<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: tunnel drop in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/tunnel-drop/m-p/1515857#M600022</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;sorry for omitting those initially.&lt;/P&gt;&lt;P&gt;our end is an ASA and other end has cisco router.&lt;/P&gt;&lt;P&gt;Ipsec tunnel comes up without any problem at first and if ping is done from 172.16.100.2 or so ip to 192.168.100.0 /24 it works well.&lt;/P&gt;&lt;P&gt;however, whenever the remote end 172.16.100.0 255.255.255.248 pings or does traceroute to 192.168.200.110 or 192.168.200.130 , the tunnel goes down.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;hope this information is much clearer.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 26 Oct 2010 02:52:27 GMT</pubDate>
    <dc:creator>suthomas1</dc:creator>
    <dc:date>2010-10-26T02:52:27Z</dc:date>
    <item>
      <title>tunnel drop</title>
      <link>https://community.cisco.com/t5/network-security/tunnel-drop/m-p/1515855#M600020</link>
      <description>&lt;P&gt;we have below list for an ipsec tunnel&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list 195 line 1 extended permit ip 192.168.100.0 255.255.255.0 172.16.100.0 255.255.255.248 &lt;BR /&gt;access-list 195 line 2 extended permit tcp host 192.168.200.110 eq 6600&amp;nbsp; 172.16.100.0 255.255.255.248&lt;/P&gt;&lt;P&gt;access-list 195 line 2 extended permit udp host 192.168.300.130 172.16.100.0 255.255.255.248 eq domain&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the other remote end of ipsec , when tries to even ping or trace to 192.168.200.110 or 192.168.300.130 , the vpn connection goes down.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;why does it do so.&lt;/P&gt;&lt;P&gt;TIA.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 19:00:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tunnel-drop/m-p/1515855#M600020</guid>
      <dc:creator>suthomas1</dc:creator>
      <dc:date>2019-03-11T19:00:11Z</dc:date>
    </item>
    <item>
      <title>Re: tunnel drop</title>
      <link>https://community.cisco.com/t5/network-security/tunnel-drop/m-p/1515856#M600021</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;please brief u smore about what the 2 devices in question are and what kind of vpn is setup&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;also what exactly do you mean when you say that ping brings down the tunnel (is it that ping brings the tunnel down or the tunnel is not coming up at all )&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 26 Oct 2010 02:37:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tunnel-drop/m-p/1515856#M600021</guid>
      <dc:creator>Jitendriya Athavale</dc:creator>
      <dc:date>2010-10-26T02:37:13Z</dc:date>
    </item>
    <item>
      <title>Re: tunnel drop</title>
      <link>https://community.cisco.com/t5/network-security/tunnel-drop/m-p/1515857#M600022</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;sorry for omitting those initially.&lt;/P&gt;&lt;P&gt;our end is an ASA and other end has cisco router.&lt;/P&gt;&lt;P&gt;Ipsec tunnel comes up without any problem at first and if ping is done from 172.16.100.2 or so ip to 192.168.100.0 /24 it works well.&lt;/P&gt;&lt;P&gt;however, whenever the remote end 172.16.100.0 255.255.255.248 pings or does traceroute to 192.168.200.110 or 192.168.200.130 , the tunnel goes down.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;hope this information is much clearer.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 26 Oct 2010 02:52:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tunnel-drop/m-p/1515857#M600022</guid>
      <dc:creator>suthomas1</dc:creator>
      <dc:date>2010-10-26T02:52:27Z</dc:date>
    </item>
    <item>
      <title>Re: tunnel drop</title>
      <link>https://community.cisco.com/t5/network-security/tunnel-drop/m-p/1515858#M600023</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;so if i understand you right you say the tunnel gpoes down bcoz you dont see ping replies coming in&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;if that is the reason assuming access-list 195 is the acl to define vpn traffic or crypto traffic, as you can see you are allowing only spefic ports through vpn for that ip's that is hwy you are not able to ping if you want to allow everything between the 2 hosts use the following on crypto acl on both ends&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list 195 line 1 extended permit ip 192.168.100.0 255.255.255.0 172.16.100.0 255.255.255.248 &lt;BR /&gt;access-list 195 line 2 extended permit &lt;STRONG&gt;ip&lt;/STRONG&gt; host 192.168.200.110&amp;nbsp;&amp;nbsp; 172.16.100.0 255.255.255.248&lt;/P&gt;&lt;P&gt;access-list 195 line 2 extended permit &lt;STRONG&gt;ip&lt;/STRONG&gt; host 192.168.300.130 172.16.100.0 255.255.255.248&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the change has been highlighted in bold&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 26 Oct 2010 03:20:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tunnel-drop/m-p/1515858#M600023</guid>
      <dc:creator>Jitendriya Athavale</dc:creator>
      <dc:date>2010-10-26T03:20:45Z</dc:date>
    </item>
    <item>
      <title>Re: tunnel drop</title>
      <link>https://community.cisco.com/t5/network-security/tunnel-drop/m-p/1515859#M600024</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;does that mean if we try to initiate connection to traffic not covered under define acl 195 , the tunnel will go down.&lt;/P&gt;&lt;P&gt;in that case how do we nail down the traffic to only the required tcp or udp ones rather than ip ..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 26 Oct 2010 03:37:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tunnel-drop/m-p/1515859#M600024</guid>
      <dc:creator>suthomas1</dc:creator>
      <dc:date>2010-10-26T03:37:28Z</dc:date>
    </item>
    <item>
      <title>Re: tunnel drop</title>
      <link>https://community.cisco.com/t5/network-security/tunnel-drop/m-p/1515860#M600025</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;the tunnel does not go down, the traffic does not go through the tunnel&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;so what ever tarffic is defined in that crypto acl only goes through the tunnel&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;can you please paste the output of&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;show run crypto -&amp;gt; on the asa&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 26 Oct 2010 03:53:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tunnel-drop/m-p/1515860#M600025</guid>
      <dc:creator>Jitendriya Athavale</dc:creator>
      <dc:date>2010-10-26T03:53:12Z</dc:date>
    </item>
    <item>
      <title>Re: tunnel drop</title>
      <link>https://community.cisco.com/t5/network-security/tunnel-drop/m-p/1515861#M600026</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;thanks,&lt;/P&gt;&lt;P&gt;i have masked some values.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;crypto ipsec transform-set vpn esp-3des esp-md5-hmac &lt;BR /&gt;crypto map kepp 60 match address 195&lt;BR /&gt;crypto map kepp 60 set peer y.y.y.y &lt;BR /&gt;crypto map kepp 60 set transform-set vpn&lt;BR /&gt;crypto map kepp 60 set security-association lifetime seconds 28800&lt;BR /&gt;crypto map kepp 60 set security-association lifetime kilobytes 4608000&lt;BR /&gt;crypto map kepp interface External&lt;BR /&gt;crypto ca trustpoint ASDM_TrustPoint0&lt;BR /&gt; enrollment self&lt;BR /&gt; fqdn VPNASABU.abc.com&lt;BR /&gt; subject-name CN=VPNASABU&lt;BR /&gt; serial-number&lt;BR /&gt; crl configure&lt;BR /&gt;crypto isakmp enable outside&lt;BR /&gt;crypto isakmp policy 60&lt;BR /&gt; authentication pre-share&lt;BR /&gt; encryption 3des&lt;BR /&gt; hash sha&lt;BR /&gt; group 2&lt;BR /&gt; lifetime 86400&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank You&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 26 Oct 2010 04:11:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tunnel-drop/m-p/1515861#M600026</guid>
      <dc:creator>suthomas1</dc:creator>
      <dc:date>2010-10-26T04:11:49Z</dc:date>
    </item>
    <item>
      <title>Re: tunnel drop</title>
      <link>https://community.cisco.com/t5/network-security/tunnel-drop/m-p/1515862#M600027</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;yeah so as i said before&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;make cahnegs to that acl on both ends and pings will start working&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 26 Oct 2010 04:23:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tunnel-drop/m-p/1515862#M600027</guid>
      <dc:creator>Jitendriya Athavale</dc:creator>
      <dc:date>2010-10-26T04:23:57Z</dc:date>
    </item>
    <item>
      <title>Re: tunnel drop</title>
      <link>https://community.cisco.com/t5/network-security/tunnel-drop/m-p/1515863#M600028</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;so if you do not want to alow everything you can use wht you have in addition to that you can allow icmp betwene the 2 hosts for testing connectivity&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list 195 extended permit &lt;STRONG&gt;icmp &lt;/STRONG&gt;host 192.168.200.110&amp;nbsp;&amp;nbsp; 172.16.100.0 255.255.255.248&lt;/P&gt;&lt;P&gt;access-list 195 extended permit &lt;STRONG&gt;icmp&lt;/STRONG&gt; host 192.168.300.130 172.16.100.0 255.255.255.248&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;hope this helps&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;let me know if you have more questions&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 26 Oct 2010 04:28:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tunnel-drop/m-p/1515863#M600028</guid>
      <dc:creator>Jitendriya Athavale</dc:creator>
      <dc:date>2010-10-26T04:28:18Z</dc:date>
    </item>
    <item>
      <title>Re: tunnel drop</title>
      <link>https://community.cisco.com/t5/network-security/tunnel-drop/m-p/1515864#M600029</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As far as I know, the best practices are to select only "ip" for the access-list applied on the crypto map.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you want to limit ports you can do it on your inside access-group ACLs for both ends or use a VPN-FIlter on the ASA.Here's a sample config for the VPN-Filters on the ASA:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/partner/products/hw/vpndevc/ps2030/products_configuration_example09186a00808c9a87.shtml"&gt;http://www.cisco.com/en/US/partner/products/hw/vpndevc/ps2030/products_configuration_example09186a00808c9a87.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In any case.. if you are willing to test by limiting the protocol on the crypto map access-list, both ends most have exactly the same access-list (mirrored) for the VPN to work. I understand this makes the encryption process harder for the appliance since more Security Associations are created when specific ports are selected instead of when only IP is selected.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 26 Oct 2010 22:18:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tunnel-drop/m-p/1515864#M600029</guid>
      <dc:creator>Daniela Herrera</dc:creator>
      <dc:date>2010-10-26T22:18:19Z</dc:date>
    </item>
  </channel>
</rss>

