<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: side-to-side vpn only comunicating in one direction in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/side-to-side-vpn-only-comunicating-in-one-direction/m-p/1293634#M950833</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;NW-Polen 255.255.255.0 &lt;/P&gt;&lt;P&gt;access-list outside_3_cryptomap extended permit ip NW-Buchholz 255.255.255.0 NW-INTEX 255.255.255.0 &lt;/P&gt;&lt;P&gt;access-list outside_4_cryptomap extended permit ip NW-Buchholz 255.255.255.0 NW-Martinnet 255.255.255.0 &lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit icmp any any log notifications &lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit ip object-group DM_INLINE_NETWORK_1 NW-Buchholz 255.255.255.0 &lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit udp object-group DM_INLINE_NETWORK_2 NW-Buchholz 255.255.255.0 &lt;/P&gt;&lt;P&gt;access-list outside_cryptomap_1 extended permit ip NW-Buchholz 255.255.255.0 NW-Muenster 255.255.255.0 &lt;/P&gt;&lt;P&gt;access-list outside_cryptomap_2 extended permit ip NW-Buchholz 255.255.255.0 NW-Muenster 255.255.255.0 &lt;/P&gt;&lt;P&gt;access-list inside_nat0_outbound_1 extended permit ip NW-Buchholz 255.255.255.0 NW-Muenster 255.255.255.0 &lt;/P&gt;&lt;P&gt;pager lines 24&lt;/P&gt;&lt;P&gt;logging enable&lt;/P&gt;&lt;P&gt;logging asdm informational&lt;/P&gt;&lt;P&gt;no logging message 302021&lt;/P&gt;&lt;P&gt;no logging message 302020&lt;/P&gt;&lt;P&gt;mtu inside 1500&lt;/P&gt;&lt;P&gt;mtu outside 1500&lt;/P&gt;&lt;P&gt;mtu dmz 1500&lt;/P&gt;&lt;P&gt;ip local pool makeIT 192.168.116.100-192.168.116.110 mask 255.255.255.0&lt;/P&gt;&lt;P&gt;ip local pool VPN-Brands-Admin 192.168.117.100-192.168.117.110 mask 255.255.255.0&lt;/P&gt;&lt;P&gt;ip local pool VPN-Brands-GS 192.168.118.100-192.168.118.110 mask 255.255.255.0&lt;/P&gt;&lt;P&gt;ip local pool VPN-Extern 192.168.121.100-192.168.121.110 mask 255.255.255.0&lt;/P&gt;&lt;P&gt;ip local pool VPN-Brands-Sales 192.168.119.100-192.168.119.110 mask 255.255.255.0&lt;/P&gt;&lt;P&gt;ip local pool VPN-Brands-CM 192.168.120.100-192.168.120.110 mask 255.255.255.0&lt;/P&gt;&lt;P&gt;icmp unreachable rate-limit 1 burst-size 1&lt;/P&gt;&lt;P&gt;asdm image disk0:/asdm-621.bin&lt;/P&gt;&lt;P&gt;no asdm history enable&lt;/P&gt;&lt;P&gt;arp timeout 14400&lt;/P&gt;&lt;P&gt;global (outside) 1 interface&lt;/P&gt;&lt;P&gt;nat (inside) 0 access-list inside_nat0_outbound&lt;/P&gt;&lt;P&gt;nat (inside) 0 access-list inside_nat0_outbound_1 outside&lt;/P&gt;&lt;P&gt;nat (inside) 1 0.0.0.0 0.0.0.0&lt;/P&gt;&lt;P&gt;access-group outside_access_in in interface outside&lt;/P&gt;&lt;P&gt;route outside 0.0.0.0 0.0.0.0 85.112.230.125 1&lt;/P&gt;&lt;P&gt;timeout xlate 3:00:00&lt;/P&gt;&lt;P&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02&lt;/P&gt;&lt;P&gt;timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00&lt;/P&gt;&lt;P&gt;timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00&lt;/P&gt;&lt;P&gt;timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute&lt;/P&gt;&lt;P&gt;timeout tcp-proxy-reassembly 0:01:00&lt;/P&gt;&lt;P&gt;dynamic-access-policy-record DfltAccessPolicy&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 27 Jul 2009 06:11:41 GMT</pubDate>
    <dc:creator>NadineMeins</dc:creator>
    <dc:date>2009-07-27T06:11:41Z</dc:date>
    <item>
      <title>side-to-side vpn only comunicating in one direction</title>
      <link>https://community.cisco.com/t5/network-security/side-to-side-vpn-only-comunicating-in-one-direction/m-p/1293631#M950830</link>
      <description>&lt;P&gt;Hi all together,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My problem is that I have a running vpn connection between cisco asa 5505 and a LANCOM 1711 VPN that is only letting traffic through in one direction. Meaning I can ping and act via Windows RDP from the net behind the Cisco (net 192.168.115.0/255.255.255.0) to the LANCOM-net (192.168.0.0./255.255.255.0) but it is not working in the other direction.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On the Cisco net there has been used an other LANCOM before und the VPN was working without problems. We now just took the configuration and fixed it to the Cisco. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And as the tunnel is established I do not see the reason why the LANCOM packages do not come though. In the Syslog of the Cisco there is no reaction.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can anybody help?&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 11:35:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/side-to-side-vpn-only-comunicating-in-one-direction/m-p/1293631#M950830</guid>
      <dc:creator>NadineMeins</dc:creator>
      <dc:date>2020-02-21T11:35:21Z</dc:date>
    </item>
    <item>
      <title>Re: side-to-side vpn only comunicating in one direction</title>
      <link>https://community.cisco.com/t5/network-security/side-to-side-vpn-only-comunicating-in-one-direction/m-p/1293632#M950831</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This could be due to numerous reasons routing related, NAT in the transit path, ESP being blocked, can you post your configurations? Also have you enabled NAT-T?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also have a look at:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/ps6120/products_tech_note09186a00807e0aca.shtml#Solution11" target="_blank"&gt;http://www.cisco.com/en/US/products/ps6120/products_tech_note09186a00807e0aca.shtml#Solution11&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Farrukh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 25 Jul 2009 05:38:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/side-to-side-vpn-only-comunicating-in-one-direction/m-p/1293632#M950831</guid>
      <dc:creator>Farrukh Haroon</dc:creator>
      <dc:date>2009-07-25T05:38:31Z</dc:date>
    </item>
    <item>
      <title>Re: side-to-side vpn only comunicating in one direction</title>
      <link>https://community.cisco.com/t5/network-security/side-to-side-vpn-only-comunicating-in-one-direction/m-p/1293633#M950832</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thx for replying.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is my configuration:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; Saved&lt;/P&gt;&lt;P&gt;:&lt;/P&gt;&lt;P&gt;ASA Version 8.2(1) &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;hostname ASABrandsDEBU&lt;/P&gt;&lt;P&gt;domain-name brands.local&lt;/P&gt;&lt;P&gt;enable password fuuwAM47BOb7KkRB encrypted&lt;/P&gt;&lt;P&gt;passwd 906qOuTz0f2InvIK encrypted&lt;/P&gt;&lt;P&gt;names&lt;/P&gt;&lt;P&gt;name 85.112.230.6x Internet description Internet&lt;/P&gt;&lt;P&gt;name 192.168.116.96 VPN-makeIT description VPN-makeIT&lt;/P&gt;&lt;P&gt;name 192.168.115.10 SRV-BrandsS01 description SRV-BrandsS01&lt;/P&gt;&lt;P&gt;name 192.168.115.30 SRV-BrandsS03 description SRV-BrandsS03&lt;/P&gt;&lt;P&gt;name 192.168.115.25 SRV-Testserver description SRV-Testserver&lt;/P&gt;&lt;P&gt;name 217.146.152.10x GW-INTEX description GW-INTEX&lt;/P&gt;&lt;P&gt;name 62.153.136.22x GW-Martinnet description GW-Martinnet&lt;/P&gt;&lt;P&gt;name 62.72.79.19x GW-Muenster description GW-Muenster&lt;/P&gt;&lt;P&gt;name 213.76.140.222 GW-Polen description GW-Polen&lt;/P&gt;&lt;P&gt;name 192.168.115.0 NW-Buchholz description NW-Buchholz&lt;/P&gt;&lt;P&gt;name 192.168.114.0 NW-DMZ description NW-DMZ&lt;/P&gt;&lt;P&gt;name 192.168.0.0 NW-Muenster description NW-Muenster&lt;/P&gt;&lt;P&gt;name 192.168.19.0 NW-Polen description NW-Polen&lt;/P&gt;&lt;P&gt;name 192.168.117.96 VPN-Brands-Admin description VPN-Brands-Admin&lt;/P&gt;&lt;P&gt;name 192.168.120.96 VPN-Brands-CM description VPN-Brands-CM&lt;/P&gt;&lt;P&gt;name 192.168.118.96 VPN-Brands-GS description VPN-Brands-GS&lt;/P&gt;&lt;P&gt;name 192.168.119.96 VPN-Brands-Sales description VPN-Brands-Sales&lt;/P&gt;&lt;P&gt;name 192.168.121.96 VPN-Extern description VPN-Extern&lt;/P&gt;&lt;P&gt;name 194.49.23.0 NW-INTEX description NW-INTEX&lt;/P&gt;&lt;P&gt;name 212.185.56.0 NW-Martinnet description NW-Martinnet&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlan1&lt;/P&gt;&lt;P&gt; nameif inside&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt; ip address 192.168.115.1 255.255.255.0 &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlan2&lt;/P&gt;&lt;P&gt; nameif outside&lt;/P&gt;&lt;P&gt; security-level 0&lt;/P&gt;&lt;P&gt; ip address 85.112.230.12x 255.255.255.252 &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlan3&lt;/P&gt;&lt;P&gt; no forward interface Vlan1&lt;/P&gt;&lt;P&gt; nameif dmz&lt;/P&gt;&lt;P&gt; security-level 50&lt;/P&gt;&lt;P&gt; ip address 192.168.114.1 255.255.255.0 &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/0&lt;/P&gt;&lt;P&gt; switchport access vlan 2&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/1&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/2&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/3&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/4&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/5&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/6&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/7&lt;/P&gt;&lt;P&gt; switchport access vlan 3&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;boot system disk0:/asa821-k8.bin&lt;/P&gt;&lt;P&gt;ftp mode passive&lt;/P&gt;&lt;P&gt;clock timezone CEST 1&lt;/P&gt;&lt;P&gt;clock summer-time CEDT recurring last Sun Mar 2:00 last Sun Oct 3:00&lt;/P&gt;&lt;P&gt;dns domain-lookup inside&lt;/P&gt;&lt;P&gt;dns domain-lookup outside&lt;/P&gt;&lt;P&gt;dns domain-lookup dmz&lt;/P&gt;&lt;P&gt;dns server-group DefaultDNS&lt;/P&gt;&lt;P&gt; domain-name brands.local&lt;/P&gt;&lt;P&gt;same-security-traffic permit intra-interface&lt;/P&gt;&lt;P&gt;object-group network DM_INLINE_NETWORK_1&lt;/P&gt;&lt;P&gt; network-object NW-Muenster 255.255.255.0&lt;/P&gt;&lt;P&gt; network-object host GW-Muenster&lt;/P&gt;&lt;P&gt;object-group network DM_INLINE_NETWORK_2&lt;/P&gt;&lt;P&gt; network-object NW-Muenster 255.255.255.0&lt;/P&gt;&lt;P&gt; network-object host GW-Muenster&lt;/P&gt;&lt;P&gt;access-list makeIT_splitTunnelAcl standard permit NW-Buchholz 255.255.255.0 &lt;/P&gt;&lt;P&gt;access-list inside_nat0_outbound extended permit ip NW-Buchholz 255.255.255.0 VPN-makeIT 255.255.255.240 &lt;/P&gt;&lt;P&gt;access-list inside_nat0_outbound extended permit ip NW-Buchholz 255.255.255.0 VPN-Brands-Admin 255.255.255.240 &lt;/P&gt;&lt;P&gt;access-list inside_nat0_outbound extended permit ip NW-Buchholz 255.255.255.0 VPN-Brands-GS 255.255.255.240 &lt;/P&gt;&lt;P&gt;access-list inside_nat0_outbound extended permit ip NW-Buchholz 255.255.255.0 VPN-Brands-Sales 255.255.255.240 &lt;/P&gt;&lt;P&gt;access-list inside_nat0_outbound extended permit ip NW-Buchholz 255.255.255.0 VPN-Brands-CM 255.255.255.240 &lt;/P&gt;&lt;P&gt;access-list inside_nat0_outbound extended permit ip NW-Buchholz 255.255.255.0 VPN-Extern 255.255.255.240 &lt;/P&gt;&lt;P&gt;access-list inside_nat0_outbound extended permit ip NW-Buchholz 255.255.255.0 NW-Polen 255.255.255.0 &lt;/P&gt;&lt;P&gt;access-list inside_nat0_outbound extended permit ip NW-Buchholz 255.255.255.0 NW-Martinnet 255.255.255.0 &lt;/P&gt;&lt;P&gt;access-list Brands-Admin_splitTunnelAcl standard permit NW-Buchholz 255.255.255.0 &lt;/P&gt;&lt;P&gt;access-list Brands-GS_splitTunnelAcl standard permit NW-Buchholz 255.255.255.0 &lt;/P&gt;&lt;P&gt;access-list Brands-Sales_splitTunnelAcl standard permit NW-Buchholz 255.255.255.0 &lt;/P&gt;&lt;P&gt;access-list Brands-CM_splitTunnelAcl standard permit NW-Buchholz 255.255.255.0 &lt;/P&gt;&lt;P&gt;access-list Extern_splitTunnelAcl standard permit NW-Buchholz 255.255.255.0 &lt;/P&gt;&lt;P&gt;access-list outside_cryptomap extended permit ip NW-Buchholz 255.255.255.0 NW-Muenster 255.255.255.0 &lt;/P&gt;&lt;P&gt;access-list outside_2_cryptomap extended permit ip NW-Buchholz 255.255.255.0 &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 27 Jul 2009 06:10:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/side-to-side-vpn-only-comunicating-in-one-direction/m-p/1293633#M950832</guid>
      <dc:creator>NadineMeins</dc:creator>
      <dc:date>2009-07-27T06:10:38Z</dc:date>
    </item>
    <item>
      <title>Re: side-to-side vpn only comunicating in one direction</title>
      <link>https://community.cisco.com/t5/network-security/side-to-side-vpn-only-comunicating-in-one-direction/m-p/1293634#M950833</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;NW-Polen 255.255.255.0 &lt;/P&gt;&lt;P&gt;access-list outside_3_cryptomap extended permit ip NW-Buchholz 255.255.255.0 NW-INTEX 255.255.255.0 &lt;/P&gt;&lt;P&gt;access-list outside_4_cryptomap extended permit ip NW-Buchholz 255.255.255.0 NW-Martinnet 255.255.255.0 &lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit icmp any any log notifications &lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit ip object-group DM_INLINE_NETWORK_1 NW-Buchholz 255.255.255.0 &lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit udp object-group DM_INLINE_NETWORK_2 NW-Buchholz 255.255.255.0 &lt;/P&gt;&lt;P&gt;access-list outside_cryptomap_1 extended permit ip NW-Buchholz 255.255.255.0 NW-Muenster 255.255.255.0 &lt;/P&gt;&lt;P&gt;access-list outside_cryptomap_2 extended permit ip NW-Buchholz 255.255.255.0 NW-Muenster 255.255.255.0 &lt;/P&gt;&lt;P&gt;access-list inside_nat0_outbound_1 extended permit ip NW-Buchholz 255.255.255.0 NW-Muenster 255.255.255.0 &lt;/P&gt;&lt;P&gt;pager lines 24&lt;/P&gt;&lt;P&gt;logging enable&lt;/P&gt;&lt;P&gt;logging asdm informational&lt;/P&gt;&lt;P&gt;no logging message 302021&lt;/P&gt;&lt;P&gt;no logging message 302020&lt;/P&gt;&lt;P&gt;mtu inside 1500&lt;/P&gt;&lt;P&gt;mtu outside 1500&lt;/P&gt;&lt;P&gt;mtu dmz 1500&lt;/P&gt;&lt;P&gt;ip local pool makeIT 192.168.116.100-192.168.116.110 mask 255.255.255.0&lt;/P&gt;&lt;P&gt;ip local pool VPN-Brands-Admin 192.168.117.100-192.168.117.110 mask 255.255.255.0&lt;/P&gt;&lt;P&gt;ip local pool VPN-Brands-GS 192.168.118.100-192.168.118.110 mask 255.255.255.0&lt;/P&gt;&lt;P&gt;ip local pool VPN-Extern 192.168.121.100-192.168.121.110 mask 255.255.255.0&lt;/P&gt;&lt;P&gt;ip local pool VPN-Brands-Sales 192.168.119.100-192.168.119.110 mask 255.255.255.0&lt;/P&gt;&lt;P&gt;ip local pool VPN-Brands-CM 192.168.120.100-192.168.120.110 mask 255.255.255.0&lt;/P&gt;&lt;P&gt;icmp unreachable rate-limit 1 burst-size 1&lt;/P&gt;&lt;P&gt;asdm image disk0:/asdm-621.bin&lt;/P&gt;&lt;P&gt;no asdm history enable&lt;/P&gt;&lt;P&gt;arp timeout 14400&lt;/P&gt;&lt;P&gt;global (outside) 1 interface&lt;/P&gt;&lt;P&gt;nat (inside) 0 access-list inside_nat0_outbound&lt;/P&gt;&lt;P&gt;nat (inside) 0 access-list inside_nat0_outbound_1 outside&lt;/P&gt;&lt;P&gt;nat (inside) 1 0.0.0.0 0.0.0.0&lt;/P&gt;&lt;P&gt;access-group outside_access_in in interface outside&lt;/P&gt;&lt;P&gt;route outside 0.0.0.0 0.0.0.0 85.112.230.125 1&lt;/P&gt;&lt;P&gt;timeout xlate 3:00:00&lt;/P&gt;&lt;P&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02&lt;/P&gt;&lt;P&gt;timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00&lt;/P&gt;&lt;P&gt;timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00&lt;/P&gt;&lt;P&gt;timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute&lt;/P&gt;&lt;P&gt;timeout tcp-proxy-reassembly 0:01:00&lt;/P&gt;&lt;P&gt;dynamic-access-policy-record DfltAccessPolicy&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 27 Jul 2009 06:11:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/side-to-side-vpn-only-comunicating-in-one-direction/m-p/1293634#M950833</guid>
      <dc:creator>NadineMeins</dc:creator>
      <dc:date>2009-07-27T06:11:41Z</dc:date>
    </item>
    <item>
      <title>Re: side-to-side vpn only comunicating in one direction</title>
      <link>https://community.cisco.com/t5/network-security/side-to-side-vpn-only-comunicating-in-one-direction/m-p/1293635#M950834</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;http server enable&lt;/P&gt;&lt;P&gt;http NW-Buchholz 255.255.255.0 inside&lt;/P&gt;&lt;P&gt;no snmp-server location&lt;/P&gt;&lt;P&gt;no snmp-server contact&lt;/P&gt;&lt;P&gt;snmp-server enable traps snmp authentication linkup linkdown coldstart&lt;/P&gt;&lt;P&gt;crypto ipsec transform-set ESP-AES-128-SHA esp-aes esp-sha-hmac &lt;/P&gt;&lt;P&gt;crypto ipsec transform-set ESP-AES-256-MD5 esp-aes-256 esp-md5-hmac &lt;/P&gt;&lt;P&gt;crypto ipsec transform-set ESP-DES-MD5 esp-des esp-md5-hmac &lt;/P&gt;&lt;P&gt;crypto ipsec transform-set ESP-AES-256-SHA esp-aes-256 esp-sha-hmac &lt;/P&gt;&lt;P&gt;crypto ipsec transform-set ESP-AES-128-MD5 esp-aes esp-md5-hmac &lt;/P&gt;&lt;P&gt;crypto ipsec transform-set ESP-DES-SHA esp-des esp-sha-hmac &lt;/P&gt;&lt;P&gt;crypto ipsec transform-set ESP-AES-192-MD5 esp-aes-192 esp-md5-hmac &lt;/P&gt;&lt;P&gt;crypto ipsec transform-set ESP-AES-192-SHA esp-aes-192 esp-sha-hmac &lt;/P&gt;&lt;P&gt;crypto ipsec transform-set ESP-3DES-SHA esp-3des esp-sha-hmac &lt;/P&gt;&lt;P&gt;crypto ipsec transform-set ESP-3DES-MD5 esp-3des esp-md5-hmac &lt;/P&gt;&lt;P&gt;crypto ipsec security-association lifetime seconds 28800&lt;/P&gt;&lt;P&gt;crypto ipsec security-association lifetime kilobytes 4608000&lt;/P&gt;&lt;P&gt;crypto dynamic-map SYSTEM_DEFAULT_CRYPTO_MAP 65535 set pfs &lt;/P&gt;&lt;P&gt;crypto dynamic-map SYSTEM_DEFAULT_CRYPTO_MAP 65535 set transform-set ESP-AES-128-SHA ESP-AES-128-MD5 ESP-AES-192-SHA ESP-AES-192-MD5 ESP-AES-256-SHA ESP-AES-256-MD5 ESP-3DES-SHA ESP-3DES-MD5 ESP-DES-SHA ESP-DES-MD5&lt;/P&gt;&lt;P&gt;crypto map outside_map 1 match address outside_cryptomap_2&lt;/P&gt;&lt;P&gt;crypto map outside_map 1 set pfs &lt;/P&gt;&lt;P&gt;crypto map outside_map 1 set peer GW-Muenster &lt;/P&gt;&lt;P&gt;crypto map outside_map 1 set transform-set ESP-3DES-MD5 ESP-AES-128-SHA ESP-AES-128-MD5 ESP-AES-192-SHA ESP-AES-192-MD5 ESP-AES-256-SHA ESP-AES-256-MD5 ESP-3DES-SHA ESP-DES-SHA ESP-DES-MD5&lt;/P&gt;&lt;P&gt;crypto map outside_map 1 set security-association lifetime seconds 43200&lt;/P&gt;&lt;P&gt;crypto map outside_map 1 set security-association lifetime kilobytes 200000&lt;/P&gt;&lt;P&gt;crypto map outside_map 1 set reverse-route&lt;/P&gt;&lt;P&gt;crypto map outside_map 2 match address outside_2_cryptomap&lt;/P&gt;&lt;P&gt;crypto map outside_map 2 set pfs &lt;/P&gt;&lt;P&gt;crypto map outside_map 2 set peer GW-Polen &lt;/P&gt;&lt;P&gt;crypto map outside_map 2 set transform-set ESP-3DES-MD5&lt;/P&gt;&lt;P&gt;crypto map outside_map 2 set security-association lifetime seconds 2013&lt;/P&gt;&lt;P&gt;crypto map outside_map 2 set security-association lifetime kilobytes 200000&lt;/P&gt;&lt;P&gt;crypto map outside_map 3 match address outside_3_cryptomap&lt;/P&gt;&lt;P&gt;crypto map outside_map 3 set pfs group5&lt;/P&gt;&lt;P&gt;crypto map outside_map 3 set peer GW-INTEX &lt;/P&gt;&lt;P&gt;crypto map outside_map 3 set transform-set ESP-AES-128-MD5&lt;/P&gt;&lt;P&gt;crypto map outside_map 3 set security-association lifetime seconds 3600&lt;/P&gt;&lt;P&gt;crypto map outside_map 3 set security-association lifetime kilobytes 200000&lt;/P&gt;&lt;P&gt;crypto map outside_map 4 match address outside_4_cryptomap&lt;/P&gt;&lt;P&gt;crypto map outside_map 4 set pfs &lt;/P&gt;&lt;P&gt;crypto map outside_map 4 set peer GW-Martinnet &lt;/P&gt;&lt;P&gt;crypto map outside_map 4 set transform-set ESP-AES-128-MD5&lt;/P&gt;&lt;P&gt;crypto map outside_map 4 set security-association lifetime seconds 3600&lt;/P&gt;&lt;P&gt;crypto map outside_map 4 set security-association lifetime kilobytes 200000&lt;/P&gt;&lt;P&gt;crypto map outside_map 65535 ipsec-isakmp dynamic SYSTEM_DEFAULT_CRYPTO_MAP&lt;/P&gt;&lt;P&gt;crypto map outside_map interface outside&lt;/P&gt;&lt;P&gt;crypto isakmp enable outside&lt;/P&gt;&lt;P&gt;crypto isakmp policy 10&lt;/P&gt;&lt;P&gt; authentication pre-share&lt;/P&gt;&lt;P&gt; encryption 3des&lt;/P&gt;&lt;P&gt; hash md5&lt;/P&gt;&lt;P&gt; group 2&lt;/P&gt;&lt;P&gt; lifetime none&lt;/P&gt;&lt;P&gt;telnet NW-Buchholz 255.255.255.0 inside&lt;/P&gt;&lt;P&gt;telnet timeout 5&lt;/P&gt;&lt;P&gt;ssh timeout 5&lt;/P&gt;&lt;P&gt;console timeout 0&lt;/P&gt;&lt;P&gt;dhcpd auto_config outside&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;threat-detection basic-threat&lt;/P&gt;&lt;P&gt;threat-detection statistics port&lt;/P&gt;&lt;P&gt;threat-detection statistics protocol&lt;/P&gt;&lt;P&gt;threat-detection statistics access-list&lt;/P&gt;&lt;P&gt;threat-detection statistics tcp-intercept rate-interval 30 burst-rate 400 average-rate 200&lt;/P&gt;&lt;P&gt;webvpn&lt;/P&gt;&lt;P&gt;group-policy Brands-GS internal&lt;/P&gt;&lt;P&gt;group-policy Brands-GS attributes&lt;/P&gt;&lt;P&gt; dns-server value 192.168.115.14 192.168.115.7&lt;/P&gt;&lt;P&gt; vpn-tunnel-protocol IPSec &lt;/P&gt;&lt;P&gt; split-tunnel-policy tunnelspecified&lt;/P&gt;&lt;P&gt; split-tunnel-network-list value Brands-GS_splitTunnelAcl&lt;/P&gt;&lt;P&gt; default-domain value brands.local&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 27 Jul 2009 06:13:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/side-to-side-vpn-only-comunicating-in-one-direction/m-p/1293635#M950834</guid>
      <dc:creator>NadineMeins</dc:creator>
      <dc:date>2009-07-27T06:13:06Z</dc:date>
    </item>
    <item>
      <title>Re: side-to-side vpn only comunicating in one direction</title>
      <link>https://community.cisco.com/t5/network-security/side-to-side-vpn-only-comunicating-in-one-direction/m-p/1293636#M950835</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;group-policy Brands-Sales internal&lt;/P&gt;&lt;P&gt;group-policy Brands-Sales attributes&lt;/P&gt;&lt;P&gt; dns-server value 192.168.115.14 192.168.115.7&lt;/P&gt;&lt;P&gt; vpn-tunnel-protocol IPSec &lt;/P&gt;&lt;P&gt; split-tunnel-policy tunnelspecified&lt;/P&gt;&lt;P&gt; split-tunnel-network-list value Brands-Sales_splitTunnelAcl&lt;/P&gt;&lt;P&gt; default-domain value brands.local&lt;/P&gt;&lt;P&gt;group-policy Brands-CM internal&lt;/P&gt;&lt;P&gt;group-policy Brands-CM attributes&lt;/P&gt;&lt;P&gt; dns-server value 192.168.115.14 192.168.115.7&lt;/P&gt;&lt;P&gt; vpn-tunnel-protocol IPSec &lt;/P&gt;&lt;P&gt; split-tunnel-policy tunnelspecified&lt;/P&gt;&lt;P&gt; split-tunnel-network-list value Brands-CM_splitTunnelAcl&lt;/P&gt;&lt;P&gt; default-domain value brands.local&lt;/P&gt;&lt;P&gt;group-policy Brands-Admin internal&lt;/P&gt;&lt;P&gt;group-policy Brands-Admin attributes&lt;/P&gt;&lt;P&gt; dns-server value 192.168.115.14 192.168.115.7&lt;/P&gt;&lt;P&gt; vpn-tunnel-protocol IPSec &lt;/P&gt;&lt;P&gt; split-tunnel-policy tunnelspecified&lt;/P&gt;&lt;P&gt; split-tunnel-network-list value Brands-Admin_splitTunnelAcl&lt;/P&gt;&lt;P&gt; default-domain value brands.local&lt;/P&gt;&lt;P&gt;group-policy DfltGrpPolicy attributes&lt;/P&gt;&lt;P&gt; vpn-filter value Brands-Sales_splitTunnelAcl&lt;/P&gt;&lt;P&gt; vpn-tunnel-protocol IPSec &lt;/P&gt;&lt;P&gt;group-policy makeIT internal&lt;/P&gt;&lt;P&gt;group-policy makeIT attributes&lt;/P&gt;&lt;P&gt; dns-server value 192.168.115.14 192.168.115.7&lt;/P&gt;&lt;P&gt; vpn-tunnel-protocol IPSec &lt;/P&gt;&lt;P&gt; split-tunnel-policy tunnelspecified&lt;/P&gt;&lt;P&gt; split-tunnel-network-list value makeIT_splitTunnelAcl&lt;/P&gt;&lt;P&gt; default-domain value brands.local&lt;/P&gt;&lt;P&gt;group-policy Extern internal&lt;/P&gt;&lt;P&gt;group-policy Extern attributes&lt;/P&gt;&lt;P&gt; dns-server value 192.168.115.14 192.168.115.7&lt;/P&gt;&lt;P&gt; vpn-tunnel-protocol IPSec &lt;/P&gt;&lt;P&gt; split-tunnel-policy tunnelspecified&lt;/P&gt;&lt;P&gt; split-tunnel-network-list value Extern_splitTunnelAcl&lt;/P&gt;&lt;P&gt; default-domain value brands.local&lt;/P&gt;&lt;P&gt;username system password gC7MwUUDUbHTlU48 encrypted privilege 15&lt;/P&gt;&lt;P&gt;username makeIT password ZBxNX0An9ytNgYIf encrypted privilege 0&lt;/P&gt;&lt;P&gt;username makeIT attributes&lt;/P&gt;&lt;P&gt; vpn-group-policy makeIT&lt;/P&gt;&lt;P&gt;username s.behrendt password l1rPzoB4p6dBQwin encrypted&lt;/P&gt;&lt;P&gt;username s.behrendt attributes&lt;/P&gt;&lt;P&gt; group-lock value Brands-Sales&lt;/P&gt;&lt;P&gt; service-type remote-access&lt;/P&gt;&lt;P&gt;tunnel-group makeIT type remote-access&lt;/P&gt;&lt;P&gt;tunnel-group makeIT general-attributes&lt;/P&gt;&lt;P&gt; address-pool makeIT&lt;/P&gt;&lt;P&gt; default-group-policy makeIT&lt;/P&gt;&lt;P&gt;tunnel-group makeIT ipsec-attributes&lt;/P&gt;&lt;P&gt; pre-shared-key *&lt;/P&gt;&lt;P&gt;tunnel-group Brands-Admin type remote-access&lt;/P&gt;&lt;P&gt;tunnel-group Brands-Admin general-attributes&lt;/P&gt;&lt;P&gt; address-pool VPN-Brands-Admin&lt;/P&gt;&lt;P&gt; default-group-policy Brands-Admin&lt;/P&gt;&lt;P&gt;tunnel-group Brands-Admin ipsec-attributes&lt;/P&gt;&lt;P&gt; pre-shared-key *&lt;/P&gt;&lt;P&gt;tunnel-group Brands-GS type remote-access&lt;/P&gt;&lt;P&gt;tunnel-group Brands-GS general-attributes&lt;/P&gt;&lt;P&gt; address-pool VPN-Brands-GS&lt;/P&gt;&lt;P&gt; default-group-policy Brands-GS&lt;/P&gt;&lt;P&gt;tunnel-group Brands-GS ipsec-attributes&lt;/P&gt;&lt;P&gt; pre-shared-key *&lt;/P&gt;&lt;P&gt;tunnel-group Brands-Sales type remote-access&lt;/P&gt;&lt;P&gt;tunnel-group Brands-Sales general-attributes&lt;/P&gt;&lt;P&gt; address-pool VPN-Brands-Sales&lt;/P&gt;&lt;P&gt; default-group-policy Brands-Sales&lt;/P&gt;&lt;P&gt;tunnel-group Brands-Sales ipsec-attributes&lt;/P&gt;&lt;P&gt; pre-shared-key *&lt;/P&gt;&lt;P&gt;tunnel-group Brands-CM type remote-access&lt;/P&gt;&lt;P&gt;tunnel-group Brands-CM general-attributes&lt;/P&gt;&lt;P&gt; address-pool VPN-Brands-CM&lt;/P&gt;&lt;P&gt; default-group-policy Brands-CM&lt;/P&gt;&lt;P&gt;tunnel-group Brands-CM ipsec-attributes&lt;/P&gt;&lt;P&gt; pre-shared-key *&lt;/P&gt;&lt;P&gt;tunnel-group Extern type remote-access&lt;/P&gt;&lt;P&gt;tunnel-group Extern general-attributes&lt;/P&gt;&lt;P&gt; address-pool VPN-Extern&lt;/P&gt;&lt;P&gt; default-group-policy Extern&lt;/P&gt;&lt;P&gt;tunnel-group Extern ipsec-attributes&lt;/P&gt;&lt;P&gt; pre-shared-key *&lt;/P&gt;&lt;P&gt;tunnel-group 62.72.79.19x type ipsec-l2l&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;tunnel-group 62.72.79.19x ipsec-attributes&lt;/P&gt;&lt;P&gt; pre-shared-key *&lt;/P&gt;&lt;P&gt; isakmp keepalive disable&lt;/P&gt;&lt;P&gt;tunnel-group 213.76.140.22x type ipsec-l2l&lt;/P&gt;&lt;P&gt;tunnel-group 213.76.140.22x ipsec-attributes&lt;/P&gt;&lt;P&gt; pre-shared-key *&lt;/P&gt;&lt;P&gt;tunnel-group 217.146.152.10x type ipsec-l2l&lt;/P&gt;&lt;P&gt;tunnel-group 217.146.152.10x ipsec-attributes&lt;/P&gt;&lt;P&gt; pre-shared-key *&lt;/P&gt;&lt;P&gt;tunnel-group 62.153.136.22x type ipsec-l2l&lt;/P&gt;&lt;P&gt;tunnel-group 62.153.136.22x ipsec-attributes&lt;/P&gt;&lt;P&gt; pre-shared-key *&lt;/P&gt;&lt;P&gt;tunnel-group GW-Muenster type ipsec-l2l&lt;/P&gt;&lt;P&gt;tunnel-group GW-Muenster ipsec-attributes&lt;/P&gt;&lt;P&gt; pre-shared-key *&lt;/P&gt;&lt;P&gt; peer-id-validate nocheck&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;class-map inspection_default&lt;/P&gt;&lt;P&gt; match default-inspection-traffic&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;policy-map type inspect dns preset_dns_map&lt;/P&gt;&lt;P&gt; parameters&lt;/P&gt;&lt;P&gt;  message-length maximum 512&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 27 Jul 2009 06:15:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/side-to-side-vpn-only-comunicating-in-one-direction/m-p/1293636#M950835</guid>
      <dc:creator>NadineMeins</dc:creator>
      <dc:date>2009-07-27T06:15:08Z</dc:date>
    </item>
    <item>
      <title>Re: side-to-side vpn only comunicating in one direction</title>
      <link>https://community.cisco.com/t5/network-security/side-to-side-vpn-only-comunicating-in-one-direction/m-p/1293637#M950836</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;policy-map global_policy&lt;/P&gt;&lt;P&gt; class inspection_default&lt;/P&gt;&lt;P&gt;  inspect dns preset_dns_map &lt;/P&gt;&lt;P&gt;  inspect ftp &lt;/P&gt;&lt;P&gt;  inspect h323 h225 &lt;/P&gt;&lt;P&gt;  inspect h323 ras &lt;/P&gt;&lt;P&gt;  inspect rsh &lt;/P&gt;&lt;P&gt;  inspect rtsp &lt;/P&gt;&lt;P&gt;  inspect esmtp &lt;/P&gt;&lt;P&gt;  inspect sqlnet &lt;/P&gt;&lt;P&gt;  inspect skinny  &lt;/P&gt;&lt;P&gt;  inspect sunrpc &lt;/P&gt;&lt;P&gt;  inspect xdmcp &lt;/P&gt;&lt;P&gt;  inspect sip  &lt;/P&gt;&lt;P&gt;  inspect netbios &lt;/P&gt;&lt;P&gt;  inspect tftp &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;service-policy global_policy global&lt;/P&gt;&lt;P&gt;prompt hostname context &lt;/P&gt;&lt;P&gt;Cryptochecksum:469d3ac0a382f10168df95e82daf916a&lt;/P&gt;&lt;P&gt;: end&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In addition: The problems I have wit NW-Muenster and GW-Muenster. The others have not been tested jet. NAT-T is enabled.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks a lot!&lt;/P&gt;&lt;P&gt;Nadine&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 27 Jul 2009 06:20:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/side-to-side-vpn-only-comunicating-in-one-direction/m-p/1293637#M950836</guid>
      <dc:creator>NadineMeins</dc:creator>
      <dc:date>2009-07-27T06:20:24Z</dc:date>
    </item>
  </channel>
</rss>

