cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1369
Views
5
Helpful
4
Replies

Site-2-site Vpn 8.25(33) NAT reverse path failure.

dmooreami
Level 3
Level 3

Have a simple site-to-site tunnel setup. AES-128, SHA, Diffie 5.  Intresting traffic is 10.122.20.0/24, 10.194.20.0/24. Used the vpn wizard to setup on both ASA 5510's running 8.25(33) code. 

I can ping and traceroute down the tunnels, but I can't get two hosts  10.122.20.215 and 10.194.20.215 down the tunnel.

Errors in ASA B that sits on the 10.194 network is:

Asymmetric NAT rules matched for forward and reverse flows;

Connection for tcp src inside:10.194.20.161/38972 dst inside:10.122.20.161/80 denied due to NAT reverse path failure

I also had to add to both ASA's:

ip verify reverse-path interface inside

What in the world is going on here with this 8.2.5(33) code?  With 8.0.5, fire up the vpn site-to-site wizard, put the Outside Internet interfaces, define the "allowed intresting traffic across the tunnel", set up encryption phase1 and phase 2 and done. None of his "Ass Nat Rule" error, or needing "reverse-path" statements.

Suggestions?

I saw somewhere mentioned that your networks or was it hosts also needed to be defined in NAT0?

Huh, if that is the case why doesn't the Vpn Wizard do this.  I am running 8.2x(xx) code, not 8.3x.

This is my first time doing site-to-site Ipsec tunnels with 8.2 code.

In the past it has been 8.0.5 to 8.0.5 tunnel or an 8.2.x to 8.0.5 tunnels . Nevery had any of these issues before.

Thanks


4 Replies 4

Hello

Can you post the ASA configuration ?

regards

Harish

Hello,

Mostly this would be nat issues.I think we need below output, Please post below on both firewalls.

  "show run nat", "show run static" and "show run global

Regards

srikanth

Looks like I have asymetrical routing being done on a router configed by a vendor causing the issue. .

I need to correct this and I think my problem will go away. Firewall knew about it before they did.   I will update if this was indeed the case. Might be a couple weeks before I get maint. window .

I would suggest to check the routing issue and get back to us in case you would need further assistance.

For now, please feel free to mark this post as answered and rate the any helpful posts.

Thanks.

Portu