07-29-2020 07:46 AM
I have some routing problems with my Cisco ASA. IPsec VPN is up and running but my ASA sends all packets for the remote network back to the switch instead of into the ipsec vpn. IPsec session only shows Rx but zero Tx...
Switch routing:
S* 0.0.0.0/0 [1/0] via 10.0.1.254
ASA:
S* 0.0.0.0 0.0.0.0 [1/0] via <wan gateway>, WAN S 10.0.0.0 255.0.0.0 [1/0] via 10.0.0.1, LAN S 172.16.0.0 255.240.0.0 [1/0] via 10.0.0.1, LAN S 192.168.0.0 255.255.0.0 [1/0] via 10.0.0.1, LAN
I don't have any problems with other different remote network vpn's.
As soon as I add the following route on the ASA the communication works:
S 192.168.111.0 255.255.255.0 [1/0] via 213.221.255.145, WAN
I know I'm routing the whole 192.168.0.0 network to the switch but longest prefix match...
Any idea why i have to add an additional route just for this network?
07-29-2020 07:57 AM
Hi,
This is to be expected. You need this specific route, because this traffic needs to be sent to the outside interface in order to matched to the crypto ACL, encrypted and then routed over the VPN.
What are the other networks you don’t need to define static routes for? Provide your configuration if necessary.
HTH
07-30-2020 12:26 AM
07-29-2020 02:48 PM
Could it be that you have configured reverse-route-injection (RRI) for the other VPNs, but not for this one?
07-30-2020 12:27 AM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide