cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
Announcements
1283
Views
30
Helpful
16
Replies
Mokhalil82
Enthusiast

ASA VPN Configuration

Hi

I have configure a site to site VPN on an ASA, At the other site there is a Watchguard firewall.  The VPN has not established. I have no isakmp or ipsec sessions established. Here i the config I am using, can anyone see if I am missing something, its my first VPN using the command line

 

object-group network SITEA
subnet 10.57.254.0 255.255.255.0

object-group network SITEB
NETWORK-OBJECT 10.254.10.0 255.255.255.0

crypto ikev1 enable outside

access-list VPN_TRAFFIC_ALLOWED extended permit ip object-group SITEA Object-Group SITEB

nat (inside,outside) source static SITEA SITEB destination static SITEA SITEB

tunnel-group X.X.X.X type ipsec-l2l
tunnel-group X.X.X.X ipsec-attributes
pre-shared-key X.X.X.X
exit

crypto ikev1 policy 10
authentication pre-share
Encryption AES 256
hash sha
lifetime 28800

crypto ipsec ikev1 transform-set TS-ESP-AES-SHA esp-aes-256 esp-sha-hmac

crypto map outside_map 1 match address VPN_TRAFFIC_ALLOWED
crypto map outside_map 1 set peer X.X.X.X
crypto map outside_map 1 set ikev1 transform-set TS-ESP-AES-SHA
crypto map outside_map 1 interface outside

 

 

1 ACCEPTED SOLUTION

Accepted Solutions
Fabian Ortega
Beginner

Hello.

 

Please correct the NAT-0 with this line:

nat (inside,outside) source static SITEA SITEA destination static SITEB SITEB no-proxy-arp route-lookup

 

If you still experience issues send me the output from:

 

packet-tracer input inside icmp 10.57.254.10 8 0 10.254.10.10 detailed.

 

Regards,

View solution in original post

16 REPLIES 16
Fabian Ortega
Beginner

Hello.

 

Please correct the NAT-0 with this line:

nat (inside,outside) source static SITEA SITEA destination static SITEB SITEB no-proxy-arp route-lookup

 

If you still experience issues send me the output from:

 

packet-tracer input inside icmp 10.57.254.10 8 0 10.254.10.10 detailed.

 

Regards,