09-22-2013 04:11 PM
I am having trouble getting a GRE tunnel up over a VPN tunnel on a 5555X ASA. This worked in the past on a pre-8.3 OS but I have not been able to solve it in the 9.x environment. I am seeing the following error:
%ASA-3-106010: Deny inbound protocol 47 src
09-25-2013 02:33 PM
hi
Make sure outside to inside acl is applied for gre. i think below link can help
http://www.cisco.com/en/US/docs/security/asa/asa80/system/message/logmsgs.html
pranesh
09-25-2013 06:10 PM
Hi,
The error may appear as GRE (protocol 47) can not pass through a PAT (dynamica NAT) on the ASA. I would recommend to configure a static translation.
- Avoid nat statements with the 'any' keywords.
- For nat identity rules (self-translation) add the no-proxy-arp and route-lookup keywords.
- Verify there is a route for the destination.
Thanks,
Itzcoatl Espinosa
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide