07-30-2018 08:40 PM - edited 07-30-2018 08:56 PM
Hi,
Trying to set up IPSEC tunnel with another site (non cisco). i'm running ASA 5540. Im nating public IP address from my wan router to ASA interface in DMZ. Vendor is getting an error that both IPs need to match and he cant enable nat transversal. Anything I can do on my end (port forwarding etc...).
I'm able to establish phase 2 but traffic is not crossing through the tunnel
07-30-2018 09:54 PM
07-31-2018 05:58 AM - edited 07-31-2018 06:06 AM
Its 1:1 NAT
tunnel is up. took a while to get to phase 2 but its initiated just don't see packets being exchange. On vendor site his firewall is showing that IPs need to match.
IKE Peer: x.x.x.x Role: responder
Type: L2L State: MM_ACTIVE
Rekey: no
I think they made some changes on their end. Can't do IPSEC right now. was able last evening
Error on their side is similar to we require to have peer id 'our public IP here" but peer declares 'ASA interface IP in DMZ here'
07-31-2018 06:21 AM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide