Cisco Firewall :: ASA5505 - IKE Initiator Unable To Find Policy

Mar 7, 2011

I have a client ASA5505 generating this level 3 log message:

3 Mar 08 2011
19:48:34
IKE Initiator unable to find policy: Intf outside, Src: 192.168.0.2, Dst: 192.168.1.3

All the site-to-site tunnels on this ASA are up, so I don't know the meaning and signifcance of this log message or how to address it.

View 6 Replies


ADVERTISEMENT

Cisco VPN :: IKE Initiator Unable To Find Policy / ASA5505

Apr 29, 2012

I am testing VPN tunnels in a lab. I have the following (simple) setup:

  -one ASA5505 has an "inside" interface with address 192.16.99.40/24 and an "outside" interface with address 205.192.0.2/24
  -one computer with address 192.16.99.1/24 ("Client") is connected to the "inside" interface
  -one ASA5510 has an "inside" interface with address 192.0.99.40/24 and an "outside" interface with address 205.192.0.1/24
  -one computer with address 192.0.99.1/24 ("Server") is connected to the "inside" interface
  -both "outside" interfaces are connected through a layer 2 switch

I had a VPN tunnel between them using "Main mode", and that worked without a problem.But in my target system, the ASA5505 will be connected to a router with a dynamic IP address, and so I need to use "Aggressive mode", where the ASA5510 will have a static address on the "outside" interface. The ASA5505 will therefore initiate the VPN session.

I am using the ASDM, by the way.I have the VPN tunnel established, but I am unable to ping from either side.When I ping the Server from the Client, the ASA5505 gives me the expected "Built/Teardown ICMP connection...", but the ASA5510 says "IKE Initiator unable to find policy: Intf inside, Src: 192.0.99.1, Dst: 192.16.99.1". So the ping makes it to the Server, but the reply can't find its way back out.When I ping the client from the Server, I get the same message on the ASA5510: "IKE Initiator unable to find policy: Intfc inside, Src: 192.0.99.1, Dst: 192.16.99.1".I attach the configuration on the ASA5510.

View 2 Replies View Related

Cisco :: IKE Initiator Unable To Find Policy?

Nov 1, 2011

I keep getting this on a site to site VPN tunnel that I have established to one of our remote offices. EVERYTHING works fine except for the phones. Everytime they try to connect I get a flood of the below error3Nov 01 201116:06:38IKE Initiator unable to find policy: Intf DS3, Src: 10.90.4.6, Dst: 10.10.20.2010.90.4.0 is our phones vla10.10.20.0 is the remote site network .20 is one of the ip phones located thereried running it through packet tracer and get this...I'm not sure where the problem is, as I said ALL domain traffic is flowing back and forth with no issues.

View 12 Replies View Related

Cisco VPN :: ASA 5520 / IPSec Over TCP - IKE Initiator Unable To Find Policy?

Jun 9, 2012

I've tried to set up IPSec over TCP with a VPN-Client V5.0.07.0440 on Win 7 64b to my ASA 5520 (Version 8.2(2)16) regarding to
 
[URL]
 
IPSec over TCP activated at the ASA
crypto isakmp ipsec-over-tcp port 10000
 
and in the transport tap of the VPN connection 'enable transport tunneling' with IPSec over TCP an port 10000 instead of 'IPSec over UDP' The connect timed out with error code 412 And this is my log from the ASA:
 
%ASA-7-710005: TCP request discarded from 178.x.x.x/53225 to INTERNET:212.x.x.x/10000
%ASA-3-713042: IKE Initiator unable to find policy: Intf INTERNET, Src: 212.x.x.x, Dst: 178.x.x.x
%ASA-7-710005: TCP request discarded from 178.x.x.x/53225 to INTERNET:212.x.x.x/10000
%ASA-3-713042: IKE Initiator unable to find policy: Intf INTERNET, Src: 212.x.x.x, Dst: 178.x.x.x
 
