<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic VPN Issues in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/vpn-issues/m-p/1883836#M457812</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jack,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From what I understand you can only establish the VPN connection from ASAs side when its a L2L VPN. With ezvpn and hardware VPN clients, the client device is usually configured to automatically connect to the central VPN device when it has a internet connection. Though there is an option to manually give the username/password during connecting on the CLI. (atleast with routers)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;About the VPN phase&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've onlyconfigured L2L VPN recently and in those cases the error message has usually related to the fact that the VPN connection isnt establishing for the connection you are testing. Usually means that the VPN settings dont match. Then again you are using the routers as VPN Clients so I'd guess the error is related to the fact that ASA cant initiate the connection to the client. The Client has to initiate the connection VPN connection first to give access to the remote networks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sorry, this is mostly me guessing. I don't really have a solid understanding of these types of VPN &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 23 Mar 2012 09:16:39 GMT</pubDate>
    <dc:creator>Jouni Forss</dc:creator>
    <dc:date>2012-03-23T09:16:39Z</dc:date>
    <item>
      <title>VPN Issues</title>
      <link>https://community.cisco.com/t5/network-security/vpn-issues/m-p/1883832#M457808</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;I have setup a VPN through my ASA for my branch routers,&amp;nbsp; Branch routers are on ADSL link and they are initiating the connection and they are able to connect to HO.On my ASA i have created dynamic-map which accepts connection dynamically.The problem is i can't initiate a connection from ASA to Branch router and also when branch routers are connected to HO when the tunnel is up though i m not able to telnet or ping to the remote branch routers??????&lt;/LI&gt;&lt;LI&gt;I also face this issue with site-site VPN.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Below is packet tracer for ping:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 1&lt;/P&gt;&lt;P&gt;Type: ROUTE-LOOKUP&lt;/P&gt;&lt;P&gt;Subtype: input&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;in&amp;nbsp;&amp;nbsp; 0.0.0.0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0.0.0.0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 2&lt;/P&gt;&lt;P&gt;Type: IP-OPTIONS&lt;/P&gt;&lt;P&gt;Subtype: &lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 3&lt;/P&gt;&lt;P&gt;Type: INSPECT&lt;/P&gt;&lt;P&gt;Subtype: np-inspect&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;class-map inspection_default&lt;/P&gt;&lt;P&gt; match default-inspection-traffic&lt;/P&gt;&lt;P&gt;policy-map global_policy&lt;/P&gt;&lt;P&gt; class inspection_default&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect icmp &lt;/P&gt;&lt;P&gt;service-policy global_policy global&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 4&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;Type: INSPECT &lt;/P&gt;&lt;P&gt;Subtype: np-inspect&lt;/P&gt;&lt;P&gt;Result: ALLOW &lt;/P&gt;&lt;P&gt;Config:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 5&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;Type: NAT&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;Subtype:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;Result: ALLOW &lt;/P&gt;&lt;P&gt;Config:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;nat (inside,outside) source static obj-192.168.0.0 obj-192.168.0.0 destination static ABC-subnet ABC-subnet no-proxy-arp route-lookup&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Static translate 192.168.100.1/0 to 192.168.100.1/0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 6&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;Type: VPN&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;Subtype: encrypt&lt;/P&gt;&lt;P&gt;Result: DROP&amp;nbsp; &lt;/P&gt;&lt;P&gt;Config:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Result:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;input-interface: inside&lt;/P&gt;&lt;P&gt;input-status: up&lt;/P&gt;&lt;P&gt;input-line-status: up&lt;/P&gt;&lt;P&gt;output-interface: outside&lt;/P&gt;&lt;P&gt;output-status: up&lt;/P&gt;&lt;P&gt;output-line-status: up&lt;/P&gt;&lt;P&gt;Action: drop&amp;nbsp; &lt;/P&gt;&lt;P&gt;Drop-reason: (acl-drop) Flow is denied by configured rule&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I dont understand why result is drop due to acl, i have kept open from HO to Branch on specific subnets and this packet tracer is from the subnet which is permited everything to the remote branch.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 22:46:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-issues/m-p/1883832#M457808</guid>
      <dc:creator>jack samuel</dc:creator>
      <dc:date>2019-03-11T22:46:04Z</dc:date>
    </item>
    <item>
      <title>VPN Issues</title>
      <link>https://community.cisco.com/t5/network-security/vpn-issues/m-p/1883833#M457809</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I guess the routers are acting as remote VPN Clients in this setup?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To my understanding only the routers can initiate the VPN connection but as you said you are facing other problems too&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ive personally configured some ezvpn clients on 800 and 1800 -series routers and some 5505 ASAs as hardware VPN clients. But I haven't had problems with the traffic after the initial setup.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What does the "show crypto ipsec sa" command show on the ASA when the VPN connection is up?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does the VPN configuration have any kind of "split-tunneling" configured that might cause the problems with the connections? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It would be helpfull in these kind of cases if you could attach configurations from each end. For me atleast this is just a guessing at the moment.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 23 Mar 2012 07:37:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-issues/m-p/1883833#M457809</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2012-03-23T07:37:43Z</dc:date>
    </item>
    <item>
      <title>VPN Issues</title>
      <link>https://community.cisco.com/t5/network-security/vpn-issues/m-p/1883834#M457810</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Can we initiate a connection from HO to branch if the HO ASA is configured for dynamic connection??&lt;/LI&gt;&lt;LI&gt;Can you tell me what the packet tracer No:6 is saying, I guess it is encrypting traffic but why it is dropping packet.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tx&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 23 Mar 2012 08:07:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-issues/m-p/1883834#M457810</guid>
      <dc:creator>jack samuel</dc:creator>
      <dc:date>2012-03-23T08:07:03Z</dc:date>
    </item>
    <item>
      <title>VPN Issues</title>
      <link>https://community.cisco.com/t5/network-security/vpn-issues/m-p/1883835#M457811</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jouniforss&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Same problem i am facing&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;when i excute show crypto isakmp sa&lt;/P&gt;&lt;P&gt;Phase 1 is up&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But when i excute show crypto&amp;nbsp;&amp;nbsp; ipsec sa&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It doesnot show any thing&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Far end is 1800 router and our is firewall&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As checked both side access-list, transformset is matching.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 23 Mar 2012 08:23:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-issues/m-p/1883835#M457811</guid>
      <dc:creator>prashantrecon</dc:creator>
      <dc:date>2012-03-23T08:23:40Z</dc:date>
    </item>
    <item>
      <title>VPN Issues</title>
      <link>https://community.cisco.com/t5/network-security/vpn-issues/m-p/1883836#M457812</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jack,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From what I understand you can only establish the VPN connection from ASAs side when its a L2L VPN. With ezvpn and hardware VPN clients, the client device is usually configured to automatically connect to the central VPN device when it has a internet connection. Though there is an option to manually give the username/password during connecting on the CLI. (atleast with routers)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;About the VPN phase&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've onlyconfigured L2L VPN recently and in those cases the error message has usually related to the fact that the VPN connection isnt establishing for the connection you are testing. Usually means that the VPN settings dont match. Then again you are using the routers as VPN Clients so I'd guess the error is related to the fact that ASA cant initiate the connection to the client. The Client has to initiate the connection VPN connection first to give access to the remote networks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sorry, this is mostly me guessing. I don't really have a solid understanding of these types of VPN &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 23 Mar 2012 09:16:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-issues/m-p/1883836#M457812</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2012-03-23T09:16:39Z</dc:date>
    </item>
    <item>
      <title>VPN Issues</title>
      <link>https://community.cisco.com/t5/network-security/vpn-issues/m-p/1883837#M457815</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dears,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When my branch routers intresting traffic initiate a connection to HO then only intresting traffic subnets from HO are able to initiate a connection.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For example:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Interesting traffic in HO 192.168.1.0 &amp;amp; 192.168.2.0&lt;/P&gt;&lt;P&gt;Interesting traffic in Branch 172.16.10.0 172.16.11.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If suppose a pc in 172.16.10.0 initiate a connection to 192.168.1.0 then only any other PC in 192.168.1.0 can initiate a connection to branch in 172.16.10.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If a PC in 192.168.1.0 want to initiate a connection to another subnet of branch suppose 172.16.11.0 the PC gets request timeout BUT if any PC in 172.16.11.0 initiate a connection to 192.168.1.0 then PC's from subnet 192.168.1.0 are also able to reach 172.16.11.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is this normal behaviour for one side static and another side dynamic IPSEC vpn.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 29 Mar 2012 22:16:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-issues/m-p/1883837#M457815</guid>
      <dc:creator>jack samuel</dc:creator>
      <dc:date>2012-03-29T22:16:04Z</dc:date>
    </item>
    <item>
      <title>VPN Issues</title>
      <link>https://community.cisco.com/t5/network-security/vpn-issues/m-p/1883838#M457817</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can anybody help me for the above query,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 30 Mar 2012 20:28:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-issues/m-p/1883838#M457817</guid>
      <dc:creator>jack samuel</dc:creator>
      <dc:date>2012-03-30T20:28:44Z</dc:date>
    </item>
  </channel>
</rss>

