<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Strange VPN Remote Issue  in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/strange-vpn-remote-issue/m-p/1174691#M859944</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Are you trying to ping from 192.168.14.0 or are you trying to ping TO 192.168.14.0? Try adding "inspect icmp" to your default policy.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH,&lt;/P&gt;&lt;P&gt;John&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 11 May 2009 19:18:10 GMT</pubDate>
    <dc:creator>John Blakley</dc:creator>
    <dc:date>2009-05-11T19:18:10Z</dc:date>
    <item>
      <title>Strange VPN Remote Issue</title>
      <link>https://community.cisco.com/t5/network-security/strange-vpn-remote-issue/m-p/1174687#M859940</link>
      <description>&lt;P&gt;we have configured IPSEC Remote VPN on  ASA 5510. Remote client is able to successfully authenticate and establish a tunnel , however user will not be able to ping any inside Hosts . As troubleshooting measure , i did enable ICMp trace 255 , i see the VPN Client  ICMP request and a echo reply back from the Inside host hitting the Inside Interface of the Firewall . Can you please go through the configuration and let me know if anything needs to be changed .&lt;/P&gt;&lt;P&gt; Path the User will take is &lt;/P&gt;&lt;P&gt;VPn Usr--&amp;gt;Firewall ( inside ip 10.10.10.2)-&amp;gt;L3switch (10.10.10.1)-&amp;gt;Host (10.10.10.5)  &lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 15:30:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/strange-vpn-remote-issue/m-p/1174687#M859940</guid>
      <dc:creator>ciscosom</dc:creator>
      <dc:date>2019-03-11T15:30:18Z</dc:date>
    </item>
    <item>
      <title>Re: Strange VPN Remote Issue</title>
      <link>https://community.cisco.com/t5/network-security/strange-vpn-remote-issue/m-p/1174688#M859941</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Missed the attachment last time &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 May 2009 18:35:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/strange-vpn-remote-issue/m-p/1174688#M859941</guid>
      <dc:creator>ciscosom</dc:creator>
      <dc:date>2009-05-11T18:35:52Z</dc:date>
    </item>
    <item>
      <title>Re: Strange VPN Remote Issue</title>
      <link>https://community.cisco.com/t5/network-security/strange-vpn-remote-issue/m-p/1174689#M859942</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Does anything else seem to work other than icmp?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Try:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;same-security-traffic permit intra-interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH,&lt;/P&gt;&lt;P&gt;John&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 May 2009 18:58:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/strange-vpn-remote-issue/m-p/1174689#M859942</guid>
      <dc:creator>John Blakley</dc:creator>
      <dc:date>2009-05-11T18:58:19Z</dc:date>
    </item>
    <item>
      <title>Re: Strange VPN Remote Issue</title>
      <link>https://community.cisco.com/t5/network-security/strange-vpn-remote-issue/m-p/1174690#M859943</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for responding back John , modified the Configuration as per your suggestion , but no LUCK . No Traffic is being received back by the Remote client . Looks like the Return/response  packet sent by the Inside host to the remote client is reaching the ASA but is not entering the IPSEC tunnel .. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Debug ICMp Trace output &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; echo reply from inside:10.10.11.1 to outside:192.168.14.1 ID=1 seq=758 len2&lt;/P&gt;&lt;P&gt;ICMP echo request from outside:192.168.14.1 to inside:10.10.11.1 ID=1 seq=759 l2&lt;/P&gt;&lt;P&gt;ICMP echo reply from inside:10.10.11.1 to outside:192.168.14.1 ID=1 seq=759 len2&lt;/P&gt;&lt;P&gt;ICMP echo request from outside:192.168.14.1 to inside:10.10.11.1 ID=1 seq=760 l2&lt;/P&gt;&lt;P&gt;ICMP echo reply from inside:10.10.11.1 to outside:192.168.14.1 ID=1 seq=760 len2&lt;/P&gt;&lt;P&gt;ICMP echo request from outside:192.168.14.1 to inside:10.10.11.1 ID=1 seq=761 l2&lt;/P&gt;&lt;P&gt;ICMP echo reply from inside:10.10.11.1 to outside:192.168.14.1 ID=1 seq=761 len&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 May 2009 19:05:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/strange-vpn-remote-issue/m-p/1174690#M859943</guid>
      <dc:creator>ciscosom</dc:creator>
      <dc:date>2009-05-11T19:05:55Z</dc:date>
    </item>
    <item>
      <title>Re: Strange VPN Remote Issue</title>
      <link>https://community.cisco.com/t5/network-security/strange-vpn-remote-issue/m-p/1174691#M859944</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Are you trying to ping from 192.168.14.0 or are you trying to ping TO 192.168.14.0? Try adding "inspect icmp" to your default policy.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH,&lt;/P&gt;&lt;P&gt;John&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 May 2009 19:18:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/strange-vpn-remote-issue/m-p/1174691#M859944</guid>
      <dc:creator>John Blakley</dc:creator>
      <dc:date>2009-05-11T19:18:10Z</dc:date>
    </item>
    <item>
      <title>Re: Strange VPN Remote Issue</title>
      <link>https://community.cisco.com/t5/network-security/strange-vpn-remote-issue/m-p/1174692#M859945</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi John , &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;192.168.14.1 is the remote Client Ip assigned by  ASA Ip pool .10.10.10.1 is the L3 Switch  interface behind the Firewall . &lt;/P&gt;&lt;P&gt;          I am trying to ping from 192.168.14.1 (remote vpn Client) ---&amp;gt; 10.10.10.1 (L3 Switch ). &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 May 2009 19:23:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/strange-vpn-remote-issue/m-p/1174692#M859945</guid>
      <dc:creator>ciscosom</dc:creator>
      <dc:date>2009-05-11T19:23:36Z</dc:date>
    </item>
    <item>
      <title>Re: Strange VPN Remote Issue</title>
      <link>https://community.cisco.com/t5/network-security/strange-vpn-remote-issue/m-p/1174693#M859946</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can you ping the .14.1 address from the ASA?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 May 2009 19:34:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/strange-vpn-remote-issue/m-p/1174693#M859946</guid>
      <dc:creator>John Blakley</dc:creator>
      <dc:date>2009-05-11T19:34:32Z</dc:date>
    </item>
    <item>
      <title>Re: Strange VPN Remote Issue</title>
      <link>https://community.cisco.com/t5/network-security/strange-vpn-remote-issue/m-p/1174694#M859947</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Do you have a route in your L3 switch back to the 192.168.14.0 subnet?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 May 2009 19:38:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/strange-vpn-remote-issue/m-p/1174694#M859947</guid>
      <dc:creator>John Blakley</dc:creator>
      <dc:date>2009-05-11T19:38:54Z</dc:date>
    </item>
    <item>
      <title>Re: Strange VPN Remote Issue</title>
      <link>https://community.cisco.com/t5/network-security/strange-vpn-remote-issue/m-p/1174695#M859948</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi John , &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes L3 has a defualt route pointing to ASA .&lt;/P&gt;&lt;P&gt;I think If routing was an issue we would not received the reply packets back from the host when we did the Debug ICMP Trace on the ASA , Your thoughts on this ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also i am not able to Ping the Remote Client (192.168.14.1) from the ASA &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 May 2009 19:46:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/strange-vpn-remote-issue/m-p/1174695#M859948</guid>
      <dc:creator>ciscosom</dc:creator>
      <dc:date>2009-05-11T19:46:46Z</dc:date>
    </item>
    <item>
      <title>Re: Strange VPN Remote Issue</title>
      <link>https://community.cisco.com/t5/network-security/strange-vpn-remote-issue/m-p/1174696#M859949</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You should at least be able to hit it from the ASA. What do you get back if you do a:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sh vpn-sessiondb remote&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 May 2009 19:52:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/strange-vpn-remote-issue/m-p/1174696#M859949</guid>
      <dc:creator>John Blakley</dc:creator>
      <dc:date>2009-05-11T19:52:44Z</dc:date>
    </item>
    <item>
      <title>Re: Strange VPN Remote Issue</title>
      <link>https://community.cisco.com/t5/network-security/strange-vpn-remote-issue/m-p/1174697#M859950</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;First of all , i have no words to Thank you !!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You are correct ,Ideally  we should be able to ping the Remote Client from the ASA Atleast . I think that 10.10.0.0 is not going into the ipsec tunnel when the destination iip is 192.168.14.0 for some reason ..Anywasy , below is the remote Db Output &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Session Type: IPsec&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Username     : Administrator          Index        : 2&lt;/P&gt;&lt;P&gt;Assigned IP  : 192.168.14.1           Public IP    : X.X.12.200&lt;/P&gt;&lt;P&gt;Protocol     : IKE IPsec&lt;/P&gt;&lt;P&gt;License      : IPsec&lt;/P&gt;&lt;P&gt;Encryption   : 3DES                   Hashing      : SHA1&lt;/P&gt;&lt;P&gt;Bytes Tx     : 1828                   Bytes Rx     : 8518&lt;/P&gt;&lt;P&gt;Group Policy : tom                    Tunnel Group : tom&lt;/P&gt;&lt;P&gt;Login Time   : 20:53:45 UTC Mon May 11 2009&lt;/P&gt;&lt;P&gt;Duration     : 0h:00m:34s&lt;/P&gt;&lt;P&gt;NAC Result   : Unknown&lt;/P&gt;&lt;P&gt;VLAN Mapping : N/A                    VLAN         : none&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 May 2009 20:03:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/strange-vpn-remote-issue/m-p/1174697#M859950</guid>
      <dc:creator>ciscosom</dc:creator>
      <dc:date>2009-05-11T20:03:01Z</dc:date>
    </item>
    <item>
      <title>Re: Strange VPN Remote Issue</title>
      <link>https://community.cisco.com/t5/network-security/strange-vpn-remote-issue/m-p/1174698#M859951</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Glad to help &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; What are they using to connect with? Cisco's VPN client? Is the stateful firewall on by chance?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And let me get this right, you've always tried to ping from this side to the 192.168.14.0 side, or have you tried 192.168.14.1 -&amp;gt; 10.x.x.x?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 May 2009 20:06:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/strange-vpn-remote-issue/m-p/1174698#M859951</guid>
      <dc:creator>John Blakley</dc:creator>
      <dc:date>2009-05-11T20:06:28Z</dc:date>
    </item>
    <item>
      <title>Re: Strange VPN Remote Issue</title>
      <link>https://community.cisco.com/t5/network-security/strange-vpn-remote-issue/m-p/1174699#M859952</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;yes i have tried both directions ..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;192.168.14.0 (remote client) ---&amp;gt; 10.x.x.x (host behind firewall_&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;10.x.x.x (host behind firewall)--&amp;gt; Remote client . No Traffic at all .&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes , Remote USers connect using Cisco VPN Client 5.03XX version  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;No , Stateful firewall is OFF .&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 May 2009 20:11:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/strange-vpn-remote-issue/m-p/1174699#M859952</guid>
      <dc:creator>ciscosom</dc:creator>
      <dc:date>2009-05-11T20:11:17Z</dc:date>
    </item>
    <item>
      <title>Re: Strange VPN Remote Issue</title>
      <link>https://community.cisco.com/t5/network-security/strange-vpn-remote-issue/m-p/1174700#M859953</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Do you get an entry in your routing table for that host? What shows as it's next hop?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Try this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list VPN permit host 0.0.0.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;group-policy tom attrib&lt;/P&gt;&lt;P&gt;split-tunnel-specified excludespecified&lt;/P&gt;&lt;P&gt;split-tunnel-network-list value VPN&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;John&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 May 2009 20:23:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/strange-vpn-remote-issue/m-p/1174700#M859953</guid>
      <dc:creator>John Blakley</dc:creator>
      <dc:date>2009-05-11T20:23:05Z</dc:date>
    </item>
    <item>
      <title>Re: Strange VPN Remote Issue</title>
      <link>https://community.cisco.com/t5/network-security/strange-vpn-remote-issue/m-p/1174701#M859954</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I tried that too , but no Luck . So i went ahead and opened a Case with TAC ,I will keep you posted on  it ..But again thanks a ton for helping me on this issue , if you ever visit Atlanta ,Beer is on me .&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 12 May 2009 01:27:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/strange-vpn-remote-issue/m-p/1174701#M859954</guid>
      <dc:creator>ciscosom</dc:creator>
      <dc:date>2009-05-12T01:27:10Z</dc:date>
    </item>
    <item>
      <title>Re: Strange VPN Remote Issue</title>
      <link>https://community.cisco.com/t5/network-security/strange-vpn-remote-issue/m-p/1174702#M859955</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can u try specific networks rather then using "any" in your nat0 acl?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 12 May 2009 19:22:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/strange-vpn-remote-issue/m-p/1174702#M859955</guid>
      <dc:creator>nomair_83</dc:creator>
      <dc:date>2009-05-12T19:22:50Z</dc:date>
    </item>
    <item>
      <title>Re: Strange VPN Remote Issue</title>
      <link>https://community.cisco.com/t5/network-security/strange-vpn-remote-issue/m-p/1174703#M859956</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for taking time to go through my Issue nomair . I modified the ip's but  that did not make any differance &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 May 2009 00:10:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/strange-vpn-remote-issue/m-p/1174703#M859956</guid>
      <dc:creator>ciscosom</dc:creator>
      <dc:date>2009-05-13T00:10:59Z</dc:date>
    </item>
  </channel>
</rss>

