<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco VPN client with ASA behind Router in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cisco-vpn-client-with-asa-behind-router/m-p/1231615#M874913</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How is ASA nat-ed through router? How many public ip's do you have?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If there is only one public ip that you should do port mapping and map UDP ports 500 and 4500 from asa to public ip. If there are more then one public ip then you can do one to one nat and then it should work if there are no access-lists.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;OK?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 17 Mar 2009 18:49:01 GMT</pubDate>
    <dc:creator>veljko.tasic</dc:creator>
    <dc:date>2009-03-17T18:49:01Z</dc:date>
    <item>
      <title>Cisco VPN client with ASA behind Router</title>
      <link>https://community.cisco.com/t5/network-security/cisco-vpn-client-with-asa-behind-router/m-p/1231614#M874910</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;here it's my scenario:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cisco VPNClient--&amp;gt; INET --&amp;gt; Cisco 877 --&amp;gt;ASA 5520.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And I can't connect with the ASA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I make a test with this scenario:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cisco VPNClient--&amp;gt;ASA 5520. and the VPN works.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think the problem it's on the router Â¿what ports must I open ? (or what aditional config)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks in advance&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 15:06:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-vpn-client-with-asa-behind-router/m-p/1231614#M874910</guid>
      <dc:creator>carlosjlopez</dc:creator>
      <dc:date>2019-03-11T15:06:03Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco VPN client with ASA behind Router</title>
      <link>https://community.cisco.com/t5/network-security/cisco-vpn-client-with-asa-behind-router/m-p/1231615#M874913</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How is ASA nat-ed through router? How many public ip's do you have?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If there is only one public ip that you should do port mapping and map UDP ports 500 and 4500 from asa to public ip. If there are more then one public ip then you can do one to one nat and then it should work if there are no access-lists.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;OK?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Mar 2009 18:49:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-vpn-client-with-asa-behind-router/m-p/1231615#M874913</guid>
      <dc:creator>veljko.tasic</dc:creator>
      <dc:date>2009-03-17T18:49:01Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco VPN client with ASA behind Router</title>
      <link>https://community.cisco.com/t5/network-security/cisco-vpn-client-with-asa-behind-router/m-p/1231616#M874915</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi tasic,&lt;/P&gt;&lt;P&gt;I only have one public IP, and I map 500 and 4500 UDP ports to the ASA from router.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip nat inside source static udp 1XX.XX.XX.1 500 interface ATM0.1 500&lt;/P&gt;&lt;P&gt;ip nat inside source static udp 1XX.XX.XX.1 4500 interface ATM0.1 4500&lt;/P&gt;&lt;P&gt;(where 1XX.XX.XX.1 is ASA IP)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;but nothing happens it says:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Reason 412: The remote peer is no longer responding&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 18 Mar 2009 09:36:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-vpn-client-with-asa-behind-router/m-p/1231616#M874915</guid>
      <dc:creator>carlosjlopez</dc:creator>
      <dc:date>2009-03-18T09:36:31Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco VPN client with ASA behind Router</title>
      <link>https://community.cisco.com/t5/network-security/cisco-vpn-client-with-asa-behind-router/m-p/1231617#M874919</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Do you have access-list on router outside interface?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You should add to asa&lt;/P&gt;&lt;P&gt;crypto isakmp nat-traversal  20&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;After that you should start troubleshooting to see what is happening. That is maximum from my side without configs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 18 Mar 2009 10:29:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-vpn-client-with-asa-behind-router/m-p/1231617#M874919</guid>
      <dc:creator>veljko.tasic</dc:creator>
      <dc:date>2009-03-18T10:29:32Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco VPN client with ASA behind Router</title>
      <link>https://community.cisco.com/t5/network-security/cisco-vpn-client-with-asa-behind-router/m-p/1231618#M874923</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi again&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I tried with crypto isakmp nat-traversal 20  but nothing happens, I think that my problem is in the router side.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;here is my router config:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;in my ATM:&lt;/P&gt;&lt;P&gt;ip nat inside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and my nat rules are:&lt;/P&gt;&lt;P&gt;ip nat inside source static udp X.X.20.1 500 interface ATM0.1 500&lt;/P&gt;&lt;P&gt;ip nat inside source static udp X.X.20.1 4500 interface ATM0.1 4500&lt;/P&gt;&lt;P&gt;ip nat inside source static udp X.X.20.1 10000 interface ATM0.1 10000&lt;/P&gt;&lt;P&gt;ip nat inside source static udp X.X.20.1 62515 interface ATM0.1 62515&lt;/P&gt;&lt;P&gt;ip nat inside source static tcp X.X.20.1 10000 interface ATM0.1 10000&lt;/P&gt;&lt;P&gt;ip nat inside source static esp X.X.20.1 interface ATM0.1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;where X.X.20.1 is my ASA&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;or maybe my problem is in cisco VPN client configuration:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I selected in transport tab:&lt;/P&gt;&lt;P&gt;Enable Transparent tunneling and IPSEC over UDP&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 24 Mar 2009 10:45:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-vpn-client-with-asa-behind-router/m-p/1231618#M874923</guid>
      <dc:creator>carlosjlopez</dc:creator>
      <dc:date>2009-03-24T10:45:31Z</dc:date>
    </item>
  </channel>
</rss>

