<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic If you ping from ASA headend device where IPSEC tunnels built, does ping take tunnel? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/if-you-ping-from-asa-headend-device-where-ipsec-tunnels-built/m-p/3884336#M5908</link>
    <description>&lt;P&gt;Say the interesting traffic is ANY source on the ASA where you have IPSEC tunnels built. If I ping a destination IP which is deemed interesting traffic, what is a good way confirm the traffic is taking the IPSEC tunnel?&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 17:16:29 GMT</pubDate>
    <dc:creator>CiscoBrownBelt</dc:creator>
    <dc:date>2020-02-21T17:16:29Z</dc:date>
    <item>
      <title>If you ping from ASA headend device where IPSEC tunnels built, does ping take tunnel?</title>
      <link>https://community.cisco.com/t5/network-security/if-you-ping-from-asa-headend-device-where-ipsec-tunnels-built/m-p/3884336#M5908</link>
      <description>&lt;P&gt;Say the interesting traffic is ANY source on the ASA where you have IPSEC tunnels built. If I ping a destination IP which is deemed interesting traffic, what is a good way confirm the traffic is taking the IPSEC tunnel?&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 17:16:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/if-you-ping-from-asa-headend-device-where-ipsec-tunnels-built/m-p/3884336#M5908</guid>
      <dc:creator>CiscoBrownBelt</dc:creator>
      <dc:date>2020-02-21T17:16:29Z</dc:date>
    </item>
    <item>
      <title>Re: If you ping from ASA headend device where IPSEC tunnels built, does ping take tunnel?</title>
      <link>https://community.cisco.com/t5/network-security/if-you-ping-from-asa-headend-device-where-ipsec-tunnels-built/m-p/3884347#M5909</link>
      <description>&lt;P&gt;if the default route interface tunnel yes, if not take - depends on source IP it will take path for outbound traffic.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Jul 2019 21:22:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/if-you-ping-from-asa-headend-device-where-ipsec-tunnels-built/m-p/3884347#M5909</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2019-07-03T21:22:08Z</dc:date>
    </item>
    <item>
      <title>Re: If you ping from ASA headend device where IPSEC tunnels built, does ping take tunnel?</title>
      <link>https://community.cisco.com/t5/network-security/if-you-ping-from-asa-headend-device-where-ipsec-tunnels-built/m-p/3884354#M5910</link>
      <description>I am not sure if I follow given its an IPSEC on no tunnel inteface IP like gre. The default route on the ASA does not point to a tunnel destination. Is that what you mean?</description>
      <pubDate>Wed, 03 Jul 2019 21:29:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/if-you-ping-from-asa-headend-device-where-ipsec-tunnels-built/m-p/3884354#M5910</guid>
      <dc:creator>CiscoBrownBelt</dc:creator>
      <dc:date>2019-07-03T21:29:21Z</dc:date>
    </item>
    <item>
      <title>Re: If you ping from ASA headend device where IPSEC tunnels built, does ping take tunnel?</title>
      <link>https://community.cisco.com/t5/network-security/if-you-ping-from-asa-headend-device-where-ipsec-tunnels-built/m-p/3884360#M5911</link>
      <description>To add, the default route points to next hop of outside interface which is what tunnel uses?</description>
      <pubDate>Wed, 03 Jul 2019 21:39:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/if-you-ping-from-asa-headend-device-where-ipsec-tunnels-built/m-p/3884360#M5911</guid>
      <dc:creator>CiscoBrownBelt</dc:creator>
      <dc:date>2019-07-03T21:39:52Z</dc:date>
    </item>
    <item>
      <title>Re: If you ping from ASA headend device where IPSEC tunnels built, does ping take tunnel?</title>
      <link>https://community.cisco.com/t5/network-security/if-you-ping-from-asa-headend-device-where-ipsec-tunnels-built/m-p/3884363#M5912</link>
      <description>Hi,&lt;BR /&gt;If the source and destination IP addresses are referenced in the crypto ACL (identified as interesting traffic) then traffic should go via the VPN tunnel. &lt;BR /&gt;&lt;BR /&gt;If those networks are private IP address (RFC 1918) then they would not be routeable over the internet and therefore could only be routed over a tunnel.&lt;BR /&gt;&lt;BR /&gt;You can confirm the path of the traffic via packet capture on the remote ASA.&lt;BR /&gt;&lt;BR /&gt;HTH</description>
      <pubDate>Wed, 03 Jul 2019 21:45:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/if-you-ping-from-asa-headend-device-where-ipsec-tunnels-built/m-p/3884363#M5912</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2019-07-03T21:45:17Z</dc:date>
    </item>
    <item>
      <title>Re: If you ping from ASA headend device where IPSEC tunnels built, does ping take tunnel?</title>
      <link>https://community.cisco.com/t5/network-security/if-you-ping-from-asa-headend-device-where-ipsec-tunnels-built/m-p/3884367#M5913</link>
      <description>I can't access the remote device.&lt;BR /&gt;For interesting traffic, the source is ANY so that means it should take it correct?</description>
      <pubDate>Wed, 03 Jul 2019 21:47:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/if-you-ping-from-asa-headend-device-where-ipsec-tunnels-built/m-p/3884367#M5913</guid>
      <dc:creator>CiscoBrownBelt</dc:creator>
      <dc:date>2019-07-03T21:47:23Z</dc:date>
    </item>
    <item>
      <title>Re: If you ping from ASA headend device where IPSEC tunnels built, does ping take tunnel?</title>
      <link>https://community.cisco.com/t5/network-security/if-you-ping-from-asa-headend-device-where-ipsec-tunnels-built/m-p/3884368#M5914</link>
      <description>What is the output of "show crypto ipsec sa" are the encaps and decaps increasing?&lt;BR /&gt;&lt;BR /&gt;What is the configuration of the other firewall? Is the destination "any"?&lt;BR /&gt;What is the output of "show crypto ipsec sa" on the remote device? encaps|decaps?&lt;BR /&gt;&lt;BR /&gt;Do you have a NO-NAT rule defined, to ensure the traffic is not unintentially natted?&lt;BR /&gt;&lt;BR /&gt;HTH</description>
      <pubDate>Wed, 03 Jul 2019 21:51:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/if-you-ping-from-asa-headend-device-where-ipsec-tunnels-built/m-p/3884368#M5914</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2019-07-03T21:51:19Z</dc:date>
    </item>
    <item>
      <title>Re: If you ping from ASA headend device where IPSEC tunnels built, does ping take tunnel?</title>
      <link>https://community.cisco.com/t5/network-security/if-you-ping-from-asa-headend-device-where-ipsec-tunnels-built/m-p/3884556#M5915</link>
      <description>&lt;P&gt;What i meant was, by defautl you are pointing your Public Facing IP address towards ISP, that way you able to establish Tunnels.&lt;/P&gt;
&lt;P&gt;So if you ping from the device it uses Public IP address so it will go to ISP.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you have setup ACL and they are part of IPSEC Tunnel intresting traffic, if you source them they use Tunnel.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;First step is - make sure your IPSEC Tunnel up and running, other side also allow your IP RANGE ( no duplication of IP RANGe, if any you need do double NAT.)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;you can check with show crypto command for the traffic going via tunnel.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;it would be nice provide more configuration both the sides including show crypto information to suggest best.&lt;/P&gt;</description>
      <pubDate>Thu, 04 Jul 2019 07:29:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/if-you-ping-from-asa-headend-device-where-ipsec-tunnels-built/m-p/3884556#M5915</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2019-07-04T07:29:56Z</dc:date>
    </item>
  </channel>
</rss>

