cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
328
Views
0
Helpful
2
Replies

ASA ping host to host

p.maillot
Level 1
Level 1

Hello,

I have a problem with this configuration.

172.16.1.2 > ASA5510 > Router 2811 > ASA5505 > 172.16.2.2

ASA5510 can ping host 172.16.1.2 and host 172.16.2.2

ASS5505 can ping host 172.16.2.2 and host 172.16.1.2

but host 172.16.2.2 cannot ping host 172.16.1.2, why?

See the attached file.

Regards

2 Replies 2

p.maillot
Level 1
Level 1

Nobody have an idea?

Regards

My config is.

Host 172.16.1.0/x > ASA 5510 > Router 2811 > Router 871 > ASA5505 > Host 172.16.2.0/x

I have a VPN between Router 2811 and 871

When I ping host 172.16.2.2 from host 172.16.1.2, I can see on router 2811

%CRYPTO-4-IKMP_BAD_MESSAGE: IKE message from 10.52.72.135 failed its sanity check or is malformed

From host 172.16.1.2 to host 172.16.2.2, I can see on router 871

%CRYPTO-4-IKMP_BAD_MESSAGE: IKE message from 10.52.72.129 failed its sanity check or is malformed

What is the problem? VPN encryption is blocked by the ASA?

Regards

Review Cisco Networking products for a $25 gift card