Heads Up :
The post you are writing will appear in a public forum. Please ensure all content is appropriate for public consumption. Review the employee guidelines for the community here.
Hi,
Been trying for a week to make this work, but alas I cannot and so I ask for help.
I have two separate IKEv1 tunnels setup between our hub ASA 5509 and two different AWS VPCs in different regions. The goal is to have the two VPCs route between...
Hi,
I have a Windows 2012R2 NPS server acting as a RADIUS box and can't get anything other than PAP to work for auth. I only need RADIUS for admin authentication to the ASA (ASA 5506-X) and not for VPN connections.
Anyone know what I need to do on t...
Hi,
Trying to sort out a configuration issue, but don't have boatloads of experience to sort it out.
The tunnel seems to come up, but I get "output crypto map check failed" when trying to ping a remote host.
Pretty simple site-to-site, here is a sc...
Fixed.
Not sure exactly what it was, but I made sure all the protected subnets matched in our two AWS VPCs and on the ASA. Also cleaned up ACLs and disabled NAT-T on the tunnels.
Likely it was a subnet summarizing that was causing my error above.
Hi Rahul,
I applied the nat rule:
nat (outside,outside) 1 source static awzn_vpc awzn_vpc destination static AWS-VPC-CA AWS-VPC-CA no-proxy-arp route-lookup
It returned a warning:
WARNING: Pool (10.25.0.0-10.25.255.255) overlap with existing pool.WAR...
Still having the issue, but I have determined that is our partner's end and we are waiting on them to make some changes so that we can test it.
I will update this thread once we get closure.
Thanks,
Hi Aditya,
Was away for a few days vacation, but I am back at it. Still having issues and here is my running config:
Current configuration : 4154 bytes!version 12.4service timestamps debug datetime msecservice timestamps log datetime msecno service p...