<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VPN between ASA and router in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/vpn-between-asa-and-router/m-p/1066936#M896499</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Joe,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;They didn't change anything from there side! It was fully working exactly before I've migrated to the ASA! &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 11 Sep 2008 18:21:35 GMT</pubDate>
    <dc:creator>georges.merhej</dc:creator>
    <dc:date>2008-09-11T18:21:35Z</dc:date>
    <item>
      <title>VPN between ASA and router</title>
      <link>https://community.cisco.com/t5/network-security/vpn-between-asa-and-router/m-p/1066934#M896497</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I had a working vpn configuration between a local and a remote router; the remote router is not under my administration.&lt;/P&gt;&lt;P&gt;Now I moved the vpn termination from my side to an ASA5540 software version 8.0(3). The tunnel is up but there is no reachability. The "show crypto ipsec sa" on the ASA shows encapsulated packets but NO decapsulated packets! Routing and no_nat are properly configured.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any idea?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Many thanks. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 13:43:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-between-asa-and-router/m-p/1066934#M896497</guid>
      <dc:creator>georges.merhej</dc:creator>
      <dc:date>2019-03-11T13:43:23Z</dc:date>
    </item>
    <item>
      <title>Re: VPN between ASA and router</title>
      <link>https://community.cisco.com/t5/network-security/vpn-between-asa-and-router/m-p/1066935#M896498</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;without seeing the other side, i suspect a routing issue there.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;does "not under my administration" mean no one there can get on the phone and work the issue with you?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Joe&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Sep 2008 18:09:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-between-asa-and-router/m-p/1066935#M896498</guid>
      <dc:creator>joe19366</dc:creator>
      <dc:date>2008-09-11T18:09:28Z</dc:date>
    </item>
    <item>
      <title>Re: VPN between ASA and router</title>
      <link>https://community.cisco.com/t5/network-security/vpn-between-asa-and-router/m-p/1066936#M896499</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Joe,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;They didn't change anything from there side! It was fully working exactly before I've migrated to the ASA! &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Sep 2008 18:21:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-between-asa-and-router/m-p/1066936#M896499</guid>
      <dc:creator>georges.merhej</dc:creator>
      <dc:date>2008-09-11T18:21:35Z</dc:date>
    </item>
    <item>
      <title>Re: VPN between ASA and router</title>
      <link>https://community.cisco.com/t5/network-security/vpn-between-asa-and-router/m-p/1066937#M896500</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Have you used the packet tracer feature in the ASDM?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would run a packet from source to destination using your adsm and see if it is fully going out as planned.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I suspect a stale xlate on the firewall, perhaps the other side that didnt change is hearing a different source that it wants?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Another option to consider is since the other side is using IOS (right?) they may be using GRE/IPSEC of some type and need to re-config to work with the ASA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Joe&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Sep 2008 18:34:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-between-asa-and-router/m-p/1066937#M896500</guid>
      <dc:creator>joe19366</dc:creator>
      <dc:date>2008-09-11T18:34:04Z</dc:date>
    </item>
    <item>
      <title>Re: VPN between ASA and router</title>
      <link>https://community.cisco.com/t5/network-security/vpn-between-asa-and-router/m-p/1066938#M896501</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I've attached the old router configuration.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Using the packet tracer:&lt;/P&gt;&lt;P&gt;inside-outside -&amp;gt; everything is fine&lt;/P&gt;&lt;P&gt;outside-inside -&amp;gt; ipsec-spoof detected! it's a normal behavior right?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Sep 2008 18:54:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-between-asa-and-router/m-p/1066938#M896501</guid>
      <dc:creator>georges.merhej</dc:creator>
      <dc:date>2008-09-11T18:54:44Z</dc:date>
    </item>
    <item>
      <title>Re: VPN between ASA and router</title>
      <link>https://community.cisco.com/t5/network-security/vpn-between-asa-and-router/m-p/1066939#M896502</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;on the asa do you have the command...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sysop connection permit-ipsec&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Sep 2008 18:57:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-between-asa-and-router/m-p/1066939#M896502</guid>
      <dc:creator>joe19366</dc:creator>
      <dc:date>2008-09-11T18:57:11Z</dc:date>
    </item>
    <item>
      <title>Re: VPN between ASA and router</title>
      <link>https://community.cisco.com/t5/network-security/vpn-between-asa-and-router/m-p/1066940#M896503</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;yeah: sysopt connection permit-vpn ( there is no permit-ipsec)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Sep 2008 19:03:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-between-asa-and-router/m-p/1066940#M896503</guid>
      <dc:creator>georges.merhej</dc:creator>
      <dc:date>2008-09-11T19:03:44Z</dc:date>
    </item>
    <item>
      <title>Re: VPN between ASA and router</title>
      <link>https://community.cisco.com/t5/network-security/vpn-between-asa-and-router/m-p/1066941#M896504</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;For traffic that enters the security appliance through a VPN tunnel and is then decrypted, the sysopt connection permit-vpn command in global configuration mode to allow the traffic to bypass interface access lists. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;can you do some debug on the ASA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;debug crypto ipsec and debug crypto isakmp and send us the output&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;francisco&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Sep 2008 19:12:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-between-asa-and-router/m-p/1066941#M896504</guid>
      <dc:creator>francisco_1</dc:creator>
      <dc:date>2008-09-11T19:12:38Z</dc:date>
    </item>
    <item>
      <title>Re: VPN between ASA and router</title>
      <link>https://community.cisco.com/t5/network-security/vpn-between-asa-and-router/m-p/1066942#M896506</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;my next educated guess;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;turn off nat-t on the ASA the other side may not support it, not have it configured or UDP 4500 may filtered somewhere in the path&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;no crypto isakmp nat-traversal&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;now clear ipsec sa on the sa, and continue testing... send interesting traffic to bring the tunnel back up&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Sep 2008 19:14:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-between-asa-and-router/m-p/1066942#M896506</guid>
      <dc:creator>joe19366</dc:creator>
      <dc:date>2008-09-11T19:14:22Z</dc:date>
    </item>
    <item>
      <title>Re: VPN between ASA and router</title>
      <link>https://community.cisco.com/t5/network-security/vpn-between-asa-and-router/m-p/1066943#M896507</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;try "no crypto isakmp nat-traversal"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;francisco&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Sep 2008 19:18:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-between-asa-and-router/m-p/1066943#M896507</guid>
      <dc:creator>francisco_1</dc:creator>
      <dc:date>2008-09-11T19:18:30Z</dc:date>
    </item>
    <item>
      <title>Re: VPN between ASA and router</title>
      <link>https://community.cisco.com/t5/network-security/vpn-between-asa-and-router/m-p/1066944#M896509</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I've configured no crypto isakmp nat-traversal and still no packets are received on the outside. the debug crypto log is attached!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Sep 2008 19:21:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-between-asa-and-router/m-p/1066944#M896509</guid>
      <dc:creator>georges.merhej</dc:creator>
      <dc:date>2008-09-11T19:21:53Z</dc:date>
    </item>
    <item>
      <title>Re: VPN between ASA and router</title>
      <link>https://community.cisco.com/t5/network-security/vpn-between-asa-and-router/m-p/1066945#M896510</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;try from global"clear crypto ipsec sa" and "clear xlate". Also get them to do the same on the other side.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;do a continous ping to the other side &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Sep 2008 19:27:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-between-asa-and-router/m-p/1066945#M896510</guid>
      <dc:creator>francisco_1</dc:creator>
      <dc:date>2008-09-11T19:27:54Z</dc:date>
    </item>
    <item>
      <title>Re: VPN between ASA and router</title>
      <link>https://community.cisco.com/t5/network-security/vpn-between-asa-and-router/m-p/1066946#M896512</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;going back over the notes your provided;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;see the issue now?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;DE-DC-INT-FW01# show crypto ipsec sa&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;    Crypto map tag: IPSec-VPN, seq num: 40, local addr: 213.184.187.98&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and now...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/1&lt;/P&gt;&lt;P&gt; description $ES_WAN$$FW_OUTSIDE$&lt;/P&gt;&lt;P&gt; bandwidth 1000&lt;/P&gt;&lt;P&gt; ip address 213.184.187.98 255.255.255.240&lt;/P&gt;&lt;P&gt; ip access-group 101 in&lt;/P&gt;&lt;P&gt; ip verify unicast reverse-path&lt;/P&gt;&lt;P&gt; no ip redirects&lt;/P&gt;&lt;P&gt; no ip unreachables&lt;/P&gt;&lt;P&gt; no ip proxy-arp&lt;/P&gt;&lt;P&gt; ip virtual-reassembly&lt;/P&gt;&lt;P&gt; ip route-cache flow&lt;/P&gt;&lt;P&gt; ip tcp adjust-mss 1200&lt;/P&gt;&lt;P&gt; crypto map VPN&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;so, my question,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;what is in front of the asa, and does it arp reach the ASA to get to 213.184.187.98?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;where does the ASA has this addr config'd?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Joe&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Sep 2008 19:30:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-between-asa-and-router/m-p/1066946#M896512</guid>
      <dc:creator>joe19366</dc:creator>
      <dc:date>2008-09-11T19:30:17Z</dc:date>
    </item>
    <item>
      <title>Re: VPN between ASA and router</title>
      <link>https://community.cisco.com/t5/network-security/vpn-between-asa-and-router/m-p/1066947#M896515</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;the 213.184.187.98 was the ip address of the outside interface of the router, now the router is removed and the same ip is configured on the outside interface of the ASA.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Sep 2008 19:33:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-between-asa-and-router/m-p/1066947#M896515</guid>
      <dc:creator>georges.merhej</dc:creator>
      <dc:date>2008-09-11T19:33:29Z</dc:date>
    </item>
    <item>
      <title>Re: VPN between ASA and router</title>
      <link>https://community.cisco.com/t5/network-security/vpn-between-asa-and-router/m-p/1066948#M896517</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I noticed you dont have crypto isakmp enable [Inside Interface]&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Sep 2008 19:36:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-between-asa-and-router/m-p/1066948#M896517</guid>
      <dc:creator>francisco_1</dc:creator>
      <dc:date>2008-09-11T19:36:00Z</dc:date>
    </item>
    <item>
      <title>Re: VPN between ASA and router</title>
      <link>https://community.cisco.com/t5/network-security/vpn-between-asa-and-router/m-p/1066949#M896519</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;the vpn is terminated on the outside interface, so there is no need for isakmp on the inside, right?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Sep 2008 19:37:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-between-asa-and-router/m-p/1066949#M896519</guid>
      <dc:creator>georges.merhej</dc:creator>
      <dc:date>2008-09-11T19:37:22Z</dc:date>
    </item>
    <item>
      <title>Re: VPN between ASA and router</title>
      <link>https://community.cisco.com/t5/network-security/vpn-between-asa-and-router/m-p/1066950#M896520</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;mmm yeah. i checked on my lab ASA 5520 on a working tunnel and i have it enable on the inside/outside as well.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Sep 2008 19:47:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-between-asa-and-router/m-p/1066950#M896520</guid>
      <dc:creator>francisco_1</dc:creator>
      <dc:date>2008-09-11T19:47:53Z</dc:date>
    </item>
    <item>
      <title>Re: VPN between ASA and router</title>
      <link>https://community.cisco.com/t5/network-security/vpn-between-asa-and-router/m-p/1066951#M896521</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have tunnels configured and the same interface and working perfectly&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Sep 2008 19:54:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-between-asa-and-router/m-p/1066951#M896521</guid>
      <dc:creator>georges.merhej</dc:creator>
      <dc:date>2008-09-11T19:54:49Z</dc:date>
    </item>
    <item>
      <title>Re: VPN between ASA and router</title>
      <link>https://community.cisco.com/t5/network-security/vpn-between-asa-and-router/m-p/1066952#M896523</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;you mean you have other tunnels active on the ASA?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Sep 2008 19:57:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-between-asa-and-router/m-p/1066952#M896523</guid>
      <dc:creator>francisco_1</dc:creator>
      <dc:date>2008-09-11T19:57:34Z</dc:date>
    </item>
    <item>
      <title>Re: VPN between ASA and router</title>
      <link>https://community.cisco.com/t5/network-security/vpn-between-asa-and-router/m-p/1066953#M896525</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;right, so the router is gone, but&lt;/P&gt;&lt;P&gt;what device is in front of the ASA?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What interface is the 213. address on? outside?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Sep 2008 19:57:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-between-asa-and-router/m-p/1066953#M896525</guid>
      <dc:creator>joe19366</dc:creator>
      <dc:date>2008-09-11T19:57:47Z</dc:date>
    </item>
  </channel>
</rss>

