09-09-2007 08:22 AM
I swapped out our PIX with an ASA 5510 v8.02 and one of tunnels won't allow traffic through. The dynnamic NAT rule shows up as the culprit in packet tracer. Our traffic has to be NATed to get to their site DMZ servers. Not sure what I missed in the conversion from PIX to ASA
09-09-2007 02:54 PM
I think you missed "sysopt connection permit-vpn"
09-10-2007 05:49 AM
That was missing. So I issued the command but it dinn't change anything. I also see the following error for traffic that should be allowed through the tunnel
Sep 10 2007 08:45:09 106001 192.168.72.102 Stibo_HTQuark Inbound TCP connection denied from 192.168.72.102/2898 to Stibo_HTQuark/11207 flags SYN on interface Inside
09-10-2007 10:31 AM
Found the problem. It was in the ACL used for Group Policy on the Tunnel Group.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide