cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
672
Views
0
Helpful
5
Replies

vpn traffic to dmz

mickyq
Level 1
Level 1

                   I have several VPN sites terminating on a 5510 firewall. all work fine but i cant get the traffic from the VPN sites to communicate with a server on a dmz on the same firewall.

a packet trace from the outside to the dmz shows this:

Type: VPN
Subtype: encrypt
Result: DROP

ive configured access to the dmz the same as to the servers on the inside. I can get to the inside servers ok.

any ideas?

1 Accepted Solution

Accepted Solutions

Jennifer Halim
Cisco Employee
Cisco Employee

Have you clear the VPN tunnel down after you added the new subnet DMZ to the crypto ACL? and I also assume that the remote end has added the same mirror image ACL for their crypto ACL?

Lastly, I also assume that you have configured the NAT exemption on DMZ interface, and perform "clear xlate" after the config?

View solution in original post

5 Replies 5

Jennifer Halim
Cisco Employee
Cisco Employee

Have you clear the VPN tunnel down after you added the new subnet DMZ to the crypto ACL? and I also assume that the remote end has added the same mirror image ACL for their crypto ACL?

Lastly, I also assume that you have configured the NAT exemption on DMZ interface, and perform "clear xlate" after the config?

thanks for the reply Jennifer

I have not cleared the tunnel down. how is this done?

I have configured mirrored acls

I have configured a nat exeption but i have not cleared the xlate table.

To clear the tunnel:

clear cry isa sa

clear cry ipsec sa

To clear the xlate:

clear xlate

Let us know how it goes after clearing it.

Hi Jennifer

when i checked this morning it was working so im assuming the xlate timed out over night so you were probably correct when you said i should clear the xlate.

thanks for the help.

Excellent. Thanks for the update.