<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: problem in asa vpn between 2 branches in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/problem-in-asa-vpn-between-2-branches/m-p/3812362#M6771</link>
    <description>The problem was back again and the sniffer inside of asa was the error message,&lt;BR /&gt;The message: Asymmetric NAT&lt;BR /&gt;" %ASA-5-305013: Asymmetric NAT rules matched for forward and reverse&lt;BR /&gt;flows; Connection protocol src interface_name:source_address/source_port [(idfw_user)] dst interface_name:dst_address/dst_port [(idfw_user)] denied due to&lt;BR /&gt;NAT reverse path failure."&lt;BR /&gt;Can you help me again&lt;BR /&gt;</description>
    <pubDate>Fri, 01 Mar 2019 09:10:02 GMT</pubDate>
    <dc:creator>hunterman</dc:creator>
    <dc:date>2019-03-01T09:10:02Z</dc:date>
    <item>
      <title>problem in asa vpn between 2 branches</title>
      <link>https://community.cisco.com/t5/network-security/problem-in-asa-vpn-between-2-branches/m-p/3809735#M6753</link>
      <description>&lt;P&gt;Hello everyone, I have 2 branches connected by vpn with ASA cisco firewall "5506 x and 5526 x", setup with branches voip server Asterisk server,all configure as well working, The ip phone's calling in branch 1 as well and the audio working fine as local between ip phone's, The ip phone's calling in branch 2 as well and the audio working fine as local between ip phone's, when i calling between 2 branches with used vpn by asa, The extension can call between 2 branches from 2 way but the problem was in branch 1 can make hear audio from extension in branch 2 BUT branch 2 can't hear the branch 1 and the same time can talking (the extension can hear directly from extension in branch 2)? I search in google and found the problem in RTP in asa how can solve the problem? Any help&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 16:51:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-in-asa-vpn-between-2-branches/m-p/3809735#M6753</guid>
      <dc:creator>hunterman</dc:creator>
      <dc:date>2020-02-21T16:51:56Z</dc:date>
    </item>
    <item>
      <title>Re: problem in asa vpn between 2 branches</title>
      <link>https://community.cisco.com/t5/network-security/problem-in-asa-vpn-between-2-branches/m-p/3809781#M6754</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;One way Voice is normally a routing issue, Please check both the voice subnets are allowed on the interesting traffic of VPN.&lt;BR /&gt;If you allowed all these subnets then Try disabling SIP inspection and check.&lt;BR /&gt;&lt;EM&gt;policy-map global_policy&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;class inspection_default&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;no inspect sip&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;HTH&lt;BR /&gt;Abheesh&lt;/P&gt;</description>
      <pubDate>Tue, 26 Feb 2019 10:19:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-in-asa-vpn-between-2-branches/m-p/3809781#M6754</guid>
      <dc:creator>Abheesh Kumar</dc:creator>
      <dc:date>2019-02-26T10:19:36Z</dc:date>
    </item>
    <item>
      <title>Re: problem in asa vpn between 2 branches</title>
      <link>https://community.cisco.com/t5/network-security/problem-in-asa-vpn-between-2-branches/m-p/3810523#M6756</link>
      <description>&lt;P&gt;Thank you for your replay&lt;/P&gt;&lt;P&gt;I'm checked in ASA and already we don't have SIP inspect&amp;nbsp; "no SIP inspect", And checked the all subnets was corrected and the 2 branches was reachable, IF you know that the ping between the 2 branches it's working and http and other services it's worked but only the problem in voip,&lt;/P&gt;&lt;P&gt;Any advice and help&lt;/P&gt;&lt;P&gt;THANKS&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Feb 2019 05:37:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-in-asa-vpn-between-2-branches/m-p/3810523#M6756</guid>
      <dc:creator>hunterman</dc:creator>
      <dc:date>2019-02-27T05:37:17Z</dc:date>
    </item>
    <item>
      <title>Re: problem in asa vpn between 2 branches</title>
      <link>https://community.cisco.com/t5/network-security/problem-in-asa-vpn-between-2-branches/m-p/3810602#M6758</link>
      <description>&lt;P&gt;So if you are saying you can route between phones by means of pinging between phones. Then as a test open up all high udp rtp ports between the two phones and test again.&amp;nbsp; I would suggest to turn sip inspection on. Unless you have a good reason not to.&lt;/P&gt;</description>
      <pubDate>Wed, 27 Feb 2019 07:48:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-in-asa-vpn-between-2-branches/m-p/3810602#M6758</guid>
      <dc:creator>Dennis Mink</dc:creator>
      <dc:date>2019-02-27T07:48:56Z</dc:date>
    </item>
    <item>
      <title>Re: problem in asa vpn between 2 branches</title>
      <link>https://community.cisco.com/t5/network-security/problem-in-asa-vpn-between-2-branches/m-p/3810716#M6759</link>
