cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1169
Views
0
Helpful
2
Replies

VPN NAT Issue

kuldeep.kaur
Level 1
Level 1

Hi Guys,

I have a VPN setup as below. The VPN tunnel starts from the site router goes through the ASA and terminates at Palo Alto at Singapore.

Site Router NZ (VPN )---------------------------DC ASA----------------------------Internet --------------------Singapore Palo Alto (VPN)

On the asa I am doing nat two times. First one from internal address to transit DMZ and then from transit DMZ to the outside interface. I have allowed all the ports going to the ip address of Palo Alto and vice versa.

The tunnel came up fine without any issue. Worked for two weeks and then the site router got rebooted. After that I am not able to get the tunnel up. On Palo Alto we can see the connection request from the site Router but it stops at phase 1. Enclosed are the logs from the router:

Could anyone please let me know why tunnel is not coming up. Is it because of nat being done two times. If nat is the issue how can i fixed this. No other changes has been been on both vpn devices / network.

I know you guys will say why not build the tunnel from asa to singapore, I can't as there are design issues.

Thanks Guys

2 Replies 2

kuldeep.kaur
Level 1
Level 1

Hi Guys,

Below are the logs from the ASA. Thanks

Feb 17 21:28:21.582: ISAKMP:(0): retransmitting phase 1 MM_NO_STATE...
*Feb 17 21:28:21.582: ISAKMP (0): incrementing error counter on sa, attempt 4 of 5: retransmit phase 1
*Feb 17 21:28:21.582: ISAKMP:(0): retransmitting phase 1 MM_NO_STATE
*Feb 17 21:28:21.582: ISAKMP:(0): sending packet to 68.208.240.80 my_port 500 peer_port 500 (I) MM_NO_STATE
*Feb 17 21:28:21.582: ISAKMP:(0):Sending an IKE IPv4 Packet.10.
*Feb 17 21:28:30.770: ISAKMP:(0):purging node 1225394322
*Feb 17 21:28:30.770: ISAKMP:(0):purging node -364328210
*Feb 17 21:28:31.582: ISAKMP:(0): retransmitting phase 1 MM_NO_STATE...
*Feb 17 21:28:31.582: ISAKMP (0): incrementing error counter on sa, attempt 5 of 5: retransmit phase 1
*Feb 17 21:28:31.582: ISAKMP:(0): retransmitting phase 1 MM_NO_STATE
*Feb 17 21:28:31.582: ISAKMP:(0): sending packet to 68.208.240.80 my_port 500 peer_port 500 (I) MM_NO_STATE
*Feb 17 21:28:31.582: ISAKMP:(0):Sending an IKE IPv4 Packet.
*Feb 17 21:28:40.770: ISAKMP:(0):purging SA., sa=2A9522A8, delme=2A9522A8
*Feb 17 21:28:41.582: ISAKMP:(0): retransmitting phase 1 MM_NO_STATE...
*Feb 17 21:28:41.582: ISAKMP:(0):peer does not do paranoid keepalives.

*Feb 17 21:28:41.582: ISAKMP:(0):deleting SA reason "Death by retransmission P1" state (I) MM_NO_STATE (peer 68.208.240.80)
*Feb 17 21:28:41.582: ISAKMP:(0):deleting SA reason "Death by retransmission P1" state (I) MM_NO_STATE (peer 68.208.240.80)
*Feb 17 21:28:41.582: ISAKMP: Unlocking peer struct 0x2B7E7A20 for isadb_mark_sa_deleted(), count 0
*Feb 17 21:28:41.582: ISAKMP: Deleting peer node by peer_reap for 68.208.240.80: 2B7E7A20
*Feb 17 21:28:41.582: ISAKMP:(0):deleting node -2073049274 error FALSE reason "IKE deleted"
*Feb 17 21:28:41.582: ISAKMP:(0):deleting node -2096190670 error FALSE reason "IKE deleted"
*Feb 17 21:28:41.582: ISAKMP:(0):Input = IKE_MESG_INTERNAL, IKE_PHASE1_DEL
*Feb 17 21:28:41.582: ISAKMP:(0):Old State = IKE_I_MM1 New State = IKE_DEST_SA
*Feb 17 21:28:41.810: ISAKMP:(0): SA request profile is (NULL)
*Feb 17 21:28:41.810: ISAKMP: Created a peer struct for 68.208.240.80, peer port 500
*Feb 17 21:28:41.810: ISAKMP: New peer created peer = 0x2B7E7A20 peer_handle = 0x80002183
*Feb 17 21:28:41.810: ISAKMP: Locking peer struct 0x2B7E7A20, refcount 1 for isakmp_initiator
*Feb 17 21:28:41.810: ISAKMP: local port 500, remote port 500
*Feb 17 21:28:41.810: ISAKMP: set new node 0 to QM_IDLE
*Feb 17 21:28:41.810: ISAKMP: Find a dup sa in the avl tree during calling isadb_insert sa = 2A9522A8
*Feb 17 21:28:41.810: ISAKMP:(0):Can not start Aggressive mode, trying Main mode.
*Feb 17 21:28:41.810: ISAKMP:(0):found peer pre-shared key matching 68.208.240.80
*Feb 17 21:28:41.810: ISAKMP:(0): constructed NAT-T vendor-rfc3947 ID
*Feb 17 21:28:41.810: ISAKMP:(0): constructed NAT-T vendor-07 ID
*Feb 17 21:28:41.810: ISAKMP:(0): constructed NAT-T vendor-03 ID
*Feb 17 21:28:41.810: ISAKMP:(0): constructed NAT-T vendor-02 ID
*Feb 17 21:28:41.810: ISAKMP:(0):Input = IKE_MESG_FROM_IPSEC, IKE_SA_REQ_MM
*Feb 17 21:28:41.810: ISAKMP:(0):Old State = IKE_READY New State = IKE_I_MM1

*Feb 17 21:28:41.810: ISAKMP:(0): beginning Main Mode exchange
*Feb 17 21:28:41.810: ISAKMP:(0): sending packet to 68.208.240.80 my_port 500 peer_port 500 (I) MM_NO_STATE
*Feb 17 21:28:41.810: ISAKMP:(0):Sending an IKE IPv4 Packet.
*Feb 17 21:28:51.810: ISAKMP:(0): retransmitting phase 1 MM_NO_STATE...
*Feb 17 21:28:51.810: ISAKMP (0): incrementing error counter on sa, attempt 1 of 5: retransmit phase 1
*Feb 17 21:28:51.810: ISAKMP:(0): retransmitting phase 1 MM_NO_STATE
*Feb 17 21:28:51.810: ISAKMP:(0): sending packet to 68.208.240.80 my_port 500 peer_port 500 (I) MM_NO_STATE
*Feb 17 21:28:51.810: ISAKMP:(0):Sending an IKE IPv4 Packet.
*Feb 17 21:29:01.810: ISAKMP:(0): retransmitting phase 1 MM_NO_STATE...
*Feb 17 21:29:01.810: ISAKMP (0): incrementing error counter on sa, attempt 2 of 5: retransmit phase 1
*Feb 17 21:29:01.810: ISAKMP:(0): retransmitting phase 1 MM_NO_STATE
*Feb 17 21:29:01.810: ISAKMP:(0): sending packet to 68.208.240.80 my_port 500 peer_port 500 (I) MM_NO_STATE
*Feb 17 21:29:01.810: ISAKMP:(0):Sending an IKE IPv4 Packet.
*Feb 17 21:29:11.810: ISAKMP: set new node 0 to QM_IDLE
*Feb 17 21:29:11.810: ISAKMP:(0):SA is still budding. Attached new ipsec request to it. (local 10.2.78.2, remote 68.208.240.80)
*Feb 17 21:29:11.810: ISAKMP: Error while processing SA request: Failed to initialize SA
*Feb 17 21:29:11.810: ISAKMP: Error while processing KMI message 0, error 2.
*Feb 17 21:29:11.810: ISAKMP:(0): retransmitting phase 1 MM_NO_STATE...
*Feb 17 21:29:11.810: ISAKMP (0): incrementing error counter on sa, attempt 3 of 5: retransmit phase 1
*Feb 17 21:29:11.810: ISAKMP:(0): retransmitting phase 1 MM_NO_STATE
*Feb 17 21:29:11.810: ISAKMP:(0): sending packet to 68.208.240.80 my_port 500 peer_port 500 (I) MM_NO_STATE
*Feb 17 21:29:11.810: ISAKMP:(0):Sending an IKE IPv4 Packet.
% Unrecognized host or address, or protocol not running.

Hi,

you local ip address is a private adress, the destination address is public, regarding your debug the firewall gets no answer, routing issue.

br Fritz

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: