<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: S2S vpn help in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/s2s-vpn-help/m-p/1461844#M739387</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;yes i have active tunnel connection to other location at site B ,&lt;/P&gt;&lt;P&gt;similarly i have done capture command for outside interface i dont see any traffic for 500 which recieving to my firerwall or my firewall is sending out , similarly i have binded capture acl to inbound direction of outside interface .&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;similalry by using my ISP connection i can use vpn dialer to connect to my HO ..&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 11 Aug 2010 19:10:51 GMT</pubDate>
    <dc:creator>SANTHOSHKUMAR SARAVANAN</dc:creator>
    <dc:date>2010-08-11T19:10:51Z</dc:date>
    <item>
      <title>S2S vpn help</title>
      <link>https://community.cisco.com/t5/network-security/s2s-vpn-help/m-p/1461838#M739381</link>
      <description>&lt;P&gt;HI All ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; I have S2S paremeter in both asa device , when my intresting traffic is initated from site A to site B , I am getting Show crypto&amp;nbsp; isakmp sa as below&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;site a (config)# sh crypto is&lt;BR /&gt;site a (config)# sh crypto isakmp sa&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; Active SA: 1&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Rekey SA: 0 (A tunnel will report 1 Active and 1 Rekey SA during rekey)&lt;BR /&gt;Total IKE SA: 1&lt;/P&gt;&lt;P&gt;1&amp;nbsp;&amp;nbsp; IKE Peer: 207.x.x.x&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Type&amp;nbsp;&amp;nbsp;&amp;nbsp; : user&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Role&amp;nbsp;&amp;nbsp;&amp;nbsp; : initiator &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Rekey&amp;nbsp;&amp;nbsp; : no&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; State&amp;nbsp;&amp;nbsp; : &lt;STRONG&gt;MM_WAIT_MSG2&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;site a (config)# Aug 11 23:19:55 [IKEv1]: IP = 207.x.x.x, Removing peer from peer table failed, no match!&lt;BR /&gt; [IKEv1]: IP = 207.x.x.x, Error: Unable to remove PeerTblEntry&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;but when i check at Site B i am nt receving ISAKMP request from siteA&amp;nbsp; , but from both side ping is happening and traceroute is completley perfect .&lt;/P&gt;&lt;P&gt;i have checked both side ISAKMP parameter ,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am just wondering y Site B is not recieving site A ISAKMP packet , but i can see ping request packet at site b firewall which is coming from site a , but i dont find isakmp hits . kindly help me&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 18:24:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/s2s-vpn-help/m-p/1461838#M739381</guid>
      <dc:creator>SANTHOSHKUMAR SARAVANAN</dc:creator>
      <dc:date>2019-03-11T18:24:02Z</dc:date>
    </item>
    <item>
      <title>Re: S2S vpn help</title>
      <link>https://community.cisco.com/t5/network-security/s2s-vpn-help/m-p/1461839#M739382</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;#1 apply captures on the other end and see if you get any packet&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; you should see packets on port udp 500 from the peer&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; if you do not see it, then contact your isp and get the ports required for vpn opened - udp 500, ip 50,51 , udp 4500&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;#2&amp;nbsp; also you will need to open these ports on firewall using access-list on your outside interface&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; alternativly to open vpn related ports on your firewall you can give the command&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; sysopt connection permit-vpn&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 11 Aug 2010 18:15:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/s2s-vpn-help/m-p/1461839#M739382</guid>
      <dc:creator>Jitendriya Athavale</dc:creator>
      <dc:date>2010-08-11T18:15:19Z</dc:date>
    </item>
    <item>
      <title>Re: S2S vpn help</title>
      <link>https://community.cisco.com/t5/network-security/s2s-vpn-help/m-p/1461840#M739383</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Thanx for your reply when i give debug cryto isakmp sa i am getting follwoing message&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;e5t-pf-sprint(config)# Aug 12 00:16:22 [IKEv1 DEBUG]: Pitcher: received a key acquire message, spi 0x0&lt;BR /&gt;Aug 12 00:16:22 [IKEv1]: IP = 207.x.x.x, IKE Initiator: New Phase 1, Intf inside, IKE Peer 207.x.xx&amp;nbsp; local Proxy Address .x98.x.x, remote Proxy Address x.x.x.0,&amp;nbsp; Crypto map &lt;BR /&gt;Aug 12 00:16:22 [IKEv1 DEBUG]: IP = x.x.x.x, constructing ISAKMP SA payload&lt;BR /&gt;Aug 12 00:16:22 [IKEv1 DEBUG]: IP = x.x.x.x, constructing Fragmentation VID + extended capabilities payload&lt;BR /&gt;Aug 12 00:16:22 [IKEv1]: IP = x.x.x.x, IKE_DECODE SENDING Message (msgid=0) with payloads : HDR + SA (1) + VENDOR (13) + NONE (0) total length : 108&lt;BR /&gt;Aug 12 00:16:24 [IKEv1 DEBUG]: Pitcher: received a key acquire message, spi 0x0&lt;BR /&gt;Aug 12 00:16:24 [IKEv1]: IP = x.x.x.x, Queuing KEY-ACQUIRE messages to be processed when P1 SA is complete.