<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA 5505 multiple VPNs not working in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-5505-multiple-vpns-not-working/m-p/1492794#M653088</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I don't know, it's all jacked up.&amp;nbsp; We are seeing other odd behaviour, like configuration changes disappearing after we save them and go back into what was just configured.&amp;nbsp; After posting this, I found out the air condition went out where the equipment is located, and we are suspecting the equipment overheated, as we are seeing some issues with other equipment as well.&amp;nbsp; We are looking into the coverage on this firewall now, and considering alternative solutions.&amp;nbsp; I'm not very experienced on Cisco yet.&amp;nbsp; Can you give me an example of all we should need to have configured for a single tunnel to work, where multiple tunnels exist to access the same internal LAN(s)?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 04 Aug 2010 22:50:58 GMT</pubDate>
    <dc:creator>bradkenn75</dc:creator>
    <dc:date>2010-08-04T22:50:58Z</dc:date>
    <item>
      <title>ASA 5505 multiple VPNs not working</title>
      <link>https://community.cisco.com/t5/network-security/asa-5505-multiple-vpns-not-working/m-p/1492788#M653082</link>
      <description>&lt;P&gt;Had a new vpn setup last week, or so; since then, other vpn tunnels stopped working (site-to-site vpns)&amp;nbsp; Need help troubleshooting issues; unable to ping across tunner when it was showing active, now all of the tunnels are not showing active.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 18:21:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5505-multiple-vpns-not-working/m-p/1492788#M653082</guid>
      <dc:creator>bradkenn75</dc:creator>
      <dc:date>2019-03-11T18:21:05Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5505 multiple VPNs not working</title>
      <link>https://community.cisco.com/t5/network-security/asa-5505-multiple-vpns-not-working/m-p/1492789#M653083</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you please post the corresponding configurations here?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;NT&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 04 Aug 2010 17:37:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5505-multiple-vpns-not-working/m-p/1492789#M653083</guid>
      <dc:creator>Nagaraja Thanthry</dc:creator>
      <dc:date>2010-08-04T17:37:40Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5505 multiple VPNs not working</title>
      <link>https://community.cisco.com/t5/network-security/asa-5505-multiple-vpns-not-working/m-p/1492790#M653084</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;let me know if you need more than this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object-group network DM_INLINE_NETWORK_1&lt;BR /&gt; network-object host 172.30.1.14&lt;BR /&gt; network-object host 172.31.1.15&lt;BR /&gt;object-group service SSH-ALT tcp&lt;BR /&gt; description SSH-ALT&lt;BR /&gt; port-object eq 24&lt;BR /&gt;object-group protocol DM_INLINE_PROTOCOL_1&lt;BR /&gt; protocol-object ip&lt;BR /&gt; protocol-object tcp&lt;BR /&gt; protocol-object icmp&lt;BR /&gt;object-group protocol DM_INLINE_PROTOCOL_2&lt;BR /&gt; protocol-object ip&lt;BR /&gt; protocol-object icmp&lt;BR /&gt; protocol-object udp&lt;BR /&gt; protocol-object tcp&lt;BR /&gt;object-group network DM_INLINE_NETWORK_2&lt;BR /&gt; network-object CDX 255.255.255.0&lt;BR /&gt; network-object 172.31.1.0 255.255.255.0&lt;BR /&gt;object-group network DM_INLINE_NETWORK_3&lt;BR /&gt; network-object CDX 255.255.255.0&lt;BR /&gt; network-object 172.31.1.0 255.255.255.0&lt;BR /&gt;object-group protocol TCPUDP&lt;BR /&gt; protocol-object udp&lt;BR /&gt; protocol-object tcp&lt;BR /&gt;object-group service PACS tcp-udp&lt;BR /&gt; description PACS&lt;BR /&gt; port-object eq 104&lt;BR /&gt;object-group network DM_INLINE_NETWORK_4&lt;BR /&gt; network-object 172.30.1.0 255.255.255.224&lt;BR /&gt; network-object 192.168.0.0 255.255.255.0&lt;BR /&gt;object-group network DM_INLINE_NETWORK_6&lt;BR /&gt; network-object 172.30.1.0 255.255.255.224&lt;BR /&gt; network-object 192.168.0.0 255.255.255.0&lt;BR /&gt;object-group protocol DM_INLINE_PROTOCOL_3&lt;BR /&gt; protocol-object ip&lt;BR /&gt; protocol-object icmp&lt;BR /&gt; protocol-object tcp&lt;BR /&gt;access-list outside extended permit icmp any any &lt;BR /&gt;access-list inside_nat0_outbound extended permit ip 172.30.1.0 255.255.255.0 172.30.250.0 255.255.255.0 &lt;BR /&gt;access-list inside_nat0_outbound extended permit ip 172.31.2.0 255.255.255.0 172.30.250.0 255.255.255.0 &lt;BR /&gt;access-list inside_nat0_outbound extended permit ip 172.31.0.0 255.255.255.0 172.30.250.0 255.255.255.0 &lt;BR /&gt;access-list inside_nat0_outbound extended permit ip 172.31.3.0 255.255.255.0 172.30.250.0 255.255.255.0 &lt;BR /&gt;access-list inside_nat0_outbound extended permit ip 172.30.2.0 255.255.255.0 172.30.250.0 255.255.255.0 &lt;BR /&gt;access-list inside_nat0_outbound extended permit ip 172.30.0.0 255.255.224.0 172.30.250.0 255.255.255.0 &lt;BR /&gt;access-list inside_nat0_outbound extended permit ip 172.31.1.0 255.255.255.0 172.30.250.0 255.255.255.0 &lt;BR /&gt;access-list inside_nat0_outbound extended permit ip 172.30.4.0 255.255.255.128 host 192.168.12.166 &lt;BR /&gt;access-list inside_nat0_outbound extended permit object-group DM_INLINE_PROTOCOL_1 object-group DM_INLINE_NETWORK_2 object-group DM_INLINE_NETWORK_3 inactive &lt;BR /&gt;access-list inside_nat0_outbound extended permit ip object-group DM_INLINE_NETWORK_1 host 10.1.1.243 &lt;BR /&gt;access-list inside_nat0_outbound extended permit object-group DM_INLINE_PROTOCOL_3 object-group DM_INLINE_NETWORK_4 object-group DM_INLINE_NETWORK_6 &lt;BR /&gt;access-list TGA-Split_splitTunnelAcl standard permit 172.30.1.0 255.255.255.0 &lt;BR /&gt;access-list TGA-Split_splitTunnelAcl standard permit 172.31.2.0 255.255.255.0 &lt;BR /&gt;access-list TGA-Split_splitTunnelAcl standard permit 172.31.0.0 255.255.255.0 &lt;BR /&gt;access-list TGA-Split_splitTunnelAcl standard permit 172.31.3.0 255.255.255.0 &lt;BR /&gt;access-list TGA-Split_splitTunnelAcl standard permit 172.30.2.0 255.255.255.0 &lt;BR /&gt;access-list TGA-Split_splitTunnelAcl standard permit 172.31.4.0 255.255.255.0 &lt;BR /&gt;access-list TGA-Split_splitTunnelAcl standard permit 172.30.4.0 255.255.255.0 &lt;BR /&gt;access-list TGA-Split_splitTunnelAcl standard permit 172.31.1.0 255.255.255.0 &lt;BR /&gt;access-list outside_1_cryptomap extended permit ip object-group DM_INLINE_NETWORK_1 host 10.1.1.243 &lt;BR /&gt;access-list outside_cryptomap_1 extended permit ip 172.30.1.0 255.255.255.224 192.168.0.0 255.255.255.0 &lt;BR /&gt;access-list outside_3_cryptomap extended permit ip 172.30.4.0 255.255.255.128 host 192.168.12.166 &lt;BR /&gt;access-list outside_cryptomap extended permit ip host 172.31.1.112 host A-10.3.3.7 &lt;BR /&gt;access-list outside_cryptomap extended permit ip 172.30.1.0 255.255.255.224 192.168.0.0 255.255.255.0 &lt;BR /&gt;access-list outside_cryptomap extended permit ip host 172.31.1.12 host A-10.3.3.7 &lt;BR /&gt;access-list outside_nat0_outbound extended permit object-group DM_INLINE_PROTOCOL_2 CDX 255.255.255.0 host 172.31.1.12 &lt;BR /&gt;access-list nonat extended permit ip host 172.31.1.12 CDX 255.255.255.0 &lt;BR /&gt;pager lines 24&lt;BR /&gt;logging enable&lt;BR /&gt;logging timestamp&lt;BR /&gt;logging buffer-size 100000&lt;BR /&gt;logging asdm informational&lt;BR /&gt;mtu inside 1500&lt;BR /&gt;mtu outside 1500&lt;BR /&gt;ip local pool FPSVPN 172.30.250.1-172.30.250.250 mask 255.255.255.0&lt;BR /&gt;ip local pool VPNTEST2 172.31.100.1-172.31.100.12 mask 255.255.255.0&lt;BR /&gt;icmp unreachable rate-limit 1 burst-size 1&lt;BR /&gt;asdm image disk0:/asdm-621.bin&lt;BR /&gt;no asdm history enable&lt;BR /&gt;arp timeout 14400&lt;BR /&gt;nat-control&lt;BR /&gt;global (outside) 1 interface&lt;BR /&gt;nat (inside) 1 0.0.0.0 0.0.0.0&lt;BR /&gt;static (inside,outside) tcp interface 3389 172.31.1.10 3389 netmask 255.255.255.255 &lt;BR /&gt;static (inside,outside) tcp interface 4012 172.31.1.12 4012 netmask 255.255.255.255 &lt;BR /&gt;static (inside,outside) tcp interface 24 172.31.1.10 24 netmask 255.255.255.255 &lt;BR /&gt;static (inside,outside) tcp interface 5711 192.168.1.200 5711 netmask 255.255.255.255 &lt;BR /&gt;access-group outside in interface outside&lt;BR /&gt;route outside 0.0.0.0 0.0.0.0 68.115.200.145 1&lt;BR /&gt;route inside 10.0.0.0 255.255.255.0 172.30.1.1 1&lt;BR /&gt;route inside 172.30.0.0 255.255.255.0 172.30.1.1 1&lt;BR /&gt;route inside 172.30.2.0 255.255.255.0 172.30.1.1 1&lt;BR /&gt;route inside 172.30.4.0 255.255.255.0 172.30.1.1 1&lt;BR /&gt;route inside 172.30.41.0 255.255.255.0 172.30.1.1 1&lt;BR /&gt;route inside 172.30.42.0 255.255.255.0 172.30.1.1 1&lt;BR /&gt;route inside 172.31.1.0 255.255.255.0 172.30.1.1 1&lt;BR /&gt;route inside 192.168.1.0 255.255.255.0 172.30.1.1 1&lt;BR /&gt;route inside 192.168.100.0 255.255.255.0 172.30.1.1 1&lt;BR /&gt;route inside 0.0.0.0 0.0.0.0 CDX tunneled&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 04 Aug 2010 17:45:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5505-multiple-vpns-not-working/m-p/1492790#M653084</guid>
      <dc:creator>bradkenn75</dc:creator>
      <dc:date>2010-08-04T17:45:23Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5505 multiple VPNs not working</title>
      <link>https://community.cisco.com/t5/network-security/asa-5505-multiple-vpns-not-working/m-p/1492791#M653085</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;please paste the crypto map config&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;but i think i know the issue&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;you probably made different crypto map fo rthe new tunnel and applied it on the interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;so on one interface you can have only 1 crypto map but you can have different entries for that&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;this gives me a feeling you might have more than 1 crypto map&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;outside_1_cryptomap&lt;/P&gt;&lt;P&gt;outside_cryptomap_1&lt;/P&gt;&lt;P&gt;outside_3_cryptomap&lt;/P&gt;&lt;P&gt;outside_cryptomap&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 04 Aug 2010 18:52:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5505-multiple-vpns-not-working/m-p/1492791#M653085</guid>
      <dc:creator>Jitendriya Athavale</dc:creator>
      <dc:date>2010-08-04T18:52:14Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5505 multiple VPNs not working</title>
      <link>https://community.cisco.com/t5/network-security/asa-5505-multiple-vpns-not-working/m-p/1492792#M653086</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;crypto ipsec transform-set ESP-AES-256-MD5 esp-aes-256 esp-md5-hmac&lt;/P&gt;&lt;P&gt;crypto ipsec transform-set ESP-DES-SHA esp-des esp-sha-hmac&lt;/P&gt;&lt;P&gt;crypto ipsec transform-set ESP-DES-MD5 esp-des esp-md5-hmac&lt;/P&gt;&lt;P&gt;crypto ipsec transform-set ESP-AES-192-MD5 esp-aes-192 esp-md5-hmac&lt;/P&gt;&lt;P&gt;crypto ipsec transform-set ESP-3DES-MD5 esp-3des esp-md5-hmac&lt;/P&gt;&lt;P&gt;crypto ipsec transform-set ESP-AES-128-SHA esp-aes esp-sha-hmac&lt;/P&gt;&lt;P&gt;crypto ipsec transform-set ESP-AES-192-SHA esp-aes-192 esp-sha-hmac&lt;/P&gt;&lt;P&gt;crypto ipsec transform-set ESP-AES-128-MD5 esp-aes esp-md5-hmac&lt;/P&gt;&lt;P&gt;crypto ipsec transform-set ESP-AES-256-SHA esp-aes-256 esp-sha-hmac&lt;/P&gt;&lt;P&gt;crypto ipsec transform-set ESP-3DES-SHA esp-3des esp-sha-hmac&lt;/P&gt;&lt;P&gt;crypto ipsec transform-set BasicESP3d esp-3des esp-md5-hmac&lt;/P&gt;&lt;P&gt;crypto ipsec security-association lifetime seconds 28800&lt;/P&gt;&lt;P&gt;crypto ipsec security-association lifetime kilobytes 4608000&lt;/P&gt;&lt;P&gt;crypto dynamic-map SYSTEM_DEFAULT_CRYPTO_MAP 65535 set pfs group1&lt;/P&gt;&lt;P&gt;crypto dynamic-map SYSTEM_DEFAULT_CRYPTO_MAP 65535 set transform-set ESP-AES-128-SHA ESP-AES-128-MD5 ESP-AES-192-SHA ESP-AES-192-MD5 ESP-AES-256-SHA ESP-AES-256-MD5 ESP-3DES-SHA ESP-3DES-MD5 ESP-DES-SHA ESP-DES-MD5&lt;/P&gt;&lt;P&gt;crypto dynamic-map SYSTEM_DEFAULT_CRYPTO_MAP 65535 set security-association lifetime seconds 28800&lt;/P&gt;&lt;P&gt;crypto dynamic-map SYSTEM_DEFAULT_CRYPTO_MAP 65535 set security-association lifetime kilobytes 4608000&lt;/P&gt;&lt;P&gt;crypto map outside_map 1 set peer BlueRidge&lt;/P&gt;&lt;P&gt;crypto map outside_map 1 set transform-set ESP-3DES-SHA&lt;/P&gt;&lt;P&gt;crypto map outside_map 1 set security-association lifetime seconds 28800&lt;/P&gt;&lt;P&gt;crypto map outside_map 1 set security-association lifetime kilobytes 4608000&lt;/P&gt;&lt;P&gt;crypto map outside_map 2 set peer 68.115.234.130&lt;/P&gt;&lt;P&gt;crypto map outside_map 2 set transform-set ESP-AES-128-SHA ESP-AES-128-MD5 ESP-AES-192-SHA ESP-AES-192-MD5 ESP-AES-256-SHA ESP-AES-256-MD5 ESP-3DES-SHA ESP-3DES-MD5 ESP-DES-SHA ESP-DES-MD5&lt;/P&gt;&lt;P&gt;crypto map outside_map 3 set peer 68.191.0.66&lt;/P&gt;&lt;P&gt;crypto map outside_map 3 set transform-set ESP-3DES-SHA&lt;/P&gt;&lt;P&gt;crypto map outside_map 3 set security-association lifetime seconds 28800&lt;/P&gt;&lt;P&gt;crypto map outside_map 3 set security-association lifetime kilobytes 4608000&lt;/P&gt;&lt;P&gt;crypto map outside_map 4 set pfs&lt;/P&gt;&lt;P&gt;crypto map outside_map 4 set peer CDX&lt;/P&gt;&lt;P&gt;crypto map outside_map 4 set transform-set BasicESP3d ESP-3DES-MD5 ESP-3DES-SHA ESP-DES-SHA ESP-DES-MD5&lt;/P&gt;&lt;P&gt;crypto map outside_map 5 match address outside_cryptomap_1&lt;/P&gt;&lt;P&gt;crypto map outside_map 5 set peer BlueRidge&lt;/P&gt;&lt;P&gt;crypto map outside_map 5 set transform-set ESP-AES-128-SHA ESP-AES-128-MD5 ESP-AES-192-SHA ESP-AES-192-MD5 ESP-AES-256-SHA ESP-AES-256-MD5 ESP-3DES-SHA ESP-3DES-MD5 ESP-DES-SHA ESP-DES-MD5&lt;/P&gt;&lt;P&gt;crypto map outside_map 65535 ipsec-isakmp dynamic SYSTEM_DEFAULT_CRYPTO_MAP&lt;/P&gt;&lt;P&gt;crypto map outside_map interface outside&lt;/P&gt;&lt;P&gt;crypto isakmp enable inside&lt;/P&gt;&lt;P&gt;crypto isakmp enable outside&lt;/P&gt;&lt;P&gt;crypto isakmp policy 5&lt;/P&gt;&lt;P&gt; authentication pre-share&lt;/P&gt;&lt;P&gt; encryption aes&lt;/P&gt;&lt;P&gt; hash md5&lt;/P&gt;&lt;P&gt; group 2&lt;/P&gt;&lt;P&gt; lifetime 86400&lt;/P&gt;&lt;P&gt;crypto isakmp policy 6&lt;/P&gt;&lt;P&gt; authentication pre-share&lt;/P&gt;&lt;P&gt; encryption 3des&lt;/P&gt;&lt;P&gt; hash sha&lt;/P&gt;&lt;P&gt; group 2&lt;/P&gt;&lt;P&gt; lifetime 86400&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 04 Aug 2010 18:58:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5505-multiple-vpns-not-working/m-p/1492792#M653086</guid>
      <dc:creator>bradkenn75</dc:creator>
      <dc:date>2010-08-04T18:58:26Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5505 multiple VPNs not working</title>
      <link>https://community.cisco.com/t5/network-security/asa-5505-multiple-vpns-not-working/m-p/1492793#M653087</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;why i do not see any match statements in crypto map for 1,2,3 &amp;amp; 4 ? did you removed any configuration for one posted below ?&lt;/P&gt;&lt;P&gt;From the posted configuration only tunnel with Blue Ridge should be working given you have mirror ACL to indentify interesting traffic on both sides.&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;Manish&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 04 Aug 2010 21:51:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5505-multiple-vpns-not-working/m-p/1492793#M653087</guid>
      <dc:creator>manish arora</dc:creator>
      <dc:date>2010-08-04T21:51:50Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5505 multiple VPNs not working</title>
      <link>https://community.cisco.com/t5/network-security/asa-5505-multiple-vpns-not-working/m-p/1492794#M653088</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I don't know, it's all jacked up.&amp;nbsp; We are seeing other odd behaviour, like configuration changes disappearing after we save them and go back into what was just configured.&amp;nbsp; After posting this, I found out the air condition went out where the equipment is located, and we are suspecting the equipment overheated, as we are seeing some issues with other equipment as well.&amp;nbsp; We are looking into the coverage on this firewall now, and considering alternative solutions.&amp;nbsp; I'm not very experienced on Cisco yet.&amp;nbsp; Can you give me an example of all we should need to have configured for a single tunnel to work, where multiple tunnels exist to access the same internal LAN(s)?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 04 Aug 2010 22:50:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5505-multiple-vpns-not-working/m-p/1492794#M653088</guid>
      <dc:creator>bradkenn75</dc:creator>
      <dc:date>2010-08-04T22:50:58Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5505 multiple VPNs not working</title>
      <link>https://community.cisco.com/t5/network-security/asa-5505-multiple-vpns-not-working/m-p/1492795#M653089</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;what you have is perfectly fine expect one thing which manish mentioned&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;crypto map outside_map 1 set peer BlueRidge&lt;/P&gt;&lt;P&gt;crypto map outside_map 1 set transform-set ESP-3DES-SHA&lt;/P&gt;&lt;P&gt;crypto map outside_map 1 set security-association lifetime seconds 28800&lt;/P&gt;&lt;P&gt;crypto map outside_map 1 set security-association lifetime kilobytes 4608000&lt;/P&gt;&lt;P&gt;crypto map outside_map 2 set peer 68.115.234.130&lt;/P&gt;&lt;P&gt;crypto&amp;nbsp; map outside_map 2 set transform-set ESP-AES-128-SHA ESP-AES-128-MD5&amp;nbsp; ESP-AES-192-SHA ESP-AES-192-MD5 ESP-AES-256-SHA ESP-AES-256-MD5&amp;nbsp; ESP-3DES-SHA ESP-3DES-MD5 ESP-DES-SHA ESP-DES-MD5&lt;/P&gt;&lt;P&gt;crypto map outside_map 3 set peer 68.191.0.66&lt;/P&gt;&lt;P&gt;crypto map outside_map 3 set transform-set ESP-3DES-SHA&lt;/P&gt;&lt;P&gt;crypto map outside_map 3 set security-association lifetime seconds 28800&lt;/P&gt;&lt;P&gt;crypto map outside_map 3 set security-association lifetime kilobytes 4608000&lt;/P&gt;&lt;P&gt;crypto map outside_map 4 set pfs&lt;/P&gt;&lt;P&gt;crypto map outside_map 4 set peer CDX&lt;/P&gt;&lt;P&gt;crypto map outside_map 4 set transform-set BasicESP3d ESP-3DES-MD5 ESP-3DES-SHA ESP-DES-SHA ESP-DES-MD5&lt;/P&gt;&lt;P&gt;crypto map outside_map 5 match address outside_cryptomap_1&lt;/P&gt;&lt;P&gt;crypto map outside_map 5 set peer BlueRidge&lt;/P&gt;&lt;P&gt;crypto&amp;nbsp; map outside_map 5 set transform-set ESP-AES-128-SHA ESP-AES-128-MD5&amp;nbsp; ESP-AES-192-SHA ESP-AES-192-MD5 ESP-AES-256-SHA ESP-AES-256-MD5&amp;nbsp; ESP-3DES-SHA ESP-3DES-MD5 ESP-DES-SHA ESP-DES-MD5&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the above is wht you have&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;see this part&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;crypto map outside_map 5&lt;STRONG&gt; match address&lt;/STRONG&gt; outside_cryptomap_1&lt;/P&gt;&lt;P&gt;crypto map outside_map 5 set peer BlueRidge&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;you have a match address, which is missing in rest of them. so it will always fall on dynamic crypto map which needs the traffic to be inited from the other end&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;all you have to do is hunt for those statemenst and put them&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;match address &lt;ACCESS-LIST&gt;&lt;/ACCESS-LIST&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;this is the format&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;this access-list will have source from your network and destination as remotes vpn network&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Aug 2010 06:23:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5505-multiple-vpns-not-working/m-p/1492795#M653089</guid>
      <dc:creator>Jitendriya Athavale</dc:creator>
      <dc:date>2010-08-05T06:23:44Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5505 multiple VPNs not working</title>
      <link>https://community.cisco.com/t5/network-security/asa-5505-multiple-vpns-not-working/m-p/1492796#M653090</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;okay, we will try adding those this a.m.; other question though, why were we unable to ping across the VPN's when they were showing as&lt;/P&gt;&lt;P&gt;"up" previously, or we cannot ping to the "Blueridge" even though it appears to be correct, right?&amp;nbsp; Also, do you know where we can run the SN# to see if smartnet is on the box?&lt;/P&gt;&lt;P&gt;THANKS!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Aug 2010 12:13:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5505-multiple-vpns-not-working/m-p/1492796#M653090</guid>
      <dc:creator>bradkenn75</dc:creator>
      <dc:date>2010-08-05T12:13:56Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5505 multiple VPNs not working</title>
      <link>https://community.cisco.com/t5/network-security/asa-5505-multiple-vpns-not-working/m-p/1492797#M653091</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;there could be many reason why the tunnel shows up and traffic doesnt pass&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;we need to check with command "sh crypto ips sa" to confirm that the phase 2 is up &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;if it shows up in "show cry isa sa" it means only phase 1 is up&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Aug 2010 12:38:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5505-multiple-vpns-not-working/m-p/1492797#M653091</guid>
      <dc:creator>Jitendriya Athavale</dc:creator>
      <dc:date>2010-08-05T12:38:41Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5505 multiple VPNs not working</title>
