cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
3987
Views
5
Helpful
24
Replies

Subnet on VPN gets decaps but no encaps, ASA 5510

JLOW1213
Level 1
Level 1

I've recofigured the VPN 5 times now and keep running into the same problem. I have a Cisco ASA 5510 connected via site-to-site VPN to a Sophos XG115. The Cisco side has 11 subnets and the Sophos has 1. The primary subnet on the Cisco does not send any traffic over the VPN. It gets decaps from the Sophos, but no encaps going the other way. The other 10 subnets on the Cisco side have no problems communicating back and forth. I have the NAT exempt rule set up and when I run packet tracer everything is allowed through. So I have no idea what to look at next. I've gone through line by line and removed every remnant of the VPN and then set it up again from scratch 5 times. Any help would be greatly appreciated.

24 Replies 24

When you do reply, you have a choose files button

 

 


Thanks
Francesco
PS: Please don't forget to rate and select as validated answer if this answered your question


@Francesco Molino wrote:

When you do reply, you have a choose files button

 

 


Thanks, not sure how I missed that! Here it is.

So here is the newest running configuration. I created another VPN that I needed to get done this morning. Basically the same setup, Sophos XG115 to Cisco ASA 5510. I followed the same process as the other one except this one works perfectly.

Can you run packet-tracer using 192.168.6.1 as source address?

Thanks
Francesco
PS: Please don't forget to rate and select as validated answer if this answered your question

I had to get the VPN done so I ended up recreating it again using a different subnet. Everything is working fine now. There must be something with the 192.168.12.0/24 subnet that was causing it not to work.

 

Thanks for you help.

 

-Jason

Francesco,

 

So I spoke too soon. It worked fine yesterday but today it is back to not working. Here is the packet tracer results if you are still able to help.

 

Thanks,

Jason

Maybe it's a bug in the ASA software. Should I try upgrading to a different version?


@JLOW1213 wrote:

Maybe it's a bug in the ASA software. Should I try upgrading to a different version?


Never mind on upgrading, I don't have access to download.

Just wanted to give an update. I believe I have found this issue to be the result of a bug in the ASA software.

 

"Duplicate ASP table entry causes FW to encrypt traffic with invalid SPI
 
I found invalid SPI's being used. The workaround to reload the ASA brought the VPN back up and it's been solid for the last 48 hours. Hopefully the issue won't return otherwise I will need to find a way to update the ASA software or replace the ASA. 
 
Thanks,
Jason

Yeah i saw it.
It will be better if you can upgrade.
You can ask your local Cisco rep to give you the image

Thanks
Francesco
PS: Please don't forget to rate and select as validated answer if this answered your question