04-20-2023 12:58 AM
Hello,
I have a problem with VPN communication from another end, they do not reach my local network in any way, I can reach the remote network at the other end. the VPN is up, can someone give me a hand.
thank you very much
04-20-2023 03:37 AM
If correct, I have tried it again, if the same as before the other end does not reach my local network, instead I correctly reach your local network
I attach the packet-trace
04-20-2023 03:41 AM - edited 04-20-2023 03:43 AM
@oelagy reverse the packet-tracer flow from outside to inside.
packet-tracer input outside icmp 10.77.158.95 8 0 172.31.1.27 detailed
I assume10.77.158.95 is a network from one of the objects defined in your Access Control rules?
04-20-2023 03:49 AM
04-20-2023 04:06 AM
@oelagy ok, so packet-tracer says that should be allowed.
Is real traffic being recieved on your FTD? If not then investigate a problem on the remote end
If you run "show crypto ipsec sa" is the counters for decaps increasing?
Does the local device on your end have a local firewall that could be blocking the connection from the remote end?
04-20-2023 04:13 AM - edited 04-20-2023 08:07 AM
#pkts encaps: 45473, #pkts encrypt: 45473, #pkts digest: 45473
#pkts decaps: 54269, #pkts decrypt: 54269, #pkts verify: 54269
#pkts compressed: 0, #pkts decompressed: 0
#pkts not compressed: 45473, #pkts comp failed: 0, #pkts decomp failed: 0
#pre-frag successes: 0, #pre-frag failures: 0, #fragments created: 0
#PMTUs sent: 0, #PMTUs rcvd: 0, #decapsulated frgs needing reassembly: 0
#TFC rcvd: 0, #TFC sent: 0
#Valid ICMP Errors rcvd: 0, #Invalid ICMP Errors rcvd: 0
#send errors: 0, #recv errors: 0
l
04-20-2023 04:32 AM
#pkts encaps: 46693, #pkts encrypt: 46693, #pkts digest: 46693
#pkts decaps: 55665, #pkts decrypt: 55665, #pkts verify: 55665
#pkts compressed: 0, #pkts decompressed: 0
#pkts not compressed: 46693, #pkts comp failed: 0, #pkts decomp failed: 0
#pre-frag successes: 0, #pre-frag failures: 0, #fragments created: 0
#PMTUs sent: 0, #PMTUs rcvd: 0, #decapsulated frgs needing reassembly: 0
#TFC rcvd: 0, #TFC sent: 0
#Valid ICMP Errors rcvd: 0, #Invalid ICMP Errors rcvd: 0
#send errors: 0, #recv errors: 0
04-20-2023 03:38 AM
04-20-2023 03:43 AM - edited 04-20-2023 03:57 AM
I see your early post you already config it ACL for INbound
04-20-2023 04:15 AM
yes, but it continues the same we do not receive ping or communication
04-20-2023 04:16 AM
share the last NAT config
04-20-2023 04:20 AM
04-20-2023 04:36 AM
> packet-tracer input inside_2 tcp 172.31.1.20 1234 10.77.158.90 80 detailed
NOTE:-
please confimr that 172.31.1.0/x is your local LAN and 10.77.158.0/x is your Remote LAN ? If you confirm that run the packet tracer above and share result
04-20-2023 04:51 AM
10.77.158.0/x Nat local lan
172.31.1.0/x LAN Remote
04-20-2023 04:52 AM
04-20-2023 05:03 AM
Now it clear there is UN-NAT and the traffic is encrypt correctly
now try ping not from FPR but from any host behind FRP to remote LAN
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide