cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
736
Views
0
Helpful
2
Replies

VPN NAT issues

sambillings459
Level 1
Level 1

Hi Experts,

 

I have some issue going on with site-site VPN, we are doing NAT for our internal subnets and to avoid conflicts we are also doing destination NAT.

 

This is new site-site VPN setup, not sure what went wrong. when we tried to do TCP ping on the other side of the tunnel, it is not pinging  and not even the phase1 is coming up

 

 when checked the logs we are getting some strange logs..please see the below logs

 

Aug 22 2017 19:18:37 10.11.12.13 : %ASA-5-305013: Asymmetric NAT rules matched for forward and reverse flows; connection for src inside:172.21.2.2/223 dst outside:172.16.24/25/80 denied due to NAT reverse path failure

 

I would really appreciate any help.

 

Thanks

SAM

2 Replies 2

Aditya Ganjoo
Cisco Employee
Cisco Employee

Hi,

 

Please move the NAT used for this VPN tunnel to line 1.

 

For instance:

 

nat (inside,outside) 1 source static obj-A obj-A destination static obj-b obj-b

 

 

Regards,

Aditya

Please rate helpful and mark correct answers

Hi Aditya,

 

Thanks for your quick response. can you please have a look at the attachment with this message. I have mentioned every thing in the attachement.. please let me know if you need any further information

 

Thanks

SAM