06-29-2017 08:24 PM - edited 02-21-2020 09:21 PM
hi All,
i have followed this link below
after i have completed the wizard and check using cli, i cannot see the vpn i have created.
i have attached pictures.
please share your ideas
regards,
John
06-30-2017 04:25 AM
I am not clear on the problem. Are you not able to connect to the vpn or not see the configuration? "show run crypto" should show you the configuration.
06-30-2017 06:22 PM
Dear Rahul,
i am not able to connect to the vpn. following the link below:
can you advise
Regards,
John
07-01-2017 10:23 PM
When you attempt to connect from the PC, what do you see there?
Can you check the ASA show command during the connection attempt?
If it simply times out and you see no SAs in progress (MM WAIT), can you confirm the traffic is reaching the ASA?
07-02-2017 07:19 PM
Hi Marvin,
can you advise i have attached the photos on this post the first picture is the error on the PC side and show commands for sa are blank on the 2nd photo
07-03-2017 01:21 AM
The two attachements are both from the ASA - one from the ASDM wizard and one from the cli.
We need to see the status while the PC attempts to connect. Best would be to do a packet capture on the ASA filtering on the PC's IP address that is presented to the ASA (probably its public IP - i.e. what is shown from whatismyip.com - unless you are in a strictly internal test environment)
07-04-2017 08:42 PM
Dear Marvin,
thank you for your inputs, apparently i have tested the configuration using Windows 7 and it worked fine. However, testing on the windows 10 PC fails. Any idea why?
FW# sh crypto isakmp sa
IKEv1 SAs:
Active SA: 1
Rekey SA: 0 (A tunnel will report 1 Active and 1 Rekey SA during rekey)
Total IKE SA: 1
1 IKE Peer: 6x.XXX.x.6
Type : user Role : responder
Rekey : no State : MM_ACTIVE
FW# sh crypto ipsec sa
interface: WAN
Crypto map tag: SYSTEM_DEFAULT_CRYPTO_MAP, seq num: 65535, local addr: XXX.XXX.XX.XXX
local ident (addr/mask/prot/port): (Xxx.XX.XXX.x11/255.255.255.255/17/1701)
remote ident (addr/mask/prot/port): (XXX.XX.XXX.x/255.255.255.255/17/0)
current_peer: XX.X.XXX.XX, username: vpn
dynamic allocated peer ip: 172.16.17.200
dynamic allocated peer ip(ipv6): 0.0.0.0
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide