <item>
      <title>Re:Adding new network to IPsec VPN</title>
      <link>https://community.cisco.com/t5/network-security/adding-new-network-to-ipsec-vpn/m-p/1951437#M435069</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your reply &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Well I cant ping from LAN to remote host either telnet as well on the ports requested, as it is a new acl added to crypto tunnel &lt;/P&gt;&lt;P&gt;do I need to do anything like clear crypto ipsec sa or clear crypto iskamp sa to reestablish the tunnel, as we havent got no one on other side at the moment to actually test.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 02 Jun 2012 17:49:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/adding-new-network-to-ipsec-vpn/m-p/1951437#M435069</guid>
      <dc:creator>Ven Diesel</dc:creator>
      <dc:date>2012-06-02T17:49:02Z</dc:date>
    </item>
    <item>
      <title>Re:Adding new network to IPsec VPN</title>
      <link>https://community.cisco.com/t5/network-security/adding-new-network-to-ipsec-vpn/m-p/1951438#M435070</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please run a packet-tracer:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;packet-tracer input inside icmp local_network 8 0 remote_network detail &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please attach the output.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sent from Cisco Technical Support Android App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 03 Jun 2012 00:25:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/adding-new-network-to-ipsec-vpn/m-p/1951438#M435070</guid>
      <dc:creator>Javier Portuguez</dc:creator>
      <dc:date>2012-06-03T00:25:19Z</dc:date>
    </item>
    <item>
      <title>Re:Adding new network to IPsec VPN</title>
      <link>https://community.cisco.com/t5/network-security/adding-new-network-to-ipsec-vpn/m-p/1951439#M435071</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="font-family: verdana, geneva;"&gt;have the tunnel negotiations completed successfully after the change? what does ur sh cry ipsec sa output look like? as Jav mentioned, a packet tracer from your specified local network to the remote peer network will basically tell us the exact problem. Oh, the power of ASA's.. gotta love the IOS &lt;SPAN __jive_emoticon_name="wink" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/images/emoticons/wink.gif"&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 03 Jun 2012 03:13:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/adding-new-network-to-ipsec-vpn/m-p/1951439#M435071</guid>
      <dc:creator>mikull.kiznozki</dc:creator>
      <dc:date>2012-06-03T03:13:29Z</dc:date>
    </item>
    <item>
      <title>Adding new network to IPsec VPN</title>
      <link>https://community.cisco.com/t5/network-security/adding-new-network-to-ipsec-vpn/m-p/1951440#M435072</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Its a fault with peer ip , assigned crypto map and renegotiated, tunnel up &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 Jun 2012 20:10:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/adding-new-network-to-ipsec-vpn/m-p/1951440#M435072</guid>
      <dc:creator>Ven Diesel</dc:creator>
      <dc:date>2012-06-20T20:10:58Z</dc:date>
    </item>
  </channel>
</rss>

