<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VPN clients cannot access inside network in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/vpn-clients-cannot-access-inside-network/m-p/1045662#M979663</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for your response.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I tried running the show crypto ipsec sa and this is what I get:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There are no ipsec sas&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 11 Nov 2008 18:59:22 GMT</pubDate>
    <dc:creator>kenzummach</dc:creator>
    <dc:date>2008-11-11T18:59:22Z</dc:date>
    <item>
      <title>VPN clients cannot access inside network</title>
      <link>https://community.cisco.com/t5/network-security/vpn-clients-cannot-access-inside-network/m-p/1045660#M979660</link>
      <description>&lt;P&gt;I have a ASA 5505 that I am using as a VPN appliance.  The outside interface is connected to the DMZ (172.16.2.10) and the inside to our internal network (10.27.1.12).  VPN clients are assigned an address in the range 10.27.2.2-10.27.2.20.  A 1841 is the router and firewall for the network.  Recently the ASA lost power when a UPS went down and now VPN clients can no longer access anything on the inside network.  Config is attached. Help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 11:05:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-clients-cannot-access-inside-network/m-p/1045660#M979660</guid>
      <dc:creator>kenzummach</dc:creator>
      <dc:date>2020-02-21T11:05:37Z</dc:date>
    </item>
    <item>
      <title>Re: VPN clients cannot access inside network</title>
      <link>https://community.cisco.com/t5/network-security/vpn-clients-cannot-access-inside-network/m-p/1045661#M979662</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do a show crypto ipsec sa and look for packets encrypts and decrypts. If you are seeing decrypts and no encrypts, then check the routing on the IP Address that you are trying to access through the VPN Client. Could be the end host that you are trying to access does not know how to route the packets back to the ASA for the VPN Client Pool.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Arul&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;*Pls rate if it helps*&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 11 Nov 2008 18:49:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-clients-cannot-access-inside-network/m-p/1045661#M979662</guid>
      <dc:creator>ajagadee</dc:creator>
      <dc:date>2008-11-11T18:49:02Z</dc:date>
    </item>
    <item>
      <title>Re: VPN clients cannot access inside network</title>
      <link>https://community.cisco.com/t5/network-security/vpn-clients-cannot-access-inside-network/m-p/1045662#M979663</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for your response.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I tried running the show crypto ipsec sa and this is what I get:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There are no ipsec sas&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 11 Nov 2008 18:59:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-clients-cannot-access-inside-network/m-p/1045662#M979663</guid>
      <dc:creator>kenzummach</dc:creator>
      <dc:date>2008-11-11T18:59:22Z</dc:date>
    </item>
    <item>
      <title>Re: VPN clients cannot access inside network</title>
      <link>https://community.cisco.com/t5/network-security/vpn-clients-cannot-access-inside-network/m-p/1045663#M979665</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I realized after I posted that I should have a connection active when running this command.  Here is the results:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Result of the command: "show crypto ipsec sa"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface: outside&lt;/P&gt;&lt;P&gt;    Crypto map tag: outside_dyn_map, seq num: 20, local addr: 172.16.2.10&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;      local ident (addr/mask/prot/port): (0.0.0.0/0.0.0.0/0/0)&lt;/P&gt;&lt;P&gt;      remote ident (addr/mask/prot/port): (10.27.2.2/255.255.255.255/0/0)&lt;/P&gt;&lt;P&gt;      current_peer: 169.130.14.253, username: kenz&lt;/P&gt;&lt;P&gt;      dynamic allocated peer ip: 10.27.2.2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;      #pkts encaps: 5, #pkts encrypt: 5, #pkts digest: 5&lt;/P&gt;&lt;P&gt;      #pkts decaps: 0, #pkts decrypt: 0, #pkts verify: 0&lt;/P&gt;&lt;P&gt;      #pkts compressed: 0, #pkts decompressed: 0&lt;/P&gt;&lt;P&gt;      #pkts not compressed: 5, #pkts comp failed: 0, #pkts decomp failed: 0&lt;/P&gt;&lt;P&gt;      #pre-frag successes: 0, #pre-frag failures: 0, #fragments created: 0&lt;/P&gt;&lt;P&gt;      #PMTUs sent: 0, #PMTUs rcvd: 0, #decapsulated frgs needing reassembly: 0&lt;/P&gt;&lt;P&gt;      #send errors: 0, #recv errors: 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;      local crypto endpt.: 172.16.2.10, remote crypto endpt.: 169.130.14.253&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;      path mtu 1500, ipsec overhead 58, media mtu 1500&lt;/P&gt;&lt;P&gt;      current outbound spi: 208F45F5&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;    inbound esp sas:&lt;/P&gt;&lt;P&gt;      spi: 0x2026D973 (539416947)&lt;/P&gt;&lt;P&gt;         transform: esp-3des esp-sha-hmac none &lt;/P&gt;&lt;P&gt;         in use settings ={RA, Tunnel, }&lt;/P&gt;&lt;P&gt;         slot: 0, conn_id: 4096, crypto-map: outside_dyn_map&lt;/P&gt;&lt;P&gt;         sa timing: remaining key lifetime (sec): 28406&lt;/P&gt;&lt;P&gt;         IV size: 8 bytes&lt;/P&gt;&lt;P&gt;         replay detection support: Y&lt;/P&gt;&lt;P&gt;    outbound esp sas:&lt;/P&gt;&lt;P&gt;      spi: 0x208F45F5 (546260469)&lt;/P&gt;&lt;P&gt;         transform: esp-3des esp-sha-hmac none &lt;/P&gt;&lt;P&gt;         in use settings ={RA, Tunnel, }&lt;/P&gt;&lt;P&gt;         slot: 0, conn_id: 4096, crypto-map: outside_dyn_map&lt;/P&gt;&lt;P&gt;         sa timing: remaining key lifetime (sec): 28406&lt;/P&gt;&lt;P&gt;         IV size: 8 bytes&lt;/P&gt;&lt;P&gt;         replay detection support: Y&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So it looks like there are encrypts but no decrypts.  What should I do now?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 11 Nov 2008 20:07:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-clients-cannot-access-inside-network/m-p/1045663#M979665</guid>
      <dc:creator>kenzummach</dc:creator>
      <dc:date>2008-11-11T20:07:20Z</dc:date>
    </item>
  </channel>
</rss>

