01-29-2014 12:41 AM - edited 02-21-2020 07:28 PM
Hello,
I have a strange Problem with my Remote-Access-VPN. It worked for days until now. Client says the remote peer is not responding.
The Client can reach the ASA with ping but is not able to esablish a vpn-connection.
Stange is, the ASA shows nothing in debug-modus.
debug crypto ipsec enabled at level 7
debug crypto ikev1 enabled at level 7
It seems like, the VPN is not active or anything. Or there no packets arriving the firewall.
I tried different Clients from different ISP. Also connected me direkt to the outside-switch where the ASA is connected on.
Any Ideas?
Thanks for your help.
Regards
01-29-2014 01:34 AM
Hello,
you say that ping to remote ASA from client side works fine ok? So probably there is not ISP problem and ASA is reachable from internet.
Then I would check logs on ASA and see if remote IP from which client should connect is shown there. If you see ICMP and not other traffic in log so it seems like client side FW is blocking outgoing traffic for IPSEC or SSL VPN.
So i would check or ask remote client if there is some firewall blocking this traffic.
Regards,
Jan
01-29-2014 06:46 AM
Thanks für your answer.
I did nothing, but its now working again for me an my clients, but other clients still can not connect.
I've checked my clients for blocking something, but they did work before an now again, but some hours ago nothing. Some other Clients (iphones for example, still have trouble to connect/establish a vpn)
Strange. I look further into this, but i do not think that the Problem is on the client side.
Regards Torsten
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide