<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic L2L VPN Issue in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/l2l-vpn-issue/m-p/1731146#M553507</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Post the ouput of comands:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;debug crypto isakmp 7&lt;/P&gt;&lt;P&gt;debug crypto ipsec 7&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; After applying&amp;nbsp; the commands, try to generate interesting traffic to force the peers to stabilish a vpn.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;[]s&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 16 Jun 2011 15:32:56 GMT</pubDate>
    <dc:creator>Rafael Mendes</dc:creator>
    <dc:date>2011-06-16T15:32:56Z</dc:date>
    <item>
      <title>L2L VPN Issue</title>
      <link>https://community.cisco.com/t5/network-security/l2l-vpn-issue/m-p/1731143#M553502</link>
      <description>&lt;P&gt;I have a L2L VPN between two ASA5510.&amp;nbsp; The tunnel is up and passing traffic between 14 network pairs but two. I have checked that the interesting traffic is in the no nat ACL, in the crypto map ACL and in the interfaces permitted ACL in both sites. I have checked that crypto mal ACLs match in both sides. When I run "show crypto ipsec sa X.X.X.X" I get the following for the both ACL lines corresponding to the network pairs:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;:: Site 1:: &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Pair 1 (10.10.1.0 ---&amp;gt; 10.10.3.0):&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;#pkts encaps: 0, #pkts encrypt: 0, #pkts digest: 0&lt;/P&gt;&lt;P&gt;#pkts decaps: 587, #pkts decrypt: 587, #pkts verify: 587&lt;/P&gt;&lt;P&gt;#pkts compressed: 0, #pkts decompressed: 0&lt;/P&gt;&lt;P&gt;#pkts not compressed: 0, #pkts comp failed: 0, #pkts decomp failed: 0&lt;/P&gt;&lt;P&gt;#pre-frag successes: 0, #pre-frag failures: 0, #fragments created: 0&lt;/P&gt;&lt;P&gt;#PMTUs sent: 0, #PMTUs rcvd: 0, #decapsulated frgs needing reassembly: 0&lt;/P&gt;&lt;P&gt;#send errors: 0, #recv errors: 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Pair 2 (10.10.19.0 ---&amp;gt; 10.10.3.0):&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;#pkts encaps: 0, #pkts encrypt: 0, #pkts digest: 0&lt;BR /&gt;#pkts decaps: 2199, #pkts decrypt: 2199, #pkts verify: 2199&lt;BR /&gt;#pkts compressed: 0, #pkts decompressed: 0&lt;BR /&gt;#pkts not compressed: 0, #pkts comp failed: 0, #pkts decomp failed: 0&lt;BR /&gt;#pre-frag successes: 0, #pre-frag failures: 0, #fragments created: 0&lt;BR /&gt;#PMTUs sent: 0, #PMTUs rcvd: 0, #decapsulated frgs needing reassembly: 0&lt;BR /&gt;#send errors: 0, #recv errors: 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;::Site 2::&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Pair 1 (10.10.3.0 --&amp;gt; 10.10.1.0)&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; #pkts encaps: 709, #pkts encrypt: 709, #pkts digest: 709&lt;/P&gt;&lt;P&gt;&amp;nbsp; #pkts decaps: 0, #pkts decrypt: 0, #pkts verify: 0&lt;/P&gt;&lt;P&gt;&amp;nbsp; #pkts compressed: 0, #pkts decompressed: 0&lt;/P&gt;&lt;P&gt;&amp;nbsp; #pkts not compressed: 709, #pkts comp failed: 0, #pkts decomp failed: 0&lt;/P&gt;&lt;P&gt;&amp;nbsp; #pre-frag successes: 0, #pre-frag failures: 0, #fragments created: 0&lt;/P&gt;&lt;P&gt;&amp;nbsp; #PMTUs sent: 0, #PMTUs rcvd: 0, #decapsulated frgs needing reassembly: 0&lt;/P&gt;&lt;P&gt;&amp;nbsp; #send errors: 0, #recv errors: 0&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Pair 2 (10.10.3.0 --&amp;gt; 10.10.19.0)&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; #pkts encaps: 2667, #pkts encrypt: 2667, #pkts digest: 2667&lt;/P&gt;&lt;P&gt;&amp;nbsp; #pkts decaps: 0, #pkts decrypt: 0, #pkts verify: 0&lt;/P&gt;&lt;P&gt;&amp;nbsp; #pkts compressed: 0, #pkts decompressed: 0&lt;/P&gt;&lt;P&gt;&amp;nbsp; #pkts not compressed: 2667, #pkts comp failed: 0, #pkts decomp failed: 0&lt;/P&gt;&lt;P&gt;&amp;nbsp; #pre-frag successes: 0, #pre-frag failures: 0, #fragments created: 0&lt;/P&gt;&lt;P&gt;&amp;nbsp; #PMTUs sent: 0, #PMTUs rcvd: 0, #decapsulated frgs needing reassembly: 0&lt;/P&gt;&lt;P&gt;&amp;nbsp; #send errors: 0, #recv errors: 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have read a similar case resolved with a reset of the equipment in the site where the packets were not being encapsulated. But I don't think a reset should be the solution. &lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 20:45:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/l2l-vpn-issue/m-p/1731143#M553502</guid>
      <dc:creator>rrivas</dc:creator>
      <dc:date>2019-03-11T20:45:56Z</dc:date>
    </item>
    <item>
      <title>L2L VPN Issue</title>
      <link>https://community.cisco.com/t5/network-security/l2l-vpn-issue/m-p/1731144#M553503</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Make sure routing is properly configured, that traffic from one subnet to another needs to go through ASA to be encrypted&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 Jun 2011 05:43:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/l2l-vpn-issue/m-p/1731144#M553503</guid>
      <dc:creator>fgasimzade</dc:creator>
      <dc:date>2011-06-16T05:43:06Z</dc:date>
    </item>
    <item>
      <title>L2L VPN Issue</title>
      <link>https://community.cisco.com/t5/network-security/l2l-vpn-issue/m-p/1731145#M553505</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It is. The server in Site 2 are connected direct to the ASA with a switch. The gateways of these servers is the ASA. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 Jun 2011 14:59:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/l2l-vpn-issue/m-p/1731145#M553505</guid>
      <dc:creator>rrivas</dc:creator>
      <dc:date>2011-06-16T14:59:58Z</dc:date>
    </item>
    <item>
      <title>L2L VPN Issue</title>
      <link>https://community.cisco.com/t5/network-security/l2l-vpn-issue/m-p/1731146#M553507</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Post the ouput of comands:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;debug crypto isakmp 7&lt;/P&gt;&lt;P&gt;debug crypto ipsec 7&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; After applying&amp;nbsp; the commands, try to generate interesting traffic to force the peers to stabilish a vpn.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;[]s&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 Jun 2011 15:32:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/l2l-vpn-issue/m-p/1731146#M553507</guid>
      <dc:creator>Rafael Mendes</dc:creator>
      <dc:date>2011-06-16T15:32:56Z</dc:date>
    </item>
    <item>
      <title>L2L VPN Issue</title>
      <link>https://community.cisco.com/t5/network-security/l2l-vpn-issue/m-p/1731147#M553508</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I ping from site 2 to site 1, and those are the results from the ASDM debugging tool for the networks with problem:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Site 1:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;6&lt;/TD&gt;&lt;TD&gt;Jun 16 2011&lt;/TD&gt;&lt;TD&gt;14:50:00&lt;/TD&gt;&lt;TD&gt;302020&lt;/TD&gt;&lt;TD&gt;10.10.3.2&lt;/TD&gt;&lt;TD&gt;512&lt;/TD&gt;&lt;TD&gt;10.10.19.38&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;Built inbound ICMP connection for faddr 10.10.3.2/512 gaddr 10.10.19.38/0 laddr 10.10.19.38/0&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;P&gt;6&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;Jun 16 2011&lt;/TD&gt;&lt;TD&gt;13:23:18&lt;/TD&gt;&lt;TD&gt;302021&lt;/TD&gt;&lt;TD&gt;10.10.3.2&lt;/TD&gt;&lt;TD&gt;512&lt;/TD&gt;&lt;TD&gt;10.10.19.38&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;Teardown ICMP connection for faddr 10.10.3.2/512 gaddr 10.10.19.38/0 laddr 10.10.19.38/0&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Site 2:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;6&lt;/TD&gt;&lt;TD&gt;Jun 16 2011&lt;/TD&gt;&lt;TD&gt;15:46:50&lt;/TD&gt;&lt;TD&gt;302020&lt;/TD&gt;&lt;TD&gt;10.10.3.2&lt;/TD&gt;&lt;TD&gt;512&lt;/TD&gt;&lt;TD&gt;10.10.19.38&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;Built outbound ICMP connection for faddr 10.10.19.38/0 gaddr 10.10.3.2/512 laddr 10.10.3.2/512&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;6&lt;/TD&gt;&lt;TD&gt;Jun 16 2011&lt;/TD&gt;&lt;TD&gt;15:46:47&lt;/TD&gt;&lt;TD&gt;302021&lt;/TD&gt;&lt;TD&gt;10.10.19.38&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;10.10.3.2&lt;/TD&gt;&lt;TD&gt;512&lt;/TD&gt;&lt;TD&gt;Teardown ICMP connection for faddr 10.10.19.38/0 gaddr 10.10.3.2/512 laddr 10.10.3.2/512&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 Jun 2011 22:11:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/l2l-vpn-issue/m-p/1731147#M553508</guid>
      <dc:creator>rrivas</dc:creator>
      <dc:date>2011-06-16T22:11:11Z</dc:date>
    </item>
    <item>
      <title>L2L VPN Issue</title>
      <link>https://community.cisco.com/t5/network-security/l2l-vpn-issue/m-p/1731148#M553509</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Do you have a nat, or exempt nat?&lt;/P&gt;&lt;P&gt;Are the two networks 10.10.1.0 and 10.10.190 in cryto map in site 1?&lt;/P&gt;&lt;P&gt;Did you check the routes from both sites?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 17 Jun 2011 15:00:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/l2l-vpn-issue/m-p/1731148#M553509</guid>
      <dc:creator>Rafael Mendes</dc:creator>
      <dc:date>2011-06-17T15:00:47Z</dc:date>
    </item>
    <item>
      <title>Re: L2L VPN Issue</title>
      <link>https://community.cisco.com/t5/network-security/l2l-vpn-issue/m-p/1731149#M553510</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Most like the issue is on 10.10.1.0 side of the firewall.  As its not encrypting the packets.   Plz check nat exempt and mask in crypto map. Btw , which version are u running.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sent from Cisco Technical Support iPhone App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 17 Jun 2011 16:39:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/l2l-vpn-issue/m-p/1731149#M553510</guid>
      <dc:creator>cco-bloom</dc:creator>
      <dc:date>2011-06-17T16:39:36Z</dc:date>
    </item>
    <item>
      <title>L2L VPN Issue</title>
      <link>https://community.cisco.com/t5/network-security/l2l-vpn-issue/m-p/1731150#M553511</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; I have exempt nat. Yes, they are, 10.10.1.0 &amp;amp; 10.10.19.0 are in the crypto map. If they weren't, they wouldn't appear in the "show crypto ipsec sa X.X.X.X" output. I don't have routes since network gateways are configured in the ASAs.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 17 Jun 2011 16:56:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/l2l-vpn-issue/m-p/1731150#M553511</guid>
      <dc:creator>rrivas</dc:creator>
      <dc:date>2011-06-17T16:56:53Z</dc:date>
    </item>
    <item>
      <title>Re: L2L VPN Issue</title>
      <link>https://community.cisco.com/t5/network-security/l2l-vpn-issue/m-p/1731151#M553512</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; I thing so too or an IOS bug. asa822-k8 in both.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 17 Jun 2011 17:59:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/l2l-vpn-issue/m-p/1731151#M553512</guid>
      <dc:creator>rrivas</dc:creator>
      <dc:date>2011-06-17T17:59:05Z</dc:date>
    </item>
    <item>
      <title>Re: L2L VPN Issue</title>
      <link>https://community.cisco.com/t5/network-security/l2l-vpn-issue/m-p/1731152#M553513</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you are running 8.22, then you are hitting buy &lt;A class="active_link" href="http://cdets.cisco.com/apps/dumpcr?&amp;amp;content=summary&amp;amp;format=html&amp;amp;identifier=CSCtd36473" target="_blank"&gt;CSCtd36473.&amp;nbsp; &lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;amp;bugId=CSCtd36473"&gt;http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;amp;bugId=CSCtd36473&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 17 Jun 2011 19:36:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/l2l-vpn-issue/m-p/1731152#M553513</guid>
      <dc:creator>cco-bloom</dc:creator>
      <dc:date>2011-06-17T19:36:46Z</dc:date>
    </item>
  </channel>
</rss>

