Heads Up :
The post you are writing will appear in a public forum. Please ensure all content is appropriate for public consumption. Review the employee guidelines for the community here.
Hi,We have a customer who has a point2point IPSEC vpn to ourselves. Its been working fine for the last year. However they recently purchased a new external IP address and as such I created a new connection profile for them with the new IP address. Th...
If ACS is configured to authenticate to two backed external authentication DBs, namely Windows A/D and RSA SecureID, is it possible to send the authentication request received by ACS from a AAA client to one or the other rather than only having the o...
hopefully this all makes sense ! extract of the config etc, and packet tracer outputABCCOMPANY = specific addresses on my sideABCCOMPANY_IPSEC = ABCCOMPANY's addressesaccess-list transit_outbound_nat0_acl extended permit ip object-group ABCCOMPANY_Ac...
Hi Eugene,I'd rather not post the config as its 1000s lines long.I've ran the clear crypto ipsec & clear crypto isakmp. This morning a 2nd VPN connection is having the same issue is the log
%ASA-3-713042: IKE Initiator unable to find policy: Intf
in...
Just to update this further - on the tunnel policy for the new IP - I added in the 2nd peer of the old IP address. and now all is working. The customer has assured me the old IP is disconnected at their side, so I can only assume somewhere the ASA is...
Hi Eugene,I removed both entries old IP entry/crypto map and new IP entry/crypto - I then re-created a new profile using the higher priority (lower number) for the new IP address. Its now got cryptomap_2 but still the same issue.I ran debug on the fi...
Hi,Both were set already (extract from config - minus the specific IPs)crypto map outside_map 1 match address internet_cryptomap_2crypto map outside_map 1 set peer x.x.x.xOLDVPNPEER_IPcrypto map outside_map 7 match address internet_cryptomap_7crypto ...