<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA problem with IPSEC VPN data not passing in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-problem-with-ipsec-vpn-data-not-passing/m-p/1422768#M713012</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have checked and there is no personal firewall on end device as one of the device is pinging.&lt;/P&gt;&lt;P&gt;Second thing if data is passing i should get hits in ACL but i am not getting any hits, what can be the reason for&amp;nbsp; that.&lt;/P&gt;&lt;P&gt;The end device are not client PC they are some node which send collection data from equipment to server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What can be the reason for not getting ACL hits i am running code 7.2(4) in ASA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 26 Apr 2010 14:40:21 GMT</pubDate>
    <dc:creator>rupam_chakra1983</dc:creator>
    <dc:date>2010-04-26T14:40:21Z</dc:date>
    <item>
      <title>ASA problem with IPSEC VPN data not passing</title>
      <link>https://community.cisco.com/t5/network-security/asa-problem-with-ipsec-vpn-data-not-passing/m-p/1422756#M712863</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am facing a starnge problem .&lt;/P&gt;&lt;P&gt;I have attached the diagram that i could make best.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now problem is that:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can ping from 172.16.15.0 &amp;gt; 10.10.16.0/24( all the IP address)&lt;/P&gt;&lt;P&gt;I can ping from 172.16.15.0(any ip) &amp;gt; 10.10.16.22 ( single ip pass )&lt;/P&gt;&lt;P&gt;I can ping from 172.16.15.0(any ip) &amp;gt; 10.10.16.X ( all other ip except .22 fails )&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I tried extended ping from router interface ip : 10.10.16.254 ( secondary ) to 172.16.15.0 ( all ip) and it is success.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The configuration and ACL ( Both side) seems to be ok, VPN Tunnel is also up thats why the data is passing and pinging.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also we found that there are ACL hits in the router, But there is no ACL hits in the ASA ,also there is no duplicate ACL so there is no chance of hitting any other ACL.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also single inteface in the router has been used for LAN as well as WAN and WAN connectivity is via wireless(ISP)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Plz find the config as below , As i can't share all the config and VPN details i am partially sharing the required one.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Router:&lt;BR /&gt;------------------ show version ------------------&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cisco IOS Software, 1841 Software (C1841-ADVIPSERVICESK9-M), Version 12.4(15)T10&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; , RELEASE SOFTWARE (fc3)&lt;BR /&gt;&lt;SPAN&gt;Technical Support: &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/techsupport" target="_blank"&gt;http://www.cisco.com/techsupport&lt;/A&gt;&lt;BR /&gt;Copyright (c) 1986-2009 by Cisco Systems, Inc.&lt;BR /&gt;Compiled Mon 14-Sep-09 12:48 by prod_rel_team&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ROM: System Bootstrap, Version 12.4(13r)T, RELEASE SOFTWARE (fc1)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;SUZSOUTH-BGHALLI_WTG-TATANET uptime is 1 hour, 29 minutes&lt;BR /&gt;System returned to ROM by power-on&lt;BR /&gt;System image file is "flash:c1841-advipservicesk9-mz.124-15.T10.bin"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;This product contains cryptographic features and is subject to United&lt;BR /&gt;States and local country laws governing import, export, transfer and&lt;BR /&gt;use. Delivery of Cisco cryptographic products does not imply&lt;BR /&gt;third-party authority to import, export, distribute or use encryption.&lt;BR /&gt;Importers, exporters, distributors and users are responsible for&lt;BR /&gt;compliance with U.S. and local country laws. By using this product you&lt;BR /&gt;agree to comply with applicable laws and regulations. If you are unable&lt;BR /&gt;to comply with U.S. and local laws, return this product immediately.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;A summary of U.S. laws governing Cisco cryptographic products may be found at:&lt;BR /&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/wwl/export/crypto/tool/stqrg.html" target="_blank"&gt;http://www.cisco.com/wwl/export/crypto/tool/stqrg.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you require further assistance please contact us by sending email to&lt;BR /&gt;&lt;A class="jive-link-email-small" href="mailto:export@cisco.com" target="_blank"&gt;export@cisco.com&lt;/A&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cisco 1841 (revision 7.0) with 236544K/25600K bytes of memory.&lt;BR /&gt;Processor board ID FHK135270VD&lt;BR /&gt;2 FastEthernet interfaces&lt;BR /&gt;2 Virtual Private Network (VPN) Modules&lt;BR /&gt;DRAM configuration is 64 bits wide with parity disabled.&lt;BR /&gt;191K bytes of NVRAM.&lt;BR /&gt;62720K bytes of ATA CompactFlash (Read/Write)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Configuration register is 0x2102&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface FastEthernet0/1&lt;BR /&gt; ip address 10.10.16.254 255.255.255.0 secondary&lt;BR /&gt; ip address 10.100.134.2 255.255.255.0 secondary&lt;BR /&gt; ip address 121.243.2.154 255.255.255.252&lt;BR /&gt; duplex auto&lt;BR /&gt; speed auto&lt;BR /&gt; crypto map Outside-Map&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip route 0.0.0.0 0.0.0.0 121.243.2.153&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip access-list extended Site_B_map&lt;BR /&gt; permit ip 10.10.16.0 0.0.0.255 10.101.150.0 0.0.0.255&lt;BR /&gt; permit ip 10.10.16.0 0.0.0.255 172.16.15.0 0.0.0.255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;====================================================================&lt;BR /&gt;ASA:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/0&lt;BR /&gt; description ### WAN Interface ###&lt;BR /&gt; nameif Outside&lt;BR /&gt; security-level 0&lt;BR /&gt; ip address 122.184.59.100 255.255.255.224 standby 122.184.59.101&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/1&lt;BR /&gt; description ### LAN Interface ###&lt;BR /&gt; nameif Inside&lt;BR /&gt; security-level 100&lt;BR /&gt; ip address 10.102.3.15 255.255.255.0 standby 10.102.3.14&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/2&lt;BR /&gt; description LAN/STATE Failover Interface&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/3&lt;BR /&gt; nameif Outside-Backup&lt;BR /&gt; security-level 0&lt;BR /&gt; ip address 121.242.42.4 255.255.255.192&lt;BR /&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list ASA-Site-B-ACL extended permit ip 172.16.15.0 255.255.255.0 10.10.16.0 255.255.255.0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;BR /&gt;access-list ASA-Site-B-ACL extended permit ip 10.11.150.0 255.255.255.0 10.10.16.0 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list ASA-Site-B-ACL extended permit ip 10.101.150.0 255.255.255.0 10.10.16.0 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Route:&lt;BR /&gt;route Outside 0.0.0.0 0.0.0.0 122.184.59.97 1 track 1&lt;BR /&gt;route Outside 0.0.0.0 0.0.0.254 122.184.59.97 1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;ASA Version: 7.2(4)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any help is appreciated&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Rupam&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 17:36:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-problem-with-ipsec-vpn-data-not-passing/m-p/1422756#M712863</guid>
      <dc:creator>rupam_chakra1983</dc:creator>
      <dc:date>2019-03-11T17:36:41Z</dc:date>
    </item>
    <item>
      <title>Re: ASA problem with IPSEC VPN data not passing</title>
      <link>https://community.cisco.com/t5/network-security/asa-problem-with-ipsec-vpn-data-not-passing/m-p/1422757#M712878</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Try to disable "ip cef" on the router.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 24 Apr 2010 03:56:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-problem-with-ipsec-vpn-data-not-passing/m-p/1422757#M712878</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2010-04-24T03:56:52Z</dc:date>
    </item>
    <item>
      <title>Re: ASA problem with IPSEC VPN data not passing</title>
      <link>https://community.cisco.com/t5/network-security/asa-problem-with-ipsec-vpn-data-not-passing/m-p/1422758#M712887</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your response.&lt;/P&gt;&lt;P&gt;I will try to disable cef on the router, But can you plz let me know how cef can be a problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As cef seems to be used for fast switching based on the ip routing table,&lt;/P&gt;&lt;P&gt;HOwever after dsabling cef also the problem is still there&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Appreciate your response.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 24 Apr 2010 05:11:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-problem-with-ipsec-vpn-data-not-passing/m-p/1422758#M712887</guid>
      <dc:creator>rupam_chakra1983</dc:creator>
      <dc:date>2010-04-24T05:11:06Z</dc:date>
    </item>
    <item>
      <title>Re: ASA problem with IPSEC VPN data not passing</title>
      <link>https://community.cisco.com/t5/network-security/asa-problem-with-ipsec-vpn-data-not-passing/m-p/1422759#M712896</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I've seen many occasions where disabling cef resolves connectivity issue when configuration looks perfect. Just something to try that might resolve the issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Another check would be to see if the host that you are trying to reach has personal firewall that might be blocking inbound connection from different subnet which is again always the case that would prevent connectivity.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 24 Apr 2010 08:45:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-problem-with-ipsec-vpn-data-not-passing/m-p/1422759#M712896</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2010-04-24T08:45:40Z</dc:date>
    </item>
    <item>
      <title>Re: ASA problem with IPSEC VPN data not passing</title>
      <link>https://community.cisco.com/t5/network-security/asa-problem-with-ipsec-vpn-data-not-passing/m-p/1422760#M712916</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Also i have a doubt as why my acl in the ASA is not hitting .&lt;/P&gt;&lt;P&gt;Also there is no duplicate ACL , so no chance of hitting any false ACL.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But my ACL is hitting in the router side,its really confused.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 25 Apr 2010 06:59:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-problem-with-ipsec-vpn-data-not-passing/m-p/1422760#M712916</guid>
      <dc:creator>rupam_chakra1983</dc:creator>
      <dc:date>2010-04-25T06:59:28Z</dc:date>
    </item>
    <item>
      <title>Re: ASA problem with IPSEC VPN data not passing</title>
      <link>https://community.cisco.com/t5/network-security/asa-problem-with-ipsec-vpn-data-not-passing/m-p/1422761#M712941</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;/32 route pointing towards ASA, but /24 is not?&amp;nbsp; I would try the packet-tracer command here, being sure to run it twice and move troubleshooting further in from there.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-skint&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 25 Apr 2010 10:16:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-problem-with-ipsec-vpn-data-not-passing/m-p/1422761#M712941</guid>
      <dc:creator>skint</dc:creator>
      <dc:date>2010-04-25T10:16:36Z</dc:date>
    </item>
    <item>
      <title>Re: ASA problem with IPSEC VPN data not passing</title>
      <link>https://community.cisco.com/t5/network-security/asa-problem-with-ipsec-vpn-data-not-passing/m-p/1422762#M712959</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;Tanks for reply&lt;/P&gt;&lt;P&gt;What i understand is that among the mentioned two routes in ASA&lt;/P&gt;&lt;P&gt;route Outside 0.0.0.0 0.0.0.0 122.184.59.97 1 track 1&lt;BR /&gt;route Outside 0.0.0.0 0.0.0.254 122.184.59.97 1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the second one " route Outside 0.0.0.0 0.0.0.254 122.184.59.97 1 " this route format is not correct .&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and we need to remove it and then check.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 25 Apr 2010 14:27:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-problem-with-ipsec-vpn-data-not-passing/m-p/1422762#M712959</guid>
      <dc:creator>rupam_chakra1983</dc:creator>
      <dc:date>2010-04-25T14:27:20Z</dc:date>
    </item>
    <item>
      <title>Re: ASA problem with IPSEC VPN data not passing</title>
      <link>https://community.cisco.com/t5/network-security/asa-problem-with-ipsec-vpn-data-not-passing/m-p/1422763#M712968</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Correct.&lt;/P&gt;&lt;P&gt;The first line is a default gateway with a metric 1 and being tracked.&lt;/P&gt;&lt;P&gt;The second line is incorrect.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Federico.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 25 Apr 2010 15:21:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-problem-with-ipsec-vpn-data-not-passing/m-p/1422763#M712968</guid>
      <dc:creator>Federico Coto Fajardo</dc:creator>
      <dc:date>2010-04-25T15:21:13Z</dc:date>
    </item>
    <item>
      <title>Re: ASA problem with IPSEC VPN data not passing</title>
      <link>https://community.cisco.com/t5/network-security/asa-problem-with-ipsec-vpn-data-not-passing/m-p/1422764#M712979</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have removed the route and also dsabled cef in the remote router but no hope,&lt;/P&gt;&lt;P&gt;still problem is there, also plz let me know how idaelly the routing should ne for ipsec.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. The route toward the remote subnet houls be pointed to ASA next hop or to the remote ipsec peer .&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a doubt and also why my ACL is not hitting the ASA&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Apr 2010 09:11:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-problem-with-ipsec-vpn-data-not-passing/m-p/1422764#M712979</guid>
