cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
Announcements

Welcome to Cisco Firewalls Community


335
Views
0
Helpful
4
Replies
Beginner

Syslog ID 106006

Hey Guys;

 

Hopefully I can get some help here with this issue; as my head is spinning around in circles in trying to figure this out; long story short. My friend and I are doing a site 2 site vpn using a 1900 cisco router >>> Cisco Fw >>>> Vpn Net. I believe I have the correct routes on my router and fw; but whenever my friend tests the vpn I keep getting "Deny inbound UDP from ISP/500 to FriendsWan/60710 on interface OUT. I have allowed all ports all interfaces to test routes; but I keep getting the same message as my friend can't vpn connect. Please can someone look over my setup and see where im doing wrong or what can I do to fix this; this is my only project left is vpn setup and this is killing me (lol)...

 

Please see attachment for Fw and Router

 

Thanks 

 

Everyone's tags (1)
4 REPLIES 4
Highlighted
VIP Advisor

Re: Syslog ID 106006

looks like one of the device behind NAT.look at this URL and make changes accordingly..

 

https://packetpushers.net/site-site-ipsec-vpn-nat/

 

BB
*** Rate All Helpful Responses ***
Highlighted
VIP Advisor

Re: Syslog ID 106006

Where is the vpn terminated, on fw or router. If on firewall, did you apply
the crypto map to isp interface and have you enabled isakmp or ikev1 on isp
interface
Highlighted
Beginner

Re: Syslog ID 106006

 

Hello;

Could it be possible that my nat is a problem on my firewall; i tried exempting it and it didn't work; i tried enable ip,upd,tcp on all interfaces still doesn't work; but i can always see the traffic when my friend tries vpn connection to me

 

Thanks 

Highlighted
Beginner

Re: Syslog ID 106006

Hello;
 it seems like when my friend starts the vpn connection it dies and ends once its hits my firewall; and only maps i have is on my router to start the initiated vpn. 

Thanks 

CreatePlease to create content
Content for Community-Ad
FusionCharts will render here