&lt;BR /&gt;Aug 12 00:16:28 [IKEv1 DEBUG]: Pitcher: received a key acquire message, spi 0x0&lt;BR /&gt;+ NONE (0) total length : 108&lt;BR /&gt;&lt;STRONG&gt;Aug 12 00:16:54 [IKEv1 DEBUG]: IP = 207.x.x.x, IKE MM Initiator FSM error history (struct &amp;amp;0x5085a20)&amp;nbsp; &lt;STATE&gt;, &lt;EVENT&gt;:&amp;nbsp; MM_DONE, EV_ERROR--&amp;gt;MM_WAIT_MSG2, EV_RETRY--&amp;gt;MM_WAIT_MSG2, EV_TIMEOUT--&amp;gt;MM_WAIT_MSG2, NullEvent--&amp;gt;MM_SND_MSG1, EV_SND_MSG--&amp;gt;MM_SND_MSG1, EV_START_TMR--&amp;gt;MM_SND_MSG1, EV_RESEND_MSG--&amp;gt;MM_WAIT_MSG2, EV_RETRY&lt;BR /&gt;&lt;/EVENT&gt;&lt;/STATE&gt;&lt;/STRONG&gt;Aug 12 00:16:54 [IKEv1 DEBUG]: IP = 207.0.x.x, IKE SA MM:15e2aabd terminating:&amp;nbsp; flags 0x01000022, refcnt 0, tuncnt 0&lt;BR /&gt;Aug 12 00:16:54 [IKEv1 DEBUG]: IP = 207.x.x, sending delete/delete with reason message&lt;BR /&gt;Aug 12 00:16:54 [IKEv1]: IP = 207.x.x.x, Removing peer from peer table failed, no match!&lt;BR /&gt;Aug 12 00:16:54 [IKEv1]: IP = 207.x.x.x, Error: Unable to remove PeerTblEntry&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;wht does FSM error history ..&lt;/P&gt;&lt;P&gt;i will post u capture comands , i am have enable syspot connection permit-vpn. could you help me over here&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 11 Aug 2010 18:28:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/s2s-vpn-help/m-p/1461840#M739383</guid>
      <dc:creator>SANTHOSHKUMAR SARAVANAN</dc:creator>
      <dc:date>2010-08-11T18:28:02Z</dc:date>
    </item>
    <item>
      <title>Re: S2S vpn help</title>
      <link>https://community.cisco.com/t5/network-security/s2s-vpn-help/m-p/1461841#M739384</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;these look like debugs from site a... can you paste debugs from site b&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 11 Aug 2010 18:34:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/s2s-vpn-help/m-p/1461841#M739384</guid>
      <dc:creator>Jitendriya Athavale</dc:creator>
      <dc:date>2010-08-11T18:34:02Z</dc:date>
    </item>
    <item>
      <title>Re: S2S vpn help</title>
      <link>https://community.cisco.com/t5/network-security/s2s-vpn-help/m-p/1461842#M739385</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Site B is not recieveing site A ISAKMP handshaking traffic . simiarly my ISP link is directly termiated on site A firewall outside interface . i wondering y site B is nt receving ISAKMP traffic .&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;how to do capture for outside interafce ..&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 11 Aug 2010 18:40:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/s2s-vpn-help/m-p/1461842#M739385</guid>
      <dc:creator>SANTHOSHKUMAR SARAVANAN</dc:creator>
      <dc:date>2010-08-11T18:40:03Z</dc:date>
    </item>
    <item>
      <title>Re: S2S vpn help</title>
      <link>https://community.cisco.com/t5/network-security/s2s-vpn-help/m-p/1461843#M739386</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;access-list capout extended permit ip host &lt;PEER ip=""&gt; host &lt;MY ip=""&gt;&lt;/MY&gt;&lt;/PEER&gt;&lt;/P&gt;&lt;P&gt;access-list capout extended permit ip host &lt;MY ip=""&gt; host &lt;PEER ip=""&gt;&lt;/PEER&gt;&lt;/MY&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;capture capo interface outside access-list capout&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i think it could well be the isp blocking it&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;do you have any other active tunnels on site b&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 11 Aug 2010 18:45:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/s2s-vpn-help/m-p/1461843#M739386</guid>
      <dc:creator>Jitendriya Athavale</dc:creator>
      <dc:date>2010-08-11T18:45:42Z</dc:date>
    </item>
    <item>
      <title>Re: S2S vpn help</title>
      <link>https://community.cisco.com/t5/network-security/s2s-vpn-help/m-p/1461844#M739387</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;yes i have active tunnel connection to other location at site B ,&lt;/P&gt;&lt;P&gt;similarly i have done capture command for outside interface i dont see any traffic for 500 which recieving to my firerwall or my firewall is sending out , similarly i have binded capture acl to inbound direction of outside interface .&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;similalry by using my ISP connection i can use vpn dialer to connect to my HO ..&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 11 Aug 2010 19:10:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/s2s-vpn-help/m-p/1461844#M739387</guid>
      <dc:creator>SANTHOSHKUMAR SARAVANAN</dc:creator>
      <dc:date>2010-08-11T19:10:51Z</dc:date>
    </item>
    <item>
      <title>Re: S2S vpn help</title>
      <link>https://community.cisco.com/t5/network-security/s2s-vpn-help/m-p/1461845#M739388</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;if this issue is still un resolved can you paste the config on the both ends&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Aug 2010 13:29:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/s2s-vpn-help/m-p/1461845#M739388</guid>
      <dc:creator>Jitendriya Athavale</dc:creator>
      <dc:date>2010-08-12T13:29:03Z</dc:date>
    </item>
  </channel>
</rss>

