cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1183
Views
1
Helpful
7
Replies

VLANS across site-to-site not letting traffic to flow between each

newbutnot
Level 1
Level 1

ASDM user - Configured site=to-site using FP1120 but traffic is not flowing to vlans which are identical other than 2nd octet at both locations. Both crypto map and Profiles are using same encyrtion and NAT exception. But I am unable to ping or rdp anything from site to site. Lastly, there are ACL rules in place to allow traffic. What am I missing?

7 Replies 7

newbutnot
Level 1
Level 1

Both sites have ASA 1120 BTW. I have confirmed the tunnel is up by looking at monitoring/sessions. I can see the tunnel active. 

Acl in one side must mirror not must be same'

Are you sure config acl for ipsec correct?

When looking at the ACL Manager under Site to Site, I do see differences. Is this what you are referring to? 

Can you share acl of both sides?

Unfortunately, not on a forum. But here is an error:

5Mar 31 202315:59:1230501310.167.x.x4990610.166.x.x3389Asymmetric NAT rules matched for forward and reverse flows; Connection for tcp src outside:10.167.x.x/49906 dst lcot:10.166.10.35/3389 denied due to NAT reverse path failure

that simple 
you use exception NAT but there is other NAT above it effect the return traffic 
only check the order the order of NAT you config 

Hello,

post the NAT rules for both sides (change the IP addresses and interface names if you don't want them to be public).

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: