cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1684
Views
0
Helpful
3
Replies

[Site to Site VPN] Cisco ASA error : deny inbound protocol 50 src outside...

Patrick Tran
Level 1
Level 1

Hi,

I configured a IPSec Site to Site VPN between 2 Cisco ASA 5515X on ASA 9.4.1.

After configuration, on remote site, I got this erreur "Deny inbound protocol 50 src outside: central@IP dst outside: remote@IP."

I had to "enable traffic between two or more hosts connected to the same interface" to make it working...

Is this normal?

 

Thanks for your help,

 

Patrick

3 Replies 3

Protocol 50 means ESP which is blocked.

If you can provide more information about the interfaces then only we can understand clearly.

I thought Cisco ASA would unblock ESP 50 automatically for the peer I configured for Site to Site on IKEv2...

2 Cisco ASA are on Internet and communicate with their outside interfaces

Which information do you want? 

 

Thanks !!!

Patrick

Hi Patrick, I know this posting is kind of old. but know know. I am using IKEV1 an seeing a huge amount of this messages from the Cisco Asa on the other end of the Up and running IKVE2 tunnel, a do you have any suggestion and/or did you ever resolve this issue?

Regards,

 

Christian