      <link>https://community.cisco.com/t5/network-security/asa-5505-multiple-vpns-not-working/m-p/1492798#M653092</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;the results for sh cry isa sa = "there are no isakmp sas"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the results for sh crypto ips sa = "There are no ipsec sas"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Added the "crypto map outside_map 3 match address ..." statements for 1, 2, 3, and 4; still have no tunnels coming up.&amp;nbsp; Thanks! &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Aug 2010 15:14:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5505-multiple-vpns-not-working/m-p/1492798#M653092</guid>
      <dc:creator>bradkenn75</dc:creator>
      <dc:date>2010-08-05T15:14:04Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5505 multiple VPNs not working</title>
      <link>https://community.cisco.com/t5/network-security/asa-5505-multiple-vpns-not-working/m-p/1492799#M653093</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;if you are ok with withclearing all the tunnels&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;if so the remove the crypto map from interafce&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;clear cry isa sa&lt;/P&gt;&lt;P&gt;clear cry ips sa&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and then apply the crypto map again&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Aug 2010 15:41:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5505-multiple-vpns-not-working/m-p/1492799#M653093</guid>
      <dc:creator>Jitendriya Athavale</dc:creator>
      <dc:date>2010-08-05T15:41:50Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5505 multiple VPNs not working</title>
      <link>https://community.cisco.com/t5/network-security/asa-5505-multiple-vpns-not-working/m-p/1492800#M653094</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I figured it may help if you have the overview of the config; I went through and changed all the public addresses we use, for confidentiality purposes.&amp;nbsp; Here is the current:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Result of the command: "sh run"&lt;/P&gt;&lt;P&gt;: Saved&lt;BR /&gt;:&lt;BR /&gt;ASA Version&amp;nbsp; 8.2(1) &lt;BR /&gt;!&lt;BR /&gt;hostname **********&lt;BR /&gt;domain-name site.local&lt;BR /&gt;enable password ********** encrypted&lt;BR /&gt;passwd ************ encrypted&lt;BR /&gt;names&lt;BR /&gt;name 172.30.1.14 BlueRidgeServer description Blue Ridge XRAY&lt;BR /&gt;name 162.114.68.115 BlueRidge&lt;BR /&gt;name 172.30.1.16 Nuclear_Test description Nuclear_testing&lt;BR /&gt;name 200.146.68.115 Public description Public&lt;BR /&gt;name 200.144.68.115 Outside&lt;BR /&gt;name 187.232.66.83 UNG description UNG&lt;BR /&gt;name 151.130.68.115 CardCons. description Cardiology Consultants&lt;BR /&gt;name 10.3.3.0 CelligentCDX description Celligent CDX&lt;BR /&gt;name 97.98.66.49 CDX description CDX&lt;BR /&gt;name 10.3.3.7 A-10.3.3.7 description Celligent&lt;BR /&gt;!&lt;BR /&gt;interface Vlan1&lt;BR /&gt; nameif inside&lt;BR /&gt; security-level 100&lt;BR /&gt; ip address 172.30.1.254 255.255.255.0 &lt;BR /&gt;!&lt;BR /&gt;interface Vlan2&lt;BR /&gt; nameif outside&lt;BR /&gt; security-level 0&lt;BR /&gt; ip address Public 255.255.255.252 &lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/0&lt;BR /&gt; switchport access vlan 2&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/1&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/2&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/3&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/4&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/5&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/6&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/7&lt;BR /&gt;!&lt;BR /&gt;boot system disk0:/asa821-k8.bin&lt;BR /&gt;ftp mode passive&lt;BR /&gt;clock timezone EST -5&lt;BR /&gt;clock summer-time EDT recurring&lt;BR /&gt;dns domain-lookup inside&lt;BR /&gt;dns server-group DefaultDNS&lt;BR /&gt; name-server 172.31.1.10&lt;BR /&gt; domain-name fps.local&lt;BR /&gt;object-group network DM_INLINE_NETWORK_1&lt;BR /&gt; network-object host BlueRidgeServer&lt;BR /&gt;**** network-object host 172.31.1.15&lt;/P&gt;&lt;P&gt;object-group service SSH-ALT tcp&lt;BR /&gt; description SSH-ALT&lt;BR /&gt; port-object eq 24&lt;BR /&gt;object-group network FTP_Access&lt;BR /&gt; description FTP Access&lt;BR /&gt; network-object UNG 255.255.255.248&lt;BR /&gt; network-object host CardCons.&lt;BR /&gt;object-group protocol DM_INLINE_PROTOCOL_1&lt;BR /&gt; protocol-object ip&lt;BR /&gt; protocol-object tcp&lt;BR /&gt; protocol-object icmp&lt;BR /&gt;object-group protocol DM_INLINE_PROTOCOL_2&lt;BR /&gt; protocol-object ip&lt;BR /&gt; protocol-object icmp&lt;BR /&gt; protocol-object udp&lt;BR /&gt; protocol-object tcp&lt;BR /&gt;object-group network DM_INLINE_NETWORK_2&lt;BR /&gt; network-object CelligentCDX 255.255.255.0&lt;BR /&gt; network-object 172.31.1.0 255.255.255.0&lt;BR /&gt;object-group network DM_INLINE_NETWORK_3&lt;BR /&gt; network-object CelligentCDX 255.255.255.0&lt;BR /&gt; network-object 172.31.1.0 255.255.255.0&lt;BR /&gt;object-group protocol TCPUDP&lt;BR /&gt; protocol-object udp&lt;BR /&gt; protocol-object tcp&lt;BR /&gt;object-group service PACS tcp-udp&lt;BR /&gt; description PACS&lt;BR /&gt; port-object eq 104&lt;BR /&gt;access-list outside extended permit icmp any any &lt;BR /&gt;access-list outside extended permit tcp any interface outside eq 3389 &lt;BR /&gt;access-list outside extended permit tcp any interface outside eq 4012 &lt;BR /&gt;access-list outside extended permit tcp object-group FTP_Access interface outside object-group SSH-ALT &lt;BR /&gt;access-list outside extended permit tcp any interface outside eq 5711 &lt;BR /&gt;access-list outside remark SSH-ALT&lt;BR /&gt;access-list outside remark Pharmacy&lt;BR /&gt;access-list inside_nat0_outbound extended permit ip 172.30.1.0 255.255.255.0 172.30.250.0 255.255.255.0 &lt;BR /&gt;access-list inside_nat0_outbound extended permit ip 172.31.2.0 255.255.255.0 172.30.250.0 255.255.255.0 &lt;BR /&gt;access-list inside_nat0_outbound extended permit ip 172.31.0.0 255.255.255.0 172.30.250.0 255.255.255.0 &lt;BR /&gt;access-list inside_nat0_outbound extended permit ip 172.31.3.0 255.255.255.0 172.30.250.0 255.255.255.0 &lt;BR /&gt;access-list inside_nat0_outbound extended permit ip 172.30.2.0 255.255.255.0 172.30.250.0 255.255.255.0 &lt;BR /&gt;access-list inside_nat0_outbound extended permit ip 172.30.0.0 255.255.224.0 172.30.250.0 255.255.255.0 &lt;BR /&gt;access-list inside_nat0_outbound extended permit ip 172.31.1.0 255.255.255.0 172.30.250.0 255.255.255.0 &lt;BR /&gt;access-list inside_nat0_outbound extended permit ip 172.30.4.0 255.255.255.128 host 192.168.12.166 &lt;BR /&gt;access-list inside_nat0_outbound extended permit ip object-group DM_INLINE_NETWORK_1 host 10.1.1.243 &lt;BR /&gt;access-list inside_nat0_outbound extended permit object-group DM_INLINE_PROTOCOL_1 object-group DM_INLINE_NETWORK_2 object-group DM_INLINE_NETWORK_3 &lt;BR /&gt;access-list inside_nat0_outbound extended permit ip 172.30.1.0 255.255.255.224 192.168.0.0 255.255.255.0 &lt;BR /&gt;access-list TGA-Split_splitTunnelAcl standard permit 172.31.1.0 255.255.255.0 &lt;BR /&gt;access-list TGA-Split_splitTunnelAcl standard permit 172.30.1.0 255.255.255.0 &lt;BR /&gt;access-list TGA-Split_splitTunnelAcl standard permit 172.31.2.0 255.255.255.0 &lt;BR /&gt;access-list TGA-Split_splitTunnelAcl standard permit 172.31.0.0 255.255.255.0 &lt;BR /&gt;access-list TGA-Split_splitTunnelAcl standard permit 172.31.3.0 255.255.255.0 &lt;BR /&gt;access-list TGA-Split_splitTunnelAcl standard permit 172.30.2.0 255.255.255.0 &lt;BR /&gt;access-list TGA-Split_splitTunnelAcl standard permit 172.31.4.0 255.255.255.0 &lt;BR /&gt;access-list TGA-Split_splitTunnelAcl standard permit 172.30.4.0 255.255.255.0 &lt;BR /&gt;access-list outside_1_cryptomap extended permit ip object-group DM_INLINE_NETWORK_1 host 10.1.1.243 &lt;BR /&gt;access-list outside_3_cryptomap extended permit ip 172.30.4.0 255.255.255.128 host 192.168.12.166 &lt;BR /&gt;access-list outside_cryptomap extended permit ip host 172.31.1.12 host A-10.3.3.7 &lt;BR /&gt;access-list outside_cryptomap extended permit ip 172.30.1.0 255.255.255.224 192.168.0.0 255.255.255.0 &lt;BR /&gt;access-list outside_nat0_outbound extended permit object-group DM_INLINE_PROTOCOL_2 CelligentCDX 255.255.255.0 172.31.1.0 255.255.255.0 &lt;BR /&gt;access-list nonat extended permit ip 172.31.1.0 255.255.255.0 CelligentCDX 255.255.255.0 &lt;BR /&gt;access-list outside_cryptomap_1 extended permit ip host BlueRidgeServer 192.168.0.0 255.255.255.0 &lt;BR /&gt;pager lines 24&lt;BR /&gt;logging enable&lt;BR /&gt;logging timestamp&lt;BR /&gt;logging buffer-size 100000&lt;BR /&gt;logging asdm informational&lt;BR /&gt;mtu inside 1500&lt;BR /&gt;mtu outside 1500&lt;BR /&gt;ip local pool FPSVPN 172.30.250.1-172.30.250.250 mask 255.255.255.0&lt;BR /&gt;ip local pool VPNTEST2 172.31.100.1-172.31.100.12 mask 255.255.255.0&lt;BR /&gt;icmp unreachable rate-limit 1 burst-size 1&lt;BR /&gt;asdm image disk0:/asdm-621.bin&lt;BR /&gt;no asdm history enable&lt;BR /&gt;arp timeout 14400&lt;BR /&gt;nat-control&lt;BR /&gt;global (outside) 1 interface&lt;BR /&gt;nat (inside) 1 0.0.0.0 0.0.0.0&lt;BR /&gt;static (inside,outside) tcp interface 3389 172.31.1.10 3389 netmask 255.255.255.255 &lt;BR /&gt;static (inside,outside) tcp interface 4012 172.31.1.12 4012 netmask 255.255.255.255 &lt;BR /&gt;static (inside,outside) tcp interface 24 172.31.1.10 24 netmask 255.255.255.255 &lt;BR /&gt;static (inside,outside) tcp interface 5711 192.168.1.200 5711 netmask 255.255.255.255 &lt;BR /&gt;route outside 0.0.0.0 0.0.0.0 68.115.200.145 1&lt;BR /&gt;route inside 10.0.0.0 255.255.255.0 172.30.1.1 1&lt;BR /&gt;route inside 172.30.0.0 255.255.255.0 172.30.1.1 1&lt;BR /&gt;route inside 172.30.2.0 255.255.255.0 172.30.1.1 1&lt;BR /&gt;route inside 172.30.4.0 255.255.255.0 172.30.1.1 1&lt;BR /&gt;route inside 172.30.41.0 255.255.255.0 172.30.1.1 1&lt;BR /&gt;route inside 172.30.42.0 255.255.255.0 172.30.1.1 1&lt;BR /&gt;route inside 172.31.1.0 255.255.255.0 172.30.1.1 1&lt;BR /&gt;route inside 192.168.1.0 255.255.255.0 172.30.1.1 1&lt;BR /&gt;route inside 192.168.100.0 255.255.255.0 172.30.1.1 1&lt;BR /&gt;route inside 0.0.0.0 0.0.0.0 CDX tunneled&lt;BR /&gt;timeout xlate 3:00:00&lt;BR /&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02&lt;BR /&gt;timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00&lt;BR /&gt;timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00&lt;BR /&gt;timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute&lt;BR /&gt;timeout tcp-proxy-reassembly 0:01:00&lt;BR /&gt;dynamic-access-policy-record DfltAccessPolicy&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;snmp-server community *****&lt;BR /&gt;snmp-server enable traps snmp