<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IPSEC VPN With DYNAMIC IP ADDRESS in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ipsec-vpn-with-dynamic-ip-address/m-p/1249068#M857774</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can anybody help me out.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 05 Nov 2009 08:29:57 GMT</pubDate>
    <dc:creator>wasiimcisco</dc:creator>
    <dc:date>2009-11-05T08:29:57Z</dc:date>
    <item>
      <title>IPSEC VPN With DYNAMIC IP ADDRESS</title>
      <link>https://community.cisco.com/t5/network-security/ipsec-vpn-with-dynamic-ip-address/m-p/1249065#M857771</link>
      <description>&lt;P&gt;i have ASA 8.0 with static ip address and remote site has a ADSL ROuter with dynamic IP address.&lt;/P&gt;&lt;P&gt;I am not able to make the Site to site vpn connection. I have tried dynamic map and standard site to site vpn&lt;/P&gt;&lt;P&gt;connection but nothing is working for me.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please help me out. I am tottally stuck.I have attached the router and firewall configuration and below error I am getting.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Nov  3 18:08:34.606: IPSEC(key_engine): request timer fired: count = 1,&lt;/P&gt;&lt;P&gt; (identity) local= 83.110.195.120, remote= x.x.x.x,&lt;/P&gt;&lt;P&gt;   local_proxy= 172.17.245.210/255.255.255.255/0/0 (type=1),&lt;/P&gt;&lt;P&gt;   remote_proxy= 192.168.0.0/255.255.0.0/0/0 (type=4)&lt;/P&gt;&lt;P&gt;Nov  3 18:08:34.606: IPSEC(sa_request): ,&lt;/P&gt;&lt;P&gt; (key eng. msg.) OUTBOUND local= 83.110.195.120, remote= x.x.x.x,&lt;/P&gt;&lt;P&gt;   local_proxy= 172.17.245.210/255.255.255.255/0/0 (type=1),&lt;/P&gt;&lt;P&gt;   remote_proxy= 192.168.0.0/255.255.0.0/0/0 (type=4),&lt;/P&gt;&lt;P&gt;   protocol= ESP, transform= esp-3des esp-md5-hmac  (Tunnel),&lt;/P&gt;&lt;P&gt;   lifedur= 3600s and 4608000kb,&lt;/P&gt;&lt;P&gt;   spi= 0x0(0), conn_id= 0, keysize= 0, flags= 0x0&lt;/P&gt;&lt;P&gt;RISTAR-JXB#&lt;/P&gt;&lt;P&gt;RISTAR-JXB#&lt;/P&gt;&lt;P&gt;Nov  3 18:08:34.810: IPSEC(key_engine): got a queue event with 1 KMI message(s)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If I give 0.0.0.0 in tunnel group configuraion it gave me following error.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ENOCDC-FW03(config)# tunnel-group 0.0.0.0 type ipsec-l2l &lt;/P&gt;&lt;P&gt;WARNING: L2L tunnel-groups that have names which are not an IP&lt;/P&gt;&lt;P&gt;address may only be used if the tunnel authentication&lt;/P&gt;&lt;P&gt;method is Digitial Certificates and/or The peer is &lt;/P&gt;&lt;P&gt;configured to use Aggressive Mode&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have change the rotuer configuration to aggressive mode but still no luck&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 16:35:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ipsec-vpn-with-dynamic-ip-address/m-p/1249065#M857771</guid>
      <dc:creator>wasiimcisco</dc:creator>
      <dc:date>2019-03-11T16:35:31Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC VPN With DYNAMIC IP ADDRESS</title>
      <link>https://community.cisco.com/t5/network-security/ipsec-vpn-with-dynamic-ip-address/m-p/1249066#M857772</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You want to use the DefaultL2LGroup for your tunnel group name, not 0.0.0.0.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 03 Nov 2009 21:43:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ipsec-vpn-with-dynamic-ip-address/m-p/1249066#M857772</guid>
      <dc:creator>acomiskey</dc:creator>
      <dc:date>2009-11-03T21:43:08Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC VPN With DYNAMIC IP ADDRESS</title>
      <link>https://community.cisco.com/t5/network-security/ipsec-vpn-with-dynamic-ip-address/m-p/1249067#M857773</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes Right and i even tried this but still not working. I am getting following errors on router. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;my head office firewall has mulitple site to site VPP connection and remote access vpn and it is working fine but only this VPN connection is giving me problem. I have tried all.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 04 Nov 2009 15:39:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ipsec-vpn-with-dynamic-ip-address/m-p/1249067#M857773</guid>
      <dc:creator>wasiimcisco</dc:creator>
      <dc:date>2009-11-04T15:39:42Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC VPN With DYNAMIC IP ADDRESS</title>
      <link>https://community.cisco.com/t5/network-security/ipsec-vpn-with-dynamic-ip-address/m-p/1249068#M857774</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can anybody help me out.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Nov 2009 08:29:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ipsec-vpn-with-dynamic-ip-address/m-p/1249068#M857774</guid>
      <dc:creator>wasiimcisco</dc:creator>
      <dc:date>2009-11-05T08:29:57Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC VPN With DYNAMIC IP ADDRESS</title>
      <link>https://community.cisco.com/t5/network-security/ipsec-vpn-with-dynamic-ip-address/m-p/1249069#M857775</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;First off, your crypto acl's should be mirrors of each other. This is how they are now...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Router&lt;/P&gt;&lt;P&gt;access-list 115 permit ip host 172.17.245.210 192.168.0.0 0.0.255.255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASA&lt;/P&gt;&lt;P&gt;access-list TRJXB extended permit ip 192.168.0.0 255.255.0.0 172.17.245.0 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is what they should be...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Router &lt;/P&gt;&lt;P&gt;access-list 115 permit ip host 172.17.245.0 0.0.0.255 192.168.0.0 0.0.255.255&lt;/P&gt;&lt;P&gt;ASA&lt;/P&gt;&lt;P&gt;access-list TRJXB extended permit ip 192.168.0.0 255.255.0.0 172.17.245.0 255.255.255.0&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Nov 2009 13:56:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ipsec-vpn-with-dynamic-ip-address/m-p/1249069#M857775</guid>
      <dc:creator>acomiskey</dc:creator>
      <dc:date>2009-11-05T13:56:23Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC VPN With DYNAMIC IP ADDRESS</title>
      <link>https://community.cisco.com/t5/network-security/ipsec-vpn-with-dynamic-ip-address/m-p/1249070#M857777</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;On ASA firewall I am making dynamic map. like &lt;/P&gt;&lt;P&gt;Dynamic IPsec Between a Statically addressed PIX and a Dynamically addressed IOS Router with NAT Configuration Example&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In dynanic map I dont have any option to recall the interesting traffic. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Nov 2009 15:08:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ipsec-vpn-with-dynamic-ip-address/m-p/1249070#M857777</guid>
      <dc:creator>wasiimcisco</dc:creator>
      <dc:date>2009-11-05T15:08:03Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC VPN With DYNAMIC IP ADDRESS</title>
      <link>https://community.cisco.com/t5/network-security/ipsec-vpn-with-dynamic-ip-address/m-p/1249071#M857779</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sure you do, it's right here...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;crypto dynamic-map TRJXB_MAP 151 match address TRJXB&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Nov 2009 15:12:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ipsec-vpn-with-dynamic-ip-address/m-p/1249071#M857779</guid>
      <dc:creator>acomiskey</dc:creator>
      <dc:date>2009-11-05T15:12:01Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC VPN With DYNAMIC IP ADDRESS</title>
      <link>https://community.cisco.com/t5/network-security/ipsec-vpn-with-dynamic-ip-address/m-p/1249072#M857781</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have configured this &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;crypto dynamic-map TRI_MAP 17 match address TRJXB&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list TRJXB extended permit ip 192.168.0.0 255.255.0.0 17.1.1.0 255.255.255.0 &lt;/P&gt;&lt;P&gt;access-list TRJXB extended permit ip 192.168.0.0 255.255.0.0 6.1.1.0 255.255.255.0 &lt;/P&gt;&lt;P&gt;access-list TRJXB extended permit ip 16.1.1.0 255.255.255.0 6.1.1.0 255.255.255.0 &lt;/P&gt;&lt;P&gt;access-list TRJXB extended permit ip 16.1.1.0 255.255.255.0 17.1.1.0 255.255.255.0 &lt;/P&gt;&lt;P&gt;access-list TRJXB extended permit ip 16.1.1.0 255.255.255.0 172.17.245.0 255.255.255.0 &lt;/P&gt;&lt;P&gt;access-list TRJXB extended permit ip 192.168.0.0 255.255.0.0 172.17.245.0 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list acl-nonat extended permit ip 16.1.1.0 255.255.255.0 host 6.1.1.1 &lt;/P&gt;&lt;P&gt;access-list acl-nonat extended permit ip 192.168.0.0 255.255.0.0 host 6.1.1.1 &lt;/P&gt;&lt;P&gt;access-list acl-nonat extended permit ip 16.1.1.0 255.255.255.0 17.1.1.0 255.255.255.0 &lt;/P&gt;&lt;P&gt;access-list acl-nonat extended permit ip 16.1.1.0 255.255.255.0 host 172.17.245.7 &lt;/P&gt;&lt;P&gt;access-list acl-nonat extended permit ip 16.1.1.0 255.255.255.0 host 172.17.245.150 &lt;/P&gt;&lt;P&gt;access-list acl-nonat extended permit ip 192.168.0.0 255.255.0.0 host 172.17.245.150 &lt;/P&gt;&lt;P&gt;access-list acl-nonat extended permit ip 192.168.0.0 255.255.0.0 host 172.17.245.7&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;but still not working. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Nov 2009 15:53:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ipsec-vpn-with-dynamic-ip-address/m-p/1249072#M857781</guid>
      <dc:creator>wasiimcisco</dc:creator>
      <dc:date>2009-11-05T15:53:25Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC VPN With DYNAMIC IP ADDRESS</title>
      <link>https://community.cisco.com/t5/network-security/ipsec-vpn-with-dynamic-ip-address/m-p/1249073#M857783</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Those aren't exact mirrors of eachother and the crypto acl on your router isn't acl-nonat, it's acl 115.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Nov 2009 16:05:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ipsec-vpn-with-dynamic-ip-address/m-p/1249073#M857783</guid>
      <dc:creator>acomiskey</dc:creator>
      <dc:date>2009-11-05T16:05:56Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC VPN With DYNAMIC IP ADDRESS</title>
      <link>https://community.cisco.com/t5/network-security/ipsec-vpn-with-dynamic-ip-address/m-p/1249074#M857784</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can you get the log from the ASA?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Nov 2009 16:14:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ipsec-vpn-with-dynamic-ip-address/m-p/1249074#M857784</guid>
      <dc:creator>acomiskey</dc:creator>
      <dc:date>2009-11-05T16:14:07Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC VPN With DYNAMIC IP ADDRESS</title>
      <link>https://community.cisco.com/t5/network-security/ipsec-vpn-with-dynamic-ip-address/m-p/1249075#M857792</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Please find attached. I am really thankful for your support and time that you are giving me to solving this issue. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Nov 2009 16:26:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ipsec-vpn-with-dynamic-ip-address/m-p/1249075#M857792</guid>
      <dc:creator>wasiimcisco</dc:creator>
      <dc:date>2009-11-05T16:26:29Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC VPN With DYNAMIC IP ADDRESS</title>
      <link>https://community.cisco.com/t5/network-security/ipsec-vpn-with-dynamic-ip-address/m-p/1249076#M857793</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Try this on the ASA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;crypto dynamic-map TRJXB-MAP 151 set pfs&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Nov 2009 16:40:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ipsec-vpn-with-dynamic-ip-address/m-p/1249076#M857793</guid>
      <dc:creator>acomiskey</dc:creator>
      <dc:date>2009-11-05T16:40:05Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC VPN With DYNAMIC IP ADDRESS</title>
      <link>https://community.cisco.com/t5/network-security/ipsec-vpn-with-dynamic-ip-address/m-p/1249077#M857794</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Tried but still not working. Even reconfigure the complete router. This time configure with the Aggressive mode on the router.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Nov 2009 21:49:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ipsec-vpn-with-dynamic-ip-address/m-p/1249077#M857794</guid>
      <dc:creator>wasiimcisco</dc:creator>
      <dc:date>2009-11-05T21:49:31Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC VPN With DYNAMIC IP ADDRESS</title>
      <link>https://community.cisco.com/t5/network-security/ipsec-vpn-with-dynamic-ip-address/m-p/1249078#M857795</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;See the fresh log after reconfiguration of Router as aggressive mode and ASA with PFS. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Nov 2009 22:13:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ipsec-vpn-with-dynamic-ip-address/m-p/1249078#M857795</guid>
      <dc:creator>wasiimcisco</dc:creator>
      <dc:date>2009-11-05T22:13:39Z</dc:date>
    </item>
  </channel>
</rss>

