cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
626
Views
10
Helpful
5
Replies

ASA/3750X VPN Issue

rjkaragrm
Level 1
Level 1

We have set up a VPN tunnel with SAP that has required a NAT translation. The tunnel is up and connected. We are able to ping the SAP side from the firewall directly. However the problem comes when we try to access the site from anything before the firewall. This tunnel is currently set up like this,

 

172.18.0.0 (SAP) -> Route Based VPN/NAT -> 192.168.1.1 (FW, ASA) -> 192.168.1.2 (Switch, 3750x) -> Users

 

Somewhere between the switch and the firewall, the packets are getting dropped and we cannot figure out why.

1 Accepted Solution

Accepted Solutions

rjkaragrm
Level 1
Level 1

Thanks for the responses, it was actually a nat rule that we were missing in the end. 

View solution in original post

5 Replies 5

Are both side route traffic of lan through vti tunnel ?

rjkaragrm
Level 1
Level 1

Yep, we're using a VTI tunnel. 

See I lan is reachable through vti.

also don’t forget if the sw behind the fw have L3 capability the sw must have route to other site lan through fw, which then the fw forward traffic via vti tunnel.

rjkaragrm
Level 1
Level 1

Thanks, I will check that out tomorrow to see

rjkaragrm
Level 1
Level 1

Thanks for the responses, it was actually a nat rule that we were missing in the end. 

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: