<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Need Urgent help for configuring VPN in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/need-urgent-help-for-configuring-vpn/m-p/939222#M919384</link>
    <description>&lt;P&gt;Hi there &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have ASA 5510 in the Headoffice with static IP and ASA 5505 in the remote site behind ADSL router , trying to establish VPN but its failing in phase 1 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Config of Head Office &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface Ethernet0/0 &lt;/P&gt;&lt;P&gt;description Link to LeaseLine Router &lt;/P&gt;&lt;P&gt;nameif outside &lt;/P&gt;&lt;P&gt;security-level 0 &lt;/P&gt;&lt;P&gt;ip address x.x.x.x 255.255.255.248 &lt;/P&gt;&lt;P&gt;! &lt;/P&gt;&lt;P&gt;interface Ethernet0/1 &lt;/P&gt;&lt;P&gt;description Link to Internal LAN &lt;/P&gt;&lt;P&gt;nameif inside &lt;/P&gt;&lt;P&gt;security-level 100 &lt;/P&gt;&lt;P&gt;ip address 172.17.1.15 255.255.255.0 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list inside_nat0_outbound_1 extended permit ip 172.17.1.0 255.255.255.0 172.20.1.0 255.255.255.0 &lt;/P&gt;&lt;P&gt;access-list inside_nat0_outbound_1 extended permit ip 172.17.1.0 255.255.255.0 172.19.1.0 255.255.255.0 &lt;/P&gt;&lt;P&gt;access-list vpn_to_remote extended permit ip 172.17.1.0 255.255.255.0 172.19.1.0 255.255.255.0 &lt;/P&gt;&lt;P&gt;access-list VPN extended permit ip 172.17.1.0 255.255.255.0 172.20.1.0 255.255.255.0 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;global (outside) 1 interface &lt;/P&gt;&lt;P&gt;nat (inside) 0 access-list inside_nat0_outbound_1 &lt;/P&gt;&lt;P&gt;nat (inside) 1 0.0.0.0 0.0.0.0 &lt;/P&gt;&lt;P&gt;route outside 0.0.0.0 0.0.0.0 x.x.x.x 1 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;crypto ipsec transform-set esp-aes-256-md5 esp-aes-256 esp-md5-hmac &lt;/P&gt;&lt;P&gt;crypto ipsec transform-set ESP-AES-256-SHA esp-aes-256 esp-sha-hmac &lt;/P&gt;&lt;P&gt;crypto dynamic-map cisco 1 match address VPN &lt;/P&gt;&lt;P&gt;crypto dynamic-map cisco 1 set transform-set ESP-AES-256-SHA &lt;/P&gt;&lt;P&gt;crypto map outside_map 10 match address vpn_to_remote &lt;/P&gt;&lt;P&gt;crypto map outside_map 10 set pfs &lt;/P&gt;&lt;P&gt;crypto map outside_map 10 set peer y.y.y.y &lt;/P&gt;&lt;P&gt;crypto map outside_map 10 set transform-set esp-aes-256-md5 &lt;/P&gt;&lt;P&gt;crypto map outside_map 10 set reverse-route &lt;/P&gt;&lt;P&gt;crypto map outside_map 30 ipsec-isakmp dynamic cisco &lt;/P&gt;&lt;P&gt;crypto map outside_map interface outside &lt;/P&gt;&lt;P&gt;crypto isakmp identity address &lt;/P&gt;&lt;P&gt;crypto isakmp enable outside &lt;/P&gt;&lt;P&gt;crypto isakmp policy 10 &lt;/P&gt;&lt;P&gt;authentication pre-share &lt;/P&gt;&lt;P&gt;encryption aes-256 &lt;/P&gt;&lt;P&gt;hash md5 &lt;/P&gt;&lt;P&gt;group 5 &lt;/P&gt;&lt;P&gt;lifetime 86400 &lt;/P&gt;&lt;P&gt;crypto isakmp policy 20 &lt;/P&gt;&lt;P&gt;authentication pre-share &lt;/P&gt;&lt;P&gt;encryption aes &lt;/P&gt;&lt;P&gt;hash md5 &lt;/P&gt;&lt;P&gt;group 2 &lt;/P&gt;&lt;P&gt;lifetime 86400 &lt;/P&gt;&lt;P&gt;crypto isakmp policy 30 &lt;/P&gt;&lt;P&gt;authentication pre-share &lt;/P&gt;&lt;P&gt;encryption aes-256 &lt;/P&gt;&lt;P&gt;hash sha &lt;/P&gt;&lt;P&gt;group 2 &lt;/P&gt;&lt;P&gt;lifetime 86400 &lt;/P&gt;&lt;P&gt;crypto isakmp nat-traversal 20 &lt;/P&gt;&lt;P&gt;tunnel-group y.y.y.y type ipsec-l2l &lt;/P&gt;&lt;P&gt;tunnel-group y.y.y.y ipsec-attributes &lt;/P&gt;&lt;P&gt;pre-shared-key * &lt;/P&gt;&lt;P&gt;tunnel-group parkplace type ipsec-l2l &lt;/P&gt;&lt;P&gt;tunnel-group parkplace ipsec-attributes &lt;/P&gt;&lt;P&gt;pre-shared-key * &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Config of Remote Site &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface Vlan1 &lt;/P&gt;&lt;P&gt;nameif inside &lt;/P&gt;&lt;P&gt;security-level 100 &lt;/P&gt;&lt;P&gt;ip address 172.20.1.1 255.255.255.0 &lt;/P&gt;&lt;P&gt;! &lt;/P&gt;&lt;P&gt;interface Vlan2 &lt;/P&gt;&lt;P&gt;nameif outside &lt;/P&gt;&lt;P&gt;security-level 0 &lt;/P&gt;&lt;P&gt;ip address 192.168.1.2 255.255.255.0 &lt;/P&gt;&lt;P&gt;! &lt;/P&gt;&lt;P&gt;interface Ethernet0/0 &lt;/P&gt;&lt;P&gt;switchport access vlan 2 &lt;/P&gt;&lt;P&gt;! &lt;/P&gt;&lt;P&gt;interface Ethernet0/1 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list ICMP extended permit icmp any any &lt;/P&gt;&lt;P&gt;access-list NONAT extended permit ip 172.20.1.0 255.255.255.0 172.17.1.0 255.255.255.0 &lt;/P&gt;&lt;P&gt;access-list VPN extended permit ip 172.20.1.0 255.255.255.0 172.17.1.0 255.255.255.0 &lt;/P&gt;&lt;P&gt;global (outside) 1 interface &lt;/P&gt;&lt;P&gt;nat (inside) 0 access-list NONAT &lt;/P&gt;&lt;P&gt;nat (inside) 1 0.0.0.0 0.0.0.0 outside &lt;/P&gt;&lt;P&gt;access-group ICMP in interface outside &lt;/P&gt;&lt;P&gt;route outside 0.0.0.0 0.0.0.0 192.168.1.1 1 &lt;/P&gt;&lt;P&gt;crypto ipsec transform-set ESP-AES-256-SHA esp-aes-256 esp-sha-hmac &lt;/P&gt;&lt;P&gt;crypto map outside_map 1 match address VPN &lt;/P&gt;&lt;P&gt;crypto map outside_map 1 set peer 83.111.252.242 &lt;/P&gt;&lt;P&gt;crypto map outside_map 1 set transform-set ESP-AES-256-SHA &lt;/P&gt;&lt;P&gt;crypto map outside_map interface outside &lt;/P&gt;&lt;P&gt;crypto isakmp enable outside &lt;/P&gt;&lt;P&gt;crypto isakmp policy 10 &lt;/P&gt;&lt;P&gt;authentication pre-share &lt;/P&gt;&lt;P&gt;encryption aes-256 &lt;/P&gt;&lt;P&gt;hash sha &lt;/P&gt;&lt;P&gt;group 2 &lt;/P&gt;&lt;P&gt;lifetime 86400 &lt;/P&gt;&lt;P&gt;crypto isakmp nat-traversal 20 &lt;/P&gt;&lt;P&gt;tunnel-group fairmount type ipsec-l2l &lt;/P&gt;&lt;P&gt;tunnel-group fairmount ipsec-attributes &lt;/P&gt;&lt;P&gt;pre-shared-key * &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards/Asfar&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 12:51:19 GMT</pubDate>
    <dc:creator>asfar.zaidi</dc:creator>
    <dc:date>2019-03-11T12:51:19Z</dc:date>
    <item>
      <title>Need Urgent help for configuring VPN</title>
      <link>https://community.cisco.com/t5/network-security/need-urgent-help-for-configuring-vpn/m-p/939222#M919384</link>
      <description>&lt;P&gt;Hi there &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have ASA 5510 in the Headoffice with static IP and ASA 5505 in the remote site behind ADSL router , trying to establish VPN but its failing in phase 1 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Config of Head Office &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface Ethernet0/0 &lt;/P&gt;&lt;P&gt;description Link to LeaseLine Router &lt;/P&gt;&lt;P&gt;nameif outside &lt;/P&gt;&lt;P&gt;security-level 0 &lt;/P&gt;&lt;P&gt;ip address x.x.x.x 255.255.255.248 &lt;/P&gt;&lt;P&gt;! &lt;/P&gt;&lt;P&gt;interface Ethernet0/1 &lt;/P&gt;&lt;P&gt;description Link to Internal LAN &lt;/P&gt;&lt;P&gt;nameif inside &lt;/P&gt;&lt;P&gt;security-level 100 &lt;/P&gt;&lt;P&gt;ip address 172.17.1.15 255.255.255.0 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list inside_nat0_outbound_1 extended permit ip 172.17.1.0 255.255.255.0 172.20.1.0 255.255.255.0 &lt;/P&gt;&lt;P&gt;access-list inside_nat0_outbound_1 extended permit ip 172.17.1.0 255.255.255.0 172.19.1.0 255.255.255.0 &lt;/P&gt;&lt;P&gt;access-list vpn_to_remote extended permit ip 172.17.1.0 255.255.255.0 172.19.1.0 255.255.255.0 &lt;/P&gt;&lt;P&gt;access-list VPN extended permit ip 172.17.1.0 255.255.255.0 172.20.1.0 255.255.255.0 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;global (outside) 1 interface &lt;/P&gt;&lt;P&gt;nat (inside) 0 access-list inside_nat0_outbound_1 &lt;/P&gt;&lt;P&gt;nat (inside) 1 0.0.0.0 0.0.0.0 &lt;/P&gt;&lt;P&gt;route outside 0.0.0.0 0.0.0.0 x.x.x.x 1 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;crypto ipsec transform-set esp-aes-256-md5 esp-aes-256 esp-md5-hmac &lt;/P&gt;&lt;P&gt;crypto ipsec transform-set ESP-AES-256-SHA esp-aes-256 esp-sha-hmac &lt;/P&gt;&lt;P&gt;crypto dynamic-map cisco 1 match address VPN &lt;/P&gt;&lt;P&gt;crypto dynamic-map cisco 1 set transform-set ESP-AES-256-SHA &lt;/P&gt;&lt;P&gt;crypto map outside_map 10 match address vpn_to_remote &lt;/P&gt;&lt;P&gt;crypto map outside_map 10 set pfs &lt;/P&gt;&lt;P&gt;crypto map outside_map 10 set peer y.y.y.y &lt;/P&gt;&lt;P&gt;crypto map outside_map 10 set transform-set esp-aes-256-md5 &lt;/P&gt;&lt;P&gt;crypto map outside_map 10 set reverse-route &lt;/P&gt;&lt;P&gt;crypto map outside_map 30 ipsec-isakmp dynamic cisco &lt;/P&gt;&lt;P&gt;crypto map outside_map interface outside &lt;/P&gt;&lt;P&gt;crypto isakmp identity address &lt;/P&gt;&lt;P&gt;crypto isakmp enable outside &lt;/P&gt;&lt;P&gt;crypto isakmp policy 10 &lt;/P&gt;&lt;P&gt;authentication pre-share &lt;/P&gt;&lt;P&gt;encryption aes-256 &lt;/P&gt;&lt;P&gt;hash md5 &lt;/P&gt;&lt;P&gt;group 5 &lt;/P&gt;&lt;P&gt;lifetime 86400 &lt;/P&gt;&lt;P&gt;crypto isakmp policy 20 &lt;/P&gt;&lt;P&gt;authentication pre-share &lt;/P&gt;&lt;P&gt;encryption aes &lt;/P&gt;&lt;P&gt;hash md5 &lt;/P&gt;&lt;P&gt;group 2 &lt;/P&gt;&lt;P&gt;lifetime 86400 &lt;/P&gt;&lt;P&gt;crypto isakmp policy 30 &lt;/P&gt;&lt;P&gt;authentication pre-share &lt;/P&gt;&lt;P&gt;encryption aes-256 &lt;/P&gt;&lt;P&gt;hash sha &lt;/P&gt;&lt;P&gt;group 2 &lt;/P&gt;&lt;P&gt;lifetime 86400 &lt;/P&gt;&lt;P&gt;crypto isakmp nat-traversal 20 &lt;/P&gt;&lt;P&gt;tunnel-group y.y.y.y type ipsec-l2l &lt;/P&gt;&lt;P&gt;tunnel-group y.y.y.y ipsec-attributes &lt;/P&gt;&lt;P&gt;pre-shared-key * &lt;/P&gt;&lt;P&gt;tunnel-group parkplace type ipsec-l2l &lt;/P&gt;&lt;P&gt;tunnel-group parkplace ipsec-attributes &lt;/P&gt;&lt;P&gt;pre-shared-key * &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Config of Remote Site &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface Vlan1 &lt;/P&gt;&lt;P&gt;nameif inside &lt;/P&gt;&lt;P&gt;security-level 100 &lt;/P&gt;&lt;P&gt;ip address 172.20.1.1 255.255.255.0 &lt;/P&gt;&lt;P&gt;! &lt;/P&gt;&lt;P&gt;interface Vlan2 &lt;/P&gt;&lt;P&gt;nameif outside &lt;/P&gt;&lt;P&gt;security-level 0 &lt;/P&gt;&lt;P&gt;ip address 192.168.1.2 255.255.255.0 &lt;/P&gt;&lt;P&gt;! &lt;/P&gt;&lt;P&gt;interface Ethernet0/0 &lt;/P&gt;&lt;P&gt;switchport access vlan 2 &lt;/P&gt;&lt;P&gt;! &lt;/P&gt;&lt;P&gt;interface Ethernet0/1 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list ICMP extended permit icmp any any &lt;/P&gt;&lt;P&gt;access-list NONAT extended permit ip 172.20.1.0 255.255.255.0 172.17.1.0 255.255.255.0 &lt;/P&gt;&lt;P&gt;access-list VPN extended permit ip 172.20.1.0 255.255.255.0 172.17.1.0 255.255.255.0 &lt;/P&gt;&lt;P&gt;global (outside) 1 interface &lt;/P&gt;&lt;P&gt;nat (inside) 0 access-list NONAT &lt;/P&gt;&lt;P&gt;nat (inside) 1 0.0.0.0 0.0.0.0 outside &lt;/P&gt;&lt;P&gt;access-group ICMP in interface outside &lt;/P&gt;&lt;P&gt;route outside 0.0.0.0 0.0.0.0 192.168.1.1 1 &lt;/P&gt;&lt;P&gt;crypto ipsec transform-set ESP-AES-256-SHA esp-aes-256 esp-sha-hmac &lt;/P&gt;&lt;P&gt;crypto map outside_map 1 match address VPN &lt;/P&gt;&lt;P&gt;crypto map outside_map 1 set peer 83.111.252.242 &lt;/P&gt;&lt;P&gt;crypto map outside_map 1 set transform-set ESP-AES-256-SHA &lt;/P&gt;&lt;P&gt;crypto map outside_map interface outside &lt;/P&gt;&lt;P&gt;crypto isakmp enable outside &lt;/P&gt;&lt;P&gt;crypto isakmp policy 10 &lt;/P&gt;&lt;P&gt;authentication pre-share &lt;/P&gt;&lt;P&gt;encryption aes-256 &lt;/P&gt;&lt;P&gt;hash sha &lt;/P&gt;&lt;P&gt;group 2 &lt;/P&gt;&lt;P&gt;lifetime 86400 &lt;/P&gt;&lt;P&gt;crypto isakmp nat-traversal 20 &lt;/P&gt;&lt;P&gt;tunnel-group fairmount type ipsec-l2l &lt;/P&gt;&lt;P&gt;tunnel-group fairmount ipsec-attributes &lt;/P&gt;&lt;P&gt;pre-shared-key * &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards/Asfar&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 12:51:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/need-urgent-help-for-configuring-vpn/m-p/939222#M919384</guid>
      <dc:creator>asfar.zaidi</dc:creator>
      <dc:date>2019-03-11T12:51:19Z</dc:date>
    </item>
    <item>
      <title>Re: Need Urgent help for configuring VPN</title>
      <link>https://community.cisco.com/t5/network-security/need-urgent-help-for-configuring-vpn/m-p/939223#M919385</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Asfar&lt;/P&gt;&lt;P&gt;   1)Remote site has a tunnel-group name called "fairmount". Assuming that you refer to your head office with faimount, Tunnel-group name must be same with peer ip, so you should do the following modification&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;clear config tunnel-group fairmount type ipsec-l2l &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;tunnel-group 83.111.252.242 type ipsec-l2l&lt;/P&gt;&lt;P&gt;tunnel-group fairmount ipsec-attributes &lt;/P&gt;&lt;P&gt;pre-shared-key *&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;    2)If doesnt work after above suggestion, try using a transform set different than ESP-AES-SHA in both locations&lt;/P&gt;&lt;P&gt;    3)Change pre shraed key to 1 and keep like that untill you resolve the connectivity problem. Then you can change to a more secure value.&lt;/P&gt;&lt;P&gt;    4) If still no joy, ensure that UDP port 4500 tcp port 10000 and udp/tcp 500 are forwarded to 192.168.1.2 in router 192.168.1.1 in remote office&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 28 May 2008 14:18:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/need-urgent-help-for-configuring-vpn/m-p/939223#M919385</guid>
      <dc:creator>Alan Huseyin Kayahan</dc:creator>
      <dc:date>2008-05-28T14:18:29Z</dc:date>
    </item>
    <item>
      <title>Re: Need Urgent help for configuring VPN</title>
      <link>https://community.cisco.com/t5/network-security/need-urgent-help-for-configuring-vpn/m-p/939224#M919386</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks the problem is resolved&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 29 May 2008 22:40:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/need-urgent-help-for-configuring-vpn/m-p/939224#M919386</guid>
      <dc:creator>asfar.zaidi</dc:creator>
      <dc:date>2008-05-29T22:40:08Z</dc:date>
    </item>
    <item>
      <title>Re: Need Urgent help for configuring VPN</title>
      <link>https://community.cisco.com/t5/network-security/need-urgent-help-for-configuring-vpn/m-p/939225#M919387</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi asfar,&lt;/P&gt;&lt;P&gt;  Why did you rate 2?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 29 May 2008 23:39:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/need-urgent-help-for-configuring-vpn/m-p/939225#M919387</guid>
      <dc:creator>Alan Huseyin Kayahan</dc:creator>
      <dc:date>2008-05-29T23:39:07Z</dc:date>
    </item>
  </channel>
</rss>

