Cisco :: Unable To Ping Over Ipsec VPN?

Mar 25, 2011

I have created a site to site Ipsec vpn with a cisco 2610 and a linksys RV042. Running a show "crypto isakmp sa" command I get a qm_idle status and when running a "show crypto ipsec sa" I see that packets are being decrypted and encrypted. Also when running the "show ip access-lists" command I do have matches to that connection.The problem is that I am unable to ping hosts from one network to another. For example, from the Cisco router in network 192.168.0.0 I am unable to ping the remote network 192.168.2.0 and vice versa.

I am not sure what is happening. Do I need to create a route to that remote network? I guess it could also be a problem with NAT or an ACL.Here is what running-config shows:

crypto isakmp policy 1
encr 3des
hash md5
authentication pre-share
group 2
lifetime 28800

View 5 Replies


ADVERTISEMENT

Cisco Switching/Routing :: 1941 / K9 Unable To Ping Over Site To Site IPSEC

Jul 12, 2012

I am trying to set up a site to site ipsec connection. AT site A, I have Vlan's 652-10.55.216.0/24, Vlan653 -10.55.217.0/24, Vlan 654-10.55.217.0/24 and Vlan655-10.55.219.0/24 and at site B, Vlan650-10.55.214.0/24 and Vlan651-10.55.215.0/24.The problem is that I am unable to get any associations when i do a "sh crypto isakmp sa"/"sh crypto ipsec sa" on either router at each site.I am also unable to ping by pluging in a laptop into the site at each site. Laptop at site A is set to access vlan 655 and laptop at site B is set to acess vlan 651. I can ping all the devices from one end to the other.I have turned on debug crypto isakmp, debug crypto ipsec, debug crypto ipsec errors but dont get anything at all as output.I have attached the sh run for each router Cisco (1941/K9) and switch (Catalyst 3750) at each site.

View 4 Replies View Related

Cisco WAN :: 2911 - Site-to-site IPsec Vpn / Unable To Ping Remote Network

Apr 3, 2013

I have two Cisco routers - 2911 in HQ and RV180 in branch office. Because in HQ LAN network I have some development servers, to which guys from branch office need to have acces, I decided to setup VPN site-to-site between HQ and branch office. Everything went quite smoothly, on both devices I see, that ipsec connection is established. Unfortunately I am not able to ping resources from one network to other one and vice versa. Below is the configuration of 2911 router (I skipped som unimportant (imho) configuration directives) :
  
crypto isakmp policy 1
encr 3des
hash md5

[Code].....

View 9 Replies View Related

Cisco Switching/Routing :: 4.2.2 Unable To Ping 1 Internet Site From Edge Router Able To Ping

Jan 18, 2013

From My Router that connects to Cable modem i am unable to ping website 4.2.2.2I am able to ping all other websites fines.Same website i can ping from my pc and all other switches fine.Router has only 1 ACL thats for NAT.

View 25 Replies View Related

Cisco :: VPN IPsec IOS Cannot Ping

Mar 3, 2011

The VPN connection seems to be etablish but I can not ping the LAN behind the router .I can see the errors with debug ipsec

88.160.250.90 CLIENT VPM >>>>>>>ROUTEUR VPN 212.94.A.B>>>>>>>>>LAN 10.100.0.182
212.94.A.B (Router with configuration IPSec VPN)
88.160.250.90 (Client VPN vpnc)
192.168.2.25 (Client VPN remote ident : tun0 )

[code]....

View 2 Replies View Related

Cisco Firewall :: Can't Ping ASA5505 Over IPSEC VPN 8.2(5)

Feb 26, 2013

I'm a CIsco ISR, Setting up my first ASA, which seems to be going well.I've setup an IPSEC VPN to a non Cisco device. And have connectivity between devices in each subnet.
 
-Subnet A - non Cisco - 10.10.13.0/24
-Subnet B - ASA 5505 - 192.168.2.0/24 (ASA is .254)
 
From Subnet A I can ping every device except the ASA on .254.
 
Edited Config attached, IP's changed for privacy, passwords removed.Let me know if I've removed too much of the config.

View 3 Replies View Related

Cisco VPN :: SRP527W IPSec VPN Tunnel Works One Way / Can Ping Other Direction Too

Aug 2, 2012

I have a IPSec tunnel that is working in one direction. Below is the router config from the side that can connect to the other  side perfectly. I believe the issue is with this router as while I was  waiting on delivery for the ASA I had an SRP527W sitting in it's place  and had exactly the same problem.On one side I have a 887VA router and the other an ASA5505.The network behind the 887VA can access the remote site perfectly, backup services are traversing the link as are web interfaces for applications. In the other direction I can ping hosts but cannot connect. What else is interesting is if from the remote site I attempt to connect to a particular device that performs a port redirect the remote site browser gets so far as being redirected to port 5000 but then hangs.
 
I am seeing some very generic packet drop debug notices on the 887va on the NAT-ACL access list but I think this is as it should be as it is dropping the tunnel traffic from the NAT'ing.The config for the router is here, I will post the ASA config when I get to the other site shortly but I am convinced the issues is on this device, all the crypto configurations match.I have looked at the MTU's on each side, the path MTU on both sides is 1492. The asa does say the media MTU is 1500 but I believe that is the ADSL link so shouldnt matter?I even went so far as installing CCP and testing the VPN. It says the tunnel is up. It did state a failure:A ping with data size of this VPN interface MTU size and 'Do  not Fragment' bit set to the other end VPN device is failing. This may  happen if there is a lesser MTU network which drops the 'Do not  fragment' packets. [code]

View 1 Replies View Related

Cisco VPN :: Cannot Ping Packet Size Larger Than 9200 Over IPSec On ASR

Feb 22, 2011

I have an existing site-2-site VPN between a Cisco 2621 router (IOS 12.3) and Cisco 1841 (IOS 12.3) and I can ping packet size of 17000 over the IPSec tunnel without any issue:c2621#ping 192.168.230.254 source f0/1 repeat 20 size 17000,Type escape sequence to abort.Sending 20, 17000-byte ICMP Echos to 192.168.230.254, timeout is 2 seconds:Packet sent with a source address of 192.168.208.254!!!!!!!!!!!!!!!!!!!!Success rate is 100 percent (20/20), round-trip min/avg/max = 144/146/148 msc2621#I replaced the Cisco 2621 with a more powerful ASR 1002 running IOS version asr1000rp1-adventerprisek9.03.01.00.S.150-1.S.bin.  However, I can not ping packet size larger than 9200 over the IPSec tunnel:Feb 24 02:42:52.362: %IOSXE-3-PLATFORM: F0: cpp_cp: QFP:00 Thread:015 TS:00000015834854465792 %IPSEC-3-PKT_TOO_BIG: IPSec Packet size 10072 larger than maximum supported size 9216 hence dropping it.Success rate is 0 percent (0/10)asr1002# Why is not working?  Basically the more expensive ASR router can not perform the same task as the old Cisco 2621 router.

View 6 Replies View Related

Cisco Routers :: RVS4000 - IPSec VPN Tunnel / Cannot Ping From One Network To Other

Aug 5, 2011

I have a RVS4000 at one location and a second RVS4000 at home.  I have established an IPSec VPN tunnel between them and it is UP.  I can ping the routers from each end no problem.  I can ping  the IPs listed in the "Local Group Setup" and the "Remote Group Setup" from both ends no problem.  I can even open up a shared resource from a Win 7 machine (e.g. by typing \10.10.10.100 in start-run from a computer on my home network).
 
But - i can't ping anything else on one network from the other.  What gives?  I need to access a 10.10.10.101 machine but can't even ping it.  
 
- both RVS4000 boxes have latest firmware (V1.3.3.5)
- home RVS4000 setup with IP 10.10.11.1
- home network has a server with IP 10.10.11.20
- other location RVS4000 setup with IP 10.10.10.1
- other location server setup with IP 10.10.10.100
 
Tunnel settings on home RVS4000 (the other location properly mirror these).
  - Local Security Gateway Type :  IP Only
  - Local Security Group Type : Subnet
  [code]....

View 2 Replies View Related

Cisco Switching/Routing :: 881 - IPsec VPN Tunnels / Ping From Workstations

Sep 25, 2012

We have a number of sites running Cisco 881 routers. A few of the sites are connected by IPSec VPN tunnels that have been configured using Cisco CCP without any issues until now.  On one location I can ping from a workstations on  Site1 to Site2, however I cannot ping from the same workstation on Site2 back to Site1.
 
Here is a strange behavior.  If I have a continuous ping going from Site1 - Site2 and then start a continuous ping from Site2 - Site1 then I get a response  until I stop the ping from Site1 - Site2.  Site 1 has approximately 5 successful tunnels with absolutely no issues. 
 
Here is some site specific Info:

Site1
Cisco 881 running Version 15.0(1)M7
crypto isakmp policy 1encr 3desauthentication pre-sharegroup 2crypto isakmp key