      <description>I'm checked in ASA and capture the photo below to see the problem and how can resolve that, You can see the photo after the replay comment.&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Wed, 27 Feb 2019 10:26:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-in-asa-vpn-between-2-branches/m-p/3810716#M6759</guid>
      <dc:creator>hunterman</dc:creator>
      <dc:date>2019-02-27T10:26:53Z</dc:date>
    </item>
    <item>
      <title>Re: problem in asa vpn between 2 branches</title>
      <link>https://community.cisco.com/t5/network-security/problem-in-asa-vpn-between-2-branches/m-p/3810720#M6761</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="voip2019.PNG" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/31039iEA906621E1917853/image-size/large?v=v2&amp;amp;px=999" role="button" title="voip2019.PNG" alt="voip2019.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Feb 2019 10:28:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-in-asa-vpn-between-2-branches/m-p/3810720#M6761</guid>
      <dc:creator>hunterman</dc:creator>
      <dc:date>2019-02-27T10:28:44Z</dc:date>
    </item>
    <item>
      <title>Re: problem in asa vpn between 2 branches</title>
      <link>https://community.cisco.com/t5/network-security/problem-in-asa-vpn-between-2-branches/m-p/3810723#M6762</link>
      <description />
      <pubDate>Wed, 27 Feb 2019 10:30:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-in-asa-vpn-between-2-branches/m-p/3810723#M6762</guid>
      <dc:creator>hunterman</dc:creator>
      <dc:date>2019-02-27T10:30:59Z</dc:date>
    </item>
    <item>
      <title>Re: problem in asa vpn between 2 branches</title>
      <link>https://community.cisco.com/t5/network-security/problem-in-asa-vpn-between-2-branches/m-p/3810725#M6765</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;%ASA-5-305013: Asymmetric NAT rules matched for forward and reverse&lt;/P&gt;&lt;P&gt;flows; Connection &lt;EM&gt;protocol&lt;/EM&gt; src &lt;EM&gt;interface_name&lt;/EM&gt;:&lt;EM&gt;source_address&lt;/EM&gt;/&lt;EM&gt;source_port &lt;/EM&gt;[(&lt;EM&gt;idfw_user&lt;/EM&gt;)] dst &lt;EM&gt;interface_name&lt;/EM&gt;:&lt;EM&gt;dst_address&lt;/EM&gt;/&lt;EM&gt;dst_port &lt;/EM&gt;[(&lt;EM&gt;idfw_user&lt;/EM&gt;)] denied due to&lt;/P&gt;&lt;P&gt;NAT reverse path failure.&lt;/P&gt;&lt;P&gt;An attempt to connect to a mapped host using its actual address was rejected.&lt;/P&gt;</description>
      <pubDate>Wed, 27 Feb 2019 10:31:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-in-asa-vpn-between-2-branches/m-p/3810725#M6765</guid>
      <dc:creator>hunterman</dc:creator>
      <dc:date>2019-02-27T10:31:51Z</dc:date>
    </item>
    <item>
      <title>Re: problem in asa vpn between 2 branches</title>
      <link>https://community.cisco.com/t5/network-security/problem-in-asa-vpn-between-2-branches/m-p/3811608#M6767</link>
      <description>Dear Dennis Mink,&lt;BR /&gt;After i checked more than times, I'm solved the problem with your method, The solving when i added SIP inspection and enabled it in ASA firewall the call between 2 branches was working fine from 2 way. and the audio was working between them,&lt;BR /&gt;Thank you for your helping me.&lt;BR /&gt;I will rate your answer&lt;BR /&gt;</description>
      <pubDate>Thu, 28 Feb 2019 10:37:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-in-asa-vpn-between-2-branches/m-p/3811608#M6767</guid>
      <dc:creator>hunterman</dc:creator>
      <dc:date>2019-02-28T10:37:41Z</dc:date>
    </item>
    <item>
      <title>Re: problem in asa vpn between 2 branches</title>
      <link>https://community.cisco.com/t5/network-security/problem-in-asa-vpn-between-2-branches/m-p/3811662#M6769</link>
      <description>&lt;P&gt;no problem, you can mark the comment as the solution.&amp;nbsp; good to hear&lt;/P&gt;</description>
      <pubDate>Thu, 28 Feb 2019 11:57:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-in-asa-vpn-between-2-branches/m-p/3811662#M6769</guid>
      <dc:creator>Dennis Mink</dc:creator>
      <dc:date>2019-02-28T11:57:03Z</dc:date>
    </item>
    <item>
      <title>Re: problem in asa vpn between 2 branches</title>
      <link>https://community.cisco.com/t5/network-security/problem-in-asa-vpn-between-2-branches/m-p/3812362#M6771</link>
      <description>The problem was back again and the sniffer inside of asa was the error message,&lt;BR /&gt;The message: Asymmetric NAT&lt;BR /&gt;" %ASA-5-305013: Asymmetric NAT rules matched for forward and reverse&lt;BR /&gt;flows; Connection protocol src interface_name:source_address/source_port [(idfw_user)] dst interface_name:dst_address/dst_port [(idfw_user)] denied due to&lt;BR /&gt;NAT reverse path failure."&lt;BR /&gt;Can you help me again&lt;BR /&gt;</description>
      <pubDate>Fri, 01 Mar 2019 09:10:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-in-asa-vpn-between-2-branches/m-p/3812362#M6771</guid>
      <dc:creator>hunterman</dc:creator>
      <dc:date>2019-03-01T09:10:02Z</dc:date>
    </item>
  </channel>
</rss>