      <dc:creator>rupam_chakra1983</dc:creator>
      <dc:date>2010-04-26T09:11:05Z</dc:date>
    </item>
    <item>
      <title>Re: ASA problem with IPSEC VPN data not passing</title>
      <link>https://community.cisco.com/t5/network-security/asa-problem-with-ipsec-vpn-data-not-passing/m-p/1422765#M712987</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The route to the remote network should point to the ASA.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-skint&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Apr 2010 12:26:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-problem-with-ipsec-vpn-data-not-passing/m-p/1422765#M712987</guid>
      <dc:creator>skint</dc:creator>
      <dc:date>2010-04-26T12:26:50Z</dc:date>
    </item>
    <item>
      <title>Re: ASA problem with IPSEC VPN data not passing</title>
      <link>https://community.cisco.com/t5/network-security/asa-problem-with-ipsec-vpn-data-not-passing/m-p/1422766#M712997</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There is a certain modification in my previous post that was a typo( copy-paste)&lt;SPAN __jive_emoticon_name="silly" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/images/emoticons/silly.gif"&gt;&lt;/SPAN&gt; errosult are:&lt;/P&gt;&lt;P&gt;&lt;SPAN class="300145111-26042010"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000080; font-family: Calibri; "&gt;&lt;SPAN class="300145111-26042010"&gt;Tried&amp;nbsp; to&lt;/SPAN&gt; ping from 172.16.15.0 &amp;gt; 10.10.16.0/24( all the IP address)&lt;SPAN class="300145111-26042010"&gt; : success&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000080; font-family: Calibri; "&gt;&lt;SPAN class="300145111-26042010"&gt;Tried&amp;nbsp; to&lt;/SPAN&gt; ping from 10.101.150.0(any ip) &amp;gt; 10.10.16.22 ( single ip pass&amp;nbsp; )&lt;SPAN class="300145111-26042010"&gt; : success&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000080; font-family: Calibri; "&gt;&lt;SPAN class="300145111-26042010"&gt;Tried &lt;/SPAN&gt;ping from 10.101.150.0(any ip) &amp;gt; 10.10.16.X ( all other ip except .22&amp;nbsp; fails )&lt;SPAN class="300145111-26042010"&gt; : Fail&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000080; font-family: Calibri; "&gt;Tried to ping&amp;nbsp; from Any server in 10.101.150.0 &amp;gt;&amp;nbsp; the router interface 10.10.16.254 :&amp;nbsp; success&lt;/SPAN&gt;&lt;/P&gt;&lt;SPAN class="300145111-26042010"&gt;&lt;P&gt;&lt;SPAN style="font-family: Calibri; color: #000080;"&gt;I tried extended ping from router interface&amp;nbsp; ip : 10.10.16.254 ( secondary ) to 10.101.150.0 ( &lt;SPAN class="897202813-26042010"&gt; random chekced live &lt;/SPAN&gt; ip) and it is&amp;nbsp; success.&lt;/SPAN&gt;&lt;/P&gt;&lt;/SPAN&gt;.&lt;P&gt;&lt;/P&gt;&lt;P&gt;e&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Apr 2010 14:12:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-problem-with-ipsec-vpn-data-not-passing/m-p/1422766#M712997</guid>
      <dc:creator>rupam_chakra1983</dc:creator>
      <dc:date>2010-04-26T14:12:39Z</dc:date>
    </item>
    <item>
      <title>Re: ASA problem with IPSEC VPN data not passing</title>
      <link>https://community.cisco.com/t5/network-security/asa-problem-with-ipsec-vpn-data-not-passing/m-p/1422767#M713006</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Check that all other ip in the 10.10.16.0/24 subnet does not have personal firewall that blocks incoming connection from different subnets.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you can ping 10.10.16.22 and 10.10.16.254, that means the VPN is up and running fine, as crypto ACL is configured on subnet base (10.10.16.0/24).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;99% of the time, it's the host itself that has personal firewall that blocks incoming connection.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Apr 2010 14:32:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-problem-with-ipsec-vpn-data-not-passing/m-p/1422767#M713006</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2010-04-26T14:32:00Z</dc:date>
    </item>
    <item>
      <title>Re: ASA problem with IPSEC VPN data not passing</title>
      <link>https://community.cisco.com/t5/network-security/asa-problem-with-ipsec-vpn-data-not-passing/m-p/1422768#M713012</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have checked and there is no personal firewall on end device as one of the device is pinging.&lt;/P&gt;&lt;P&gt;Second thing if data is passing i should get hits in ACL but i am not getting any hits, what can be the reason for&amp;nbsp; that.&lt;/P&gt;&lt;P&gt;The end device are not client PC they are some node which send collection data from equipment to server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What can be the reason for not getting ACL hits i am running code 7.2(4) in ASA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Apr 2010 14:40:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-problem-with-ipsec-vpn-data-not-passing/m-p/1422768#M713012</guid>
      <dc:creator>rupam_chakra1983</dc:creator>
      <dc:date>2010-04-26T14:40:21Z</dc:date>
    </item>
    <item>
      <title>Re: ASA problem with IPSEC VPN data not passing</title>
      <link>https://community.cisco.com/t5/network-security/asa-problem-with-ipsec-vpn-data-not-passing/m-p/1422769#M713015</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Try running the following command:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;packet-tracer input Inside icmp 172.16.15.1 8 0 10.10.16.21 det&lt;/P&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt;See if it's hitting the encrypt step, based on your messages and not seeing the counters increment, it would appear to be a routing issue.&lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt;-skint&lt;/DIV&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Apr 2010 14:44:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-problem-with-ipsec-vpn-data-not-passing/m-p/1422769#M713015</guid>
      <dc:creator>skint</dc:creator>
      <dc:date>2010-04-26T14:44:43Z</dc:date>
    </item>
    <item>
      <title>Re: ASA problem with IPSEC VPN data not passing</title>
      <link>https://community.cisco.com/t5/network-security/asa-problem-with-ipsec-vpn-data-not-passing/m-p/1422770#M713018</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have done the packet tracer from GUI and it is getting passed and permitting from inside to outside the report says success , but i can't find out which ACL it is hitting in the tracer.&lt;/P&gt;&lt;P&gt;Is there any other way to check.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Apr 2010 14:48:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-problem-with-ipsec-vpn-data-not-passing/m-p/1422770#M713018</guid>
      <dc:creator>rupam_chakra1983</dc:creator>
      <dc:date>2010-04-26T14:48:57Z</dc:date>
    </item>
    <item>
      <title>Re: ASA problem with IPSEC VPN data not passing</title>
      <link>https://community.cisco.com/t5/network-security/asa-problem-with-ipsec-vpn-data-not-passing/m-p/1422771#M713021</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Try it from CLI, you can see if the action if VPN encrypt or VPN drop.&amp;nbsp; You should also see an increment on your interesting traffic ACL.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-skint&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Apr 2010 14:51:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-problem-with-ipsec-vpn-data-not-passing/m-p/1422771#M713021</guid>
      <dc:creator>skint</dc:creator>
      <dc:date>2010-04-26T14:51:35Z</dc:date>
    </item>
    <item>
      <title>Re: ASA problem with IPSEC VPN data not passing</title>
      <link>https://community.cisco.com/t5/network-security/asa-problem-with-ipsec-vpn-data-not-passing/m-p/1422772#M713026</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks to all of you for sharing your ideas.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It seems that the packet for some of the remote device are nt reaching the remote router interface,&lt;/P&gt;&lt;P&gt;It may be a problem and we are planning to test the same.&lt;/P&gt;&lt;P&gt;Also at the remote end my router has oly one inetrface configured for LAN and WAn and Lan ip i have given as seondary and wan ip as primary to same interface.&lt;/P&gt;&lt;P&gt;.22 is a end host connected to the common switch where router and wireless device is connceted.&lt;/P&gt;&lt;P&gt;.22 is able to ping but the other ip cann't able to ping (.21,.23 etc)those are some power rating device, But from the Router LAN interface was able to ping the device the de the&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 27 Apr 2010 14:51:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-problem-with-ipsec-vpn-data-not-passing/m-p/1422772#M713026</guid>
      <dc:creator>rupam_chakra1983</dc:creator>
      <dc:date>2010-04-27T14:51:39Z</dc:date>
    </item>
    <item>
      <title>Re: ASA problem with IPSEC VPN data not passing</title>
      <link>https://community.cisco.com/t5/network-security/asa-problem-with-ipsec-vpn-data-not-passing/m-p/1422773#M713031</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Will disabling proxy arp in the router(remote) side help in this case&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 May 2010 08:55:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-problem-with-ipsec-vpn-data-not-passing/m-p/1422773#M713031</guid>
      <dc:creator>rupam_chakra1983</dc:creator>
      <dc:date>2010-05-06T08:55:29Z</dc:date>
    </item>
  </channel>
</rss>

