12-02-2023 03:51 PM
Moved cisco firewall to new location and now cannot connect to the VPN, Does anyone know how to fix this issue? In down state now. I still have to clean configs, but wanted to get this in place. So I moved the firewall from Atlanta Georgia to Jacksonville Florida into a Colo. I switched IP addresses and still cannot connect to VPN. I am new to this and not sure what I am doing.
Solved! Go to Solution.
12-03-2023 09:56 AM
@coreillycisco reconfigure your interface Gi0/4 and set the new default route.
interface GigabitEthernet0/4
nameif Flexential
security-level 0
ip address 72.15.233.228 255.255.255.248
route Flexential 0 0 72.15.233.225
Remove you other default route via the incorrect next hop.
12-02-2023 03:53 PM
Vpn s2s or anyconnect ?
Can you share config?
MHM
12-02-2023 03:59 PM
12-02-2023 05:08 PM
You have vti and ipsec vpn' many command lines you have.
But let start from basic
Do you check reachability' since I think public IP of outside interface change?
Do you modify peer config to match your IP change?
Try clear crypto (for ipsec s2s vpn)
MHM
12-02-2023 05:17 PM
I can ping the IP 72.15.233.225. I do not know where peer config is. I am using ASDM. How do I clear crypto with ASDM?
12-02-2023 05:31 PM
In the ASDM
12-02-2023 05:37 PM
12-03-2023 07:25 AM
12-03-2023 07:31 AM
@coreillycisco you do not appear to have a default route via your outside interface "Flexential" in your configuration and the error from your debugs below confirms it failed to find the next hop address:
6|Dec 03 2023|10:19:27|110003|Ifc||40.70.3.44|62465|Routing failed to locate next hop for udp from NP Identity Ifc:72.15.233.225/62465 to Flexential:40.70.3.44/62465
Create a default route, example:-
route Flexential 0 0 <next hop ip address>
12-03-2023 08:21 AM
I am new to cisco and using what they have. They use ASDM. And I am not sure what next hop ip i need to be using. The ones I try say cannot be routed.
12-03-2023 08:26 AM
@coreillycisco you need to use the IP address of the upstream router (your ISP) as the next hop. The only usable IP addresses in the public network of the Flexential interface are - 72.15.233.225 - 72.15.233.230, so it's either .226, .227, .228, .229 or .230
12-03-2023 08:30 AM
Would this be to my Internal subnet? Such as: route Flexential 0.0.0.0 0.0.0.0 10.1.3.1 1
12-03-2023 08:34 AM
@coreillycisco no, 10.1.3.1 1 isn't even in the same network as the Flexential interface (Gi0/4) .You need a default route to the internet via the Flexential interface - which is in the 72.15.233.225/28 network, therefore the next hop is either .226, .227, .228, .229 or .230.
12-03-2023 08:35 AM
Ok, Yeah I see what you are saying. Been a long week. I will add that route.
12-03-2023 08:43 AM
So I now have the route as: route Flexential 0.0.0.0 0.0.0.0 72.15.233.226 1
Is there somewhere else I have to change for anyconnect?
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide