cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
589
Views
10
Helpful
5
Replies

IPSEC TUNNEL IS UP AND CAN PING PEER TUNNEL BUT CANT PING DESTINATION

arjun_4790
Level 1
Level 1

Hello

i have configured IPsec tunnel between ASA and Branch router.

can ping peer tunnel and ping is not working from branch host to asa internal host but asa internal host can ping host in branch.

could anyone help with this??

i have shared tunnel configuration of ASA and Branch below

Thank you!!

5 Replies 5

balaji.bandi
Hall of Fame
Hall of Fame

what is the source IP and what is the Destination IP you trying to PING

how does your config looks like,

Branch side i see encrypting packet, i do not see any descrytpiton

at main ASA i dont see any of them.

so check the ACL and config again..make sure source and destination part of VPN domain.

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

tunnel is up and acl's are also fine!

could u check acl which i have given below

arjun_4790
Level 1
Level 1

source ip is 198.133.219.35 which is from branch and destination host ip is 192.168.10.1 internal host of ASA

acl of ASA:

access-list VPN extended permit ip host 192.168.10.1 host 198.133.219.35

acl of branch:

access-list 101 permit ip host 198.133.219.35 host 192.168.10.1

arjun_4790
Level 1
Level 1

Capture1.PNG

 

topology.

there are many reason but 
can I see the ASA config ?

Review Cisco Networking for a $25 gift card