I don't have a clue what's here missing.I have static crypto maps for the L2L tunnels and the default dynamic crypto map for the VPN clients which come over NAT-T
 
crypto map INTERNET_map 65535 ipsec-isakmp dynamic SYSTEM_DEFAULT_CRYPTO_MAP
crypto dynamic-map SYSTEM_DEFAULT_CRYPTO_MAP 65535 match address INTERNET_cryptomap_65535.65535
crypto dynamic-map SYSTEM_DEFAULT_CRYPTO_MAP 65535 set pfs
crypto dynamic-map SYSTEM_DEFAULT_CRYPTO_MAP 65535 set transform-set ESP-AES-256-SHA ESP-AES-256-MD5 ESP-3DES-SHA ESP-3DES-MD5
crypto dynamic-map SYSTEM_DEFAULT_CRYPTO_MAP 65535 set reverse-route

View 1 Replies View Related

Cisco VPN :: ASA 5510 VPN Site-to-Site IKE Initiator Unable To Find Policy

Sep 30, 2012

I have a dynamic VPN site to site between ASA 5510 vs C880 with segment 172.23.191.0/25 for ASA side and some host in C880 side (e.g. 128.1.100.211, 128.1.115.181, 128.1.104.212) . The VPN is up, but only have communication with a host (128.1.115.181).
 
In the logs appears the next message when I try communication for all aother IP in the policy map configuration: IKE Initioator unable to find policy: Intf Inside, Src: 172.23.191.87, Dst: 128.1.115.182..ONLY WHEN I PINGING FROM SOME HOST IN C880 SIDE (e.g. 128.1.100.211) the communication is successfull.

What happen with this VPN, because I need to pinging from C880 IP host to ASA segment for establish communication?

View 7 Replies View Related

Cisco Firewall :: Users Behind ASA5505 Firewall Are Unable To Access Internet

Feb 24, 2011

I have a normal setup of ASA5505 (without security license) connected behind an internet router. From the ASA5505 console I can ping the Internet. However, users behind the Firewall on the internal LAN, cannot ping the Internet even though NATing is configured. The users can ping the Inside interface of the Firewall so there is no internal reachability problem. In addition, I noticed that the NAT inside access list is not having any hit counts at all when users are trying to reach the internet.

When i replace the ASA5505 with a router with NAT overload configuration on it, the setup works normally and users are able to browse the internet.

The ASA5505 configuration is shown below.

hostname Firewall

interface Ethernet0/0
description Connected To Internet Router
switchport access vlan 10

[Code].....

View 2 Replies View Related

Cisco Firewall :: Unable To Ping Internet IPs From ASA5505 Firewall

Jan 9, 2013

Internet ISP -> Juniper SRX 210 Ge-0/0/0
Juniper fe0/0/2  -> Cisco ASA 5505
Cisco ASA 5505 - >Inernal LAN switch.
 
1.  Internet  is connected to Juniper Ge0/0/0  via /30 IP.
 
2. Juniper fe0/0/2 port is configured as inet port and configured the Internal public LAN pool provided by the ISP. And this port is directly connected to  Cisco ASA 5505 E0/0. Its a /28 pool IP address. This interface is configured as outside and security level set to 0.

From Juniper SRX, am able to ping public Internet IPs (8.8.8.8).
 
Issue:

1. From ASA am unable to ping public ip configured on Juniper G0/0/0 port.(/30)
2. From ASA no other Public internet IP is pinging.
 
Troubleshooting Done so far.
 
1, Configured icmp inspection on ASA.
2. Used the packet tracer in ASA, it shows the packet is flowing outside without a drop.
3.  Allowed all services in untrust zone in bound traffic in Juniper SRX.
4. Viewed the logs when I was trying the ping 8.8.8.8 in ASA. It says "Tear down ICMP connection for faddrr **** gaddr **

View 2 Replies View Related

Cisco Firewall :: Unable To Connect To Internet With ASA5505

Mar 13, 2011

Recently, I have bought an ASA 5505 firewall which I have tried to connect to my ADSL router (Modem).It is now more than a week that I am trying to get internet connection through the firewall but I still can't succeed. I have tried many advices I get from this community but I still don't know what is wrong with my ASA Firewall configuration. From inside I am able to ping the inside and outside interface with a great success. and from my laptop which is connected to the firewall, I am able to ping the both interfaces (inside and outside) but still I can't access the internet.
 
As I don't have a static IP address from my ISP, I have configured the outside interface to pick up the ip address dynamically. Most of the time, the outside interface get the 192.168.1.2 ip address. [code]

View 5 Replies View Related

Cisco Firewall :: Unable To Access Internet ASA5505?

Dec 10, 2012

I've been struggling with gaining access to the inter through our Comcast business gateway. We have had Comcast configure the device fro true static IP subnetting. Turned of local DHCP on the device etc. Here is my config.
 
ASA Version 9.1(1)
!
hostname TOCN-EX-01A-C5505-GW
 xlate per-session deny tcp any4 any4
xlate per-session deny tcp any4 any6
xlate per-session deny tcp any6 any4

[code]....

View 9 Replies View Related

Cisco Firewall :: Unable To Connect Via ASDM To ASA5505?

Sep 10, 2012

Running ASA 5505
 
ASA Version: asa844-1-k8.bin
ASDM: Cisco ASDM 6.2(1)
 
I updated my ASA with version asa844-1-k8.bin.
 
However, whenever I try and run the ASDM client, I get the following error:
 
"Your ASA image has a version number 8.4(4)1 which is not supported by ASDM 6.2(1)."
 
How do I get the latest version installed on my Mac desktop?  I know that I can connect via the web interface and run the ASDM client, but the same error persists.  I have the asdm-649-103.bin file, but cannot connect to the ASA to install (I don't recall ever setting up SSH).

View 5 Replies View Related

Cisco Firewall :: Unable To NAT ASA5505 To Windows 2012 Server

Apr 17, 2013

I have an unusual issue, for which I can find nothing on the net similar.
 
Setup:
 
ASA5505  = > CISCO3524 => Windows 2012 server
 
ASA is internet edge with ACL / NAT implemented.
 
We are wanting to implement inbound NATs for this server - 3389.  We have many other servers on the internal side of this ASA that we are NATing to.  Creating NATs using the same outside IP to another server is fine, no issues.  This other test server resides on the same VLAN as the windows 2012 server.  All IPv6 is turned off on the W2012 server, and it can web-browse out via the ASA as well.  No matter what I do, however I cannot get iinbound NAT, on ANY port to this server working.  Internally from another server to this server on any port is fine, i.e. we can RDP to this server without issue, so we know this works - the firewall on this server is turned off too.  This is our ONLY w2012 server on the internal side.  When we run a wireshark on the server whilst testing the NAT there is no traffic, so its getting blocked somewhere.
 
The config of the ASA is fairly big to to santize it and remove all customer reference would take a while to make display of this secure difficult.

View 1 Replies View Related

Cisco Firewall :: ASA5505 - SSH Timeout / Unable To Access Device From Host

Jul 19, 2007

I have an ASA5505 running ver 8.0(2). I have configured the ssh timeout, ssh host commands and did the crypt o key gen. I am unable to access the device from the host I am allowing. Is there like ca save all command required? I am trying to use the default pix and telnet password. Do those still work?

View 3 Replies View Related

Cisco VPN :: ASA5505 QoS Policy On VPN Tunnels

Dec 14, 2011

I set up a full mesh LAN-to-LAN VPN for a client with 4 sites.  Each site has an ASA 5505 running 8.2(5).   Site-to-site VoIP traffic runs in the VPN tunnels, as well as traffic to/from a file-server located at the main site.  There are two back-up servers, one at the main site and one at a remote site.  The main site has 2 bonded T1s and the other three sites have a single T1. How should I go about setting up my QoS? 
 
My top requirement is that VoIP traffic will never be pushed out of the way for data traffic.  My secondary consideration is to give more preference to file-server traffic than to web traffic and to make back-up traffic the least important.  I'm currently researching to see if the VoIP provider is DSCP marking EF on the VoIP traffic, but I am going to assume they are for now.  I know the IP of the file-server and back-up servers.

View 3 Replies View Related

Cisco Firewall :: ASA5505 - Windows 7 Machine Unable To Load Images For A Website

Dec 20, 2011

Ths only hapeens at one location. All the other locations are working the difference is this location goes through the firewall. If I bypass the firewall at this location it works.

View 1 Replies View Related

Cisco Firewall :: VPN Tunnel Built Via ASA5505 But Unable To RDP / ICMP Back To Internal Network

Oct 10, 2012

I'm able to build my tunnel but unable to RDP nor ICMP back to the internal network. 
 
VPN Client IP: 192.168.200.200
INTERNAL IP:  172.17.130.200
 
my configuration is below:

HOME-ASAFW02(config)# wr t: Saved:ASA Version 8.4(4)!hostname HOME-ASAFW02domain-name hsd1.nj.comcast.netenable password ViPq56cvd3SGvB08 encryptedpasswd 8bcozHCAwCqA5BmN encryptednames!interface Ethernet0/0description OUTSIDE-Connectionswitchport access vlan 2switchport protected!interface Ethernet0/1description INSIDE-Connectionswitchport protectedspeed 100duplex full!interface Ethernet0/2description WiFi-LinkSYSswitchport access vlan 3switchport protected!interface Ethernet0/3shutdown!interface Ethernet0/4shutdown!interface Ethernet0/5shutdown!interface Ethernet0/6shutdown!interface Ethernet0/7shutdown!interface Vlan1description INTERNAL-Networknameif insidesecurity-level 100ip address 172.17.130.129 255.255.255.128!interface Vlan2description OUTSIDE-Link-to-ISPnameif

[code]....

View 12 Replies View Related

Cisco WAN :: 1760 Unable To Enable Policy Map On Interface

Sep 6, 2012

Class and Policy maps are defined properly but when I am going to apply the policy-map on interface ,throwing an error as "'set' command is not supported in a 2nd level policymap".
 
Class/Policy map configuration given below ....
 
class-map match-any cm_traffic_control
  match access-group name acl_traffic_control
class-map match-any BE
  match access-group name be
[Code] ....

View 8 Replies View Related

Cisco Switching/Routing :: WS-c3750G -24T / Unable To Look Ip Policy Route-map In PBR?

Apr 22, 2012

i have a Layer3 Switch Cisco WS-c3750G -24T , initially i have a IOS version c3750-Ipbase , recentely i have upgraded my IOS to c3750-Ipservices-M to enable to PBR for my network , i have created all the acl and tried to give the route-map with PBR , the command was initiallying but i am not able to see the applied route-map in my policy route , i have gone through the blog and enabled SDM prefer routing , but no luck .

View 1 Replies View Related

Cisco Switching/Routing :: Unable To Policy Switchport Interface Of 861

Jul 24, 2012

I'm unable to apply a policing limit in a switchport of the CISCO861 router. This is my configuration:interface FastEthernet0, service-policy input wired-input,service-policy output wired-output end.

View 3 Replies View Related

Cisco Routers :: SRP541W Unable To Create IPSEC Policy To ANY (0.0.0.0)

Feb 26, 2012

Unfortunately, it does not appear as if the SRP500 series will allow you to create an ipsec policy where the local or remote traffic selection is 0.0.0.0/0.0.0.0. It wants a specific network. I have a scenario where I want to send all traffic over the vpn tunnel.
 
Is there a workaround to this or a special way to input "ANY" as the remote network?

View 3 Replies View Related

Cisco Firewall :: 1811 / Zone-Based Policy Firewall Configuration

May 16, 2011

I have two 1811's connected in a lab using a ipsec vpn tunnel (using a switch to simulate an internet connection between them).I am trying to configure one of the routers as a ZBPF just to allow a remote windows login (DC on the firewalled side, workstations on the other side).I'm trying to verify that the zbpf is working, but it doesn't seem to stop anything.  I had match icmp added to the class-map, but took it out to test if icmp would fail.  It didn't.  Basically, I don't think the firewall is working at all.  Any thoughts on how I can configure this so that the policies will work between zone-pairs?

Here's an quick drawing:

Here are the configurations:

 Local router:
 hostname sdc-1811-LocalLab
!
boot-start-marker
boot-end-marker
!
no aaa new-model
!
resource policy

[code]....

View 11 Replies View Related

Cisco WAN :: Unable To Configure Service Policy Output Command In 2921 Router

Apr 25, 2011

I am not able to configure Service policy output command in Cisco 2921 router.While configuring I am getting below error.Same config is working fine in Cisco 3845  router.I am suspectting the problem with license in IOS.

View 3 Replies View Related

Cisco Switching/Routing :: Unable To Apply IP Policy Route-Map To VLan 4 In C-3750

Apr 22, 2012

Here is my configuration below , i have upgraded my C-3750 switch IOS from IPbase to IPservices , after upgrading i have tried to apply PBR on my Vlan 4 and failed , when i am tying to apply route-map to Vlan4 the command was taking but i am unable to see the route-map when sh run , i am giving the command as "ip policy route-map TTSL" in my Vlan4 , below is the configuration.
 
In Vlan2 i have connected one ISP and Vlan4 I have connected one ISP , my local subnets are 192.168.1.x and 192.168.2.x , now i want to route the 192.168.1.x traffic from Vlan2 and 192.168.2.x Traffic from Vlan4 .
  
sh boot
coreswitch#sh boot
BOOT path-list      : flash:c3750-ipservices-mz.122-35.SE5/c3750-ipservices-mz.122-35.SE5.bin

[Code].....

View 9 Replies View Related

Synology DS1511 NAS / ISCSI Initiator Crashing Server 2008?

Aug 16, 2011

I have a Server 2008 server and a Synology DS1511+ Nas.The goal is to make an iSCSI connection from the Synology to the Server 2008 server. However, I am having an issue. I set this all up two weeks ago. For two weeks it was all running fine. Now, my iSCSI drive is dropping daily. And everytime I go into the iSCSI initiator and click anything, the server still allows me to do some things, but it basically locks up. I can't restart, services stop responding, etc... The only was I can break it out of that is a hard reset. Why iSCSI initiator keeps taking down my entire server to the point of hard restart? Once this is solved, I bet the iSCSI dropping daily will be solved as well. I have already talked with Synology, the log is producing nothing and they are suspicious that it has been running fine the past two weeks. Windows update is off (I manually do it during scheduled maintenance), and there is no av or firewall running, so rule those out.

View 8 Replies View Related

Cisco Routers :: SRP527W Act As L2TP Tunnel Initiator Over ADSL PPPoE Interface

Jan 29, 2013

We are using SRP527 routers with PPPoE ADSL connections. From the SRP527 we create an IPSec tunnel to our core routers (Cisco ASR). We are wanting to change the IPSec tunnels to L2TP, and I need to know if this can be done from the SRP527. I cannot find any L2TP configuration options in the setup options.Can the SRP527W act as an L2TP tunnel initiator over the ADSL PPPoE interface?

View 1 Replies View Related

Cisco Firewall :: ASA5505 Lose Configuration If Upgrade Firewall

May 17, 2011

i have asa 5505 with the asdm v5.2 (4), and the asa v7.2(4). This platform has a base license. if i upgrade adsm and asa on v6.2(1) and v8.2(2) if I lose my license and that you need to activate them? i configured site to site vpn (this firewall and the another) that i lose my configuration if i upgrade my firewall.

View 2 Replies View Related

Cisco Firewall :: ASA5505 Can't Ping New Firewall On Inside Interface

Jul 14, 2011

I've recently upgraded my old firewall from a PIX to an ASA5505 and have been trying to match up the configuration settings to no avail. I have is that I can't ping the new firewall on it's inside interface, despite having "icmp permit any inside" in the running config. Secondly, the server I have on there ("Sar") can't connect out to the internet.I've included the ASA's running config incase anybody can see if something stands out. I have a feeling it's either not letting anything onto the inside interface, or there is no nat going on. Lastly (and possibly relevant), the firewall is actually going at the end of a vlan, which is different to the firewall's inside vlan number. I don't know if this is actually the problem because the server can't connect out even if connected directly into the firewall.

View 32 Replies View Related

Cisco Firewall :: Using Static Policy NAT On ASA 8.2?

Jul 6, 2011

i am doind a policy NAT on the folowing scenarion. 
 
acess-list policy_nat extended permit ip host 10.0.0.1 host 192.168.1.1
static (inside,outempresa) 170.66.53.1  access-list policy_nat
 
I understand that when host A 10.0.0.1 wants to connect to host B192.168.1.1 its going to be translated to 170.66.53.1 when host  192.168.1.1 wants to connect to10.0.0.1  the same entry will change the destination when the packet hits the asa from 170.66.53.1  to 10.0.0.1, is that correct ?

View 2 Replies View Related

Cisco Firewall :: Policy Based NAT On ASA 8.4.1

Feb 27, 2011

How can I configure police-based nat to allow ICMP-only traffic on asaos 8.4.1 or 8.3?On 8.3 it was very simple:global (outside) 1 interface ,access-list outside_nat_outbound extended permit icmp any any,nat (outside) 1 access-list outside_nat_outbound.

View 10 Replies View Related

Cisco Firewall :: ASA 8.3 Dynamic Policy NAT

Apr 11, 2011

I have devices on Inside interface of ASA that need to get to Internet to get ntp. Hence I want to set up dynamic pat (interface overload) which 8.3 style would be
 
-object network obj_NTP-DEV
-host 192.168.1.250
-nat (INSIDE,INTERNET) dynamic interface
 
But I need to limit nat to only Internet destined traffic on ntp port not all ports for traffic from 192.168.1.250.I'm not using this nat set up to control outbound access - I also have incoming RA VPN tunnels to the box and traffic from these sources need to be able to get to 192.168.1.250 and the above simple set up would break that access as all traffic involving 192.168.1.250 would get nat'd
 
Reading the doco I've sent myself round in a loops trying to figure how you are meant to do such a  " Dynamic Policy NAT (overload)" call it what you will config in 8.3

View 2 Replies View Related

Cisco Firewall :: ASA5505 Firewall Rule Not Blocking

Apr 1, 2013

I'm trying to troubleshoot an ASA5505.
 
The original goal was to block "Mumble/Murmur" (a voip app) traffic, which runs on TCP/UDP 64738, both inbound and outbound, except to a certain host (63.223.117.170).
 
However, when nothing I tried seemed to make a difference, just to troubleshoot, I decided to try blocking all inbound traffic.  I first disconnected ethernet port 0/0 to ensure that it was cabled correctly and the outside interface went down when I did.  That worked as expected, so I confirmed I had the right interface and it was cabled correctly.
 
I then applied a "any any deny ip" rule as the first element in the outside interface access_list, as you can see below.  However, it appears to have had no real effect and the hit count is very low (it should be astronomical).
  
show ver 
Cisco Adaptive Security Appliance Software Version 9.0(2)
Device Manager Version 7.1(2) 
Compiled on Thu 21-Feb-13 13:10 by builders
System image file is "disk0:/asa902-k8.bin"

[Code].....

View 4 Replies View Related

Cisco Firewall :: Setup QoS Policy On ASA 5515?

Mar 18, 2013

I´m triing to setup a QoS policy on ASA 5515, i read several pages, but my questions are, how setup the real BW?, or is not necessary to do this?

View 7 Replies View Related

Cisco Firewall :: Configure Policy NAT On ASA5510?

Apr 12, 2011

how can I configure policy NAT on ASA5510. I would like to do the following;
 
9.1.1.9     NAT to      10.1.1.9
 If source IP =     1.1.1.1
then NAT to     =      10.2.2.9
the rest NAT to = 10.1.1.9
 
The issue is I want 1.1.1.1 NAT to 10.2.2.9 when access www.example.com. The rest NAT to current NAT.

View 4 Replies View Related

Cisco Firewall :: ASA5510 / Create NAT Policy For Two DSL Connections?

Sep 20, 2012

How to configure our ASA to nat our to internetconnections, at the moment the first work fine,
  
ISP1                        NAT
ASA5510      LAN
ISP2                         NAT

View 1 Replies View Related







Copyrights 2005-15 www.BigResource.com, All rights reserved