authentication linkup linkdown coldstart&lt;BR /&gt;crypto ipsec transform-set ESP-AES-256-MD5 esp-aes-256 esp-md5-hmac &lt;BR /&gt;crypto ipsec transform-set ESP-DES-SHA esp-des esp-sha-hmac &lt;BR /&gt;crypto ipsec transform-set ESP-DES-MD5 esp-des esp-md5-hmac &lt;BR /&gt;crypto ipsec transform-set ESP-AES-192-MD5 esp-aes-192 esp-md5-hmac &lt;BR /&gt;crypto ipsec transform-set ESP-3DES-MD5 esp-3des esp-md5-hmac &lt;BR /&gt;crypto ipsec transform-set ESP-AES-128-SHA esp-aes esp-sha-hmac &lt;BR /&gt;crypto ipsec transform-set ESP-AES-192-SHA esp-aes-192 esp-sha-hmac &lt;BR /&gt;crypto ipsec transform-set ESP-AES-128-MD5 esp-aes esp-md5-hmac &lt;BR /&gt;crypto ipsec transform-set ESP-AES-256-SHA esp-aes-256 esp-sha-hmac &lt;BR /&gt;crypto ipsec transform-set ESP-3DES-SHA esp-3des esp-sha-hmac &lt;BR /&gt;crypto ipsec transform-set BasicESP3d esp-3des esp-md5-hmac &lt;BR /&gt;crypto ipsec security-association lifetime seconds 28800&lt;BR /&gt;crypto ipsec security-association lifetime kilobytes 4608000&lt;BR /&gt;crypto dynamic-map SYSTEM_DEFAULT_CRYPTO_MAP 65535 set pfs group1&lt;BR /&gt;crypto dynamic-map SYSTEM_DEFAULT_CRYPTO_MAP 65535 set transform-set ESP-AES-128-SHA ESP-AES-128-MD5 ESP-AES-192-SHA ESP-AES-192-MD5 ESP-AES-256-SHA ESP-AES-256-MD5 ESP-3DES-SHA ESP-3DES-MD5 ESP-DES-SHA ESP-DES-MD5&lt;BR /&gt;crypto dynamic-map SYSTEM_DEFAULT_CRYPTO_MAP 65535 set security-association lifetime seconds 28800&lt;BR /&gt;crypto dynamic-map SYSTEM_DEFAULT_CRYPTO_MAP 65535 set security-association lifetime kilobytes 4608000&lt;BR /&gt;crypto map outside_map 1 match address outside_1_cryptomap&lt;BR /&gt;crypto map outside_map 1 set peer BlueRidge &lt;BR /&gt;crypto map outside_map 1 set transform-set ESP-3DES-SHA&lt;BR /&gt;crypto map outside_map 1 set security-association lifetime seconds 28800&lt;BR /&gt;crypto map outside_map 1 set security-association lifetime kilobytes 4608000&lt;BR /&gt;crypto map outside_map 2 match address outside_cryptomap_1&lt;BR /&gt;crypto map outside_map 2 set peer 234.130.68.115 &lt;BR /&gt;crypto map outside_map 2 set transform-set ESP-AES-128-SHA ESP-AES-128-MD5 ESP-AES-192-SHA ESP-AES-192-MD5 ESP-AES-256-SHA ESP-AES-256-MD5 ESP-3DES-SHA ESP-3DES-MD5 ESP-DES-SHA ESP-DES-MD5&lt;BR /&gt;crypto map outside_map 3 match address outside_3_cryptomap&lt;BR /&gt;crypto map outside_map 3 set peer 110.66.68.191 &lt;BR /&gt;crypto map outside_map 3 set transform-set ESP-3DES-SHA&lt;BR /&gt;crypto map outside_map 3 set security-association lifetime seconds 28800&lt;BR /&gt;crypto map outside_map 3 set security-association lifetime kilobytes 4608000&lt;BR /&gt;crypto map outside_map 4 match address outside_cryptomap&lt;BR /&gt;crypto map outside_map 4 set pfs &lt;BR /&gt;crypto map outside_map 4 set peer CDX &lt;BR /&gt;crypto map outside_map 4 set transform-set BasicESP3d ESP-3DES-MD5 ESP-3DES-SHA ESP-DES-SHA ESP-DES-MD5&lt;BR /&gt;crypto map outside_map 65535 ipsec-isakmp dynamic SYSTEM_DEFAULT_CRYPTO_MAP&lt;BR /&gt;crypto map outside_map interface outside&lt;BR /&gt;crypto isakmp enable inside&lt;BR /&gt;crypto isakmp enable outside&lt;BR /&gt;crypto isakmp policy 5&lt;BR /&gt; authentication pre-share&lt;BR /&gt; encryption aes&lt;BR /&gt; hash md5&lt;BR /&gt; group 2&lt;BR /&gt; lifetime 86400&lt;BR /&gt;crypto isakmp policy 6&lt;BR /&gt; authentication pre-share&lt;BR /&gt; encryption 3des&lt;BR /&gt; hash sha&lt;BR /&gt; group 2&lt;BR /&gt; lifetime 86400&lt;BR /&gt;telnet 172.30.0.0 255.255.0.0 inside&lt;BR /&gt;telnet timeout 5&lt;BR /&gt;ssh 110.64.68.191 255.255.255.224 outside&lt;BR /&gt;ssh timeout 5&lt;BR /&gt;console timeout 0&lt;BR /&gt;dhcpd auto_config outside&lt;BR /&gt;!&lt;/P&gt;&lt;P&gt;threat-detection basic-threat&lt;BR /&gt;threat-detection statistics port&lt;BR /&gt;threat-detection statistics protocol&lt;BR /&gt;threat-detection statistics access-list&lt;BR /&gt;threat-detection statistics tcp-intercept rate-interval 30 burst-rate 400 average-rate 200&lt;BR /&gt;ntp authenticate&lt;BR /&gt;ntp server 192.5.41.40 source inside&lt;BR /&gt;ntp server 172.31.1.10 source inside prefer&lt;BR /&gt;webvpn&lt;BR /&gt; enable inside&lt;BR /&gt; enable outside&lt;BR /&gt; svc image disk0:/anyconnect-win-2.3.0254-k9.pkg 1&lt;BR /&gt; svc enable&lt;BR /&gt; tunnel-group-list enable&lt;BR /&gt;group-policy DfltGrpPolicy attributes&lt;BR /&gt; vpn-tunnel-protocol IPSec l2tp-ipsec &lt;BR /&gt;group-policy TGA-Split internal&lt;BR /&gt;group-policy TGA-Split attributes&lt;BR /&gt; dns-server value ****&lt;BR /&gt; vpn-tunnel-protocol IPSec &lt;BR /&gt; split-tunnel-policy tunnelspecified&lt;BR /&gt; split-tunnel-network-list value TGA-Split_splitTunnelAcl&lt;BR /&gt;group-policy FPSVPN internal&lt;BR /&gt;group-policy FPSVPN attributes&lt;BR /&gt; dns-server value **********&lt;BR /&gt; vpn-tunnel-protocol IPSec &lt;BR /&gt;group-policy remotetest internal&lt;BR /&gt;group-policy remotetest attributes&lt;BR /&gt; dns-server value **********&lt;BR /&gt; vpn-tunnel-protocol IPSec &lt;BR /&gt;group-policy Physician-Portal internal&lt;BR /&gt;group-policy Physician-Portal attributes&lt;BR /&gt; vpn-simultaneous-logins 10&lt;BR /&gt; vpn-tunnel-protocol svc webvpn&lt;BR /&gt; webvpn&lt;BR /&gt;&amp;nbsp; url-list value Physician-Portal&lt;BR /&gt;&amp;nbsp; customization value Physician-Portal&lt;BR /&gt;&amp;nbsp; hidden-shares visible&lt;BR /&gt;&amp;nbsp; file-entry enable&lt;BR /&gt;&amp;nbsp; file-browsing enable&lt;BR /&gt;&amp;nbsp; url-entry enable&lt;BR /&gt;group-policy CDX internal&lt;BR /&gt;group-policy CDX attributes&lt;BR /&gt; vpn-filter none&lt;BR /&gt; vpn-tunnel-protocol IPSec&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;tunnel-group FPSVPN type remote-access&lt;BR /&gt;tunnel-group FPSVPN general-attributes&lt;BR /&gt; address-pool FPSVPN&lt;BR /&gt; default-group-policy FPSVPN&lt;BR /&gt;tunnel-group FPSVPN ipsec-attributes&lt;BR /&gt; pre-shared-key *&lt;BR /&gt;tunnel-group TGA-Split type remote-access&lt;BR /&gt;tunnel-group TGA-Split general-attributes&lt;BR /&gt; address-pool FPSVPN&lt;BR /&gt; default-group-policy TGA-Split&lt;BR /&gt;tunnel-group TGA-Split ipsec-attributes&lt;BR /&gt; pre-shared-key *&lt;BR /&gt;tunnel-group remotetest type remote-access&lt;BR /&gt;tunnel-group remotetest general-attributes&lt;BR /&gt; address-pool VPNTEST2&lt;BR /&gt; default-group-policy remotetest&lt;BR /&gt;tunnel-group remotetest ipsec-attributes&lt;BR /&gt; pre-shared-key *&lt;BR /&gt;tunnel-group 162.114.68.115 type ipsec-l2l&lt;BR /&gt;tunnel-group 162.114.68.115 ipsec-attributes&lt;BR /&gt; pre-shared-key *&lt;BR /&gt;tunnel-group 234.130.68.115 type ipsec-l2l&lt;BR /&gt;tunnel-group 234.130.68.115 ipsec-attributes&lt;BR /&gt; pre-shared-key *&lt;BR /&gt;tunnel-group Physician-Portal type remote-access&lt;BR /&gt;tunnel-group Physician-Portal general-attributes&lt;BR /&gt; address-pool FPSVPN&lt;BR /&gt; default-group-policy Physician-Portal&lt;BR /&gt;tunnel-group Physician-Portal webvpn-attributes&lt;BR /&gt; customization Physician-Portal&lt;BR /&gt; nbns-server 172.31.1.10 timeout 2 retry 2&lt;BR /&gt; group-alias Physician-Portal enable&lt;BR /&gt;tunnel-group 97.98.66.49 type ipsec-l2l&lt;BR /&gt;tunnel-group 97.98.66.49 general-attributes&lt;BR /&gt; default-group-policy CDX&lt;BR /&gt;tunnel-group 97.98.66.49 ipsec-attributes&lt;BR /&gt; pre-shared-key *&lt;BR /&gt; peer-id-validate nocheck&lt;BR /&gt;!&lt;BR /&gt;class-map inspection_default&lt;BR /&gt; match default-inspection-traffic&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;policy-map type inspect dns preset_dns_map&lt;BR /&gt; parameters&lt;BR /&gt;&amp;nbsp; message-length maximum 512&lt;BR /&gt;policy-map global_policy&lt;BR /&gt; class inspection_default&lt;BR /&gt;&amp;nbsp; inspect dns preset_dns_map &lt;BR /&gt;&amp;nbsp; inspect ftp &lt;BR /&gt;&amp;nbsp; inspect h323 h225 &lt;BR /&gt;&amp;nbsp; inspect h323 ras &lt;BR /&gt;&amp;nbsp; inspect rsh &lt;BR /&gt;&amp;nbsp; inspect rtsp &lt;BR /&gt;&amp;nbsp; inspect esmtp &lt;BR /&gt;&amp;nbsp; inspect sqlnet &lt;BR /&gt;&amp;nbsp; inspect skinny&amp;nbsp; &lt;BR /&gt;&amp;nbsp; inspect sunrpc &lt;BR /&gt;&amp;nbsp; inspect xdmcp &lt;BR /&gt;&amp;nbsp; inspect sip&amp;nbsp; &lt;BR /&gt;&amp;nbsp; inspect netbios &lt;BR /&gt;&amp;nbsp; inspect tftp &lt;BR /&gt;!&lt;BR /&gt;service-policy global_policy global&lt;BR /&gt;prompt hostname context &lt;BR /&gt;Cryptochecksum:************&lt;BR /&gt;: end&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Aug 2010 16:07:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5505-multiple-vpns-not-working/m-p/1492800#M653094</guid>
      <dc:creator>bradkenn75</dc:creator>
      <dc:date>2010-08-05T16:07:14Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5505 multiple VPNs not working</title>
      <link>https://community.cisco.com/t5/network-security/asa-5505-multiple-vpns-not-working/m-p/1492801#M653095</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I ran these, "clear cry isa sa" / "clear cry ips sa" also, and the "crypto map" statements are still in the config. (in "sh run")&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Aug 2010 19:19:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5505-multiple-vpns-not-working/m-p/1492801#M653095</guid>
      <dc:creator>bradkenn75</dc:creator>
      <dc:date>2010-08-05T19:19:25Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5505 multiple VPNs not working</title>
      <link>https://community.cisco.com/t5/network-security/asa-5505-multiple-vpns-not-working/m-p/1492802#M653096</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you configure "management-access inside" on the firewall and then try to ping the inside interface from a remote location?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;NT&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 06 Aug 2010 00:19:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5505-multiple-vpns-not-working/m-p/1492802#M653096</guid>
      <dc:creator>Nagaraja Thanthry</dc:creator>
      <dc:date>2010-08-06T00:19:18Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5505 multiple VPNs not working</title>
      <link>https://community.cisco.com/t5/network-security/asa-5505-multiple-vpns-not-working/m-p/1492803#M653097</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Your are also missing the nat exempt statement i believe in your sh run.Also, you have a lot of access lists identifying traffic that should not get NAT.&lt;/P&gt;&lt;P&gt;try&lt;/P&gt;&lt;P&gt;nat (inside) 0 access-list inside_nat0_outside&lt;/P&gt;&lt;P&gt;then try pinging the ip address ( private ) that are associated with it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Manish&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 06 Aug 2010 00:44:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5505-multiple-vpns-not-working/m-p/1492803#M653097</guid>
      <dc:creator>manish arora</dc:creator>
      <dc:date>2010-08-06T00:44:56Z</dc:date>
    </item>
  </channel>
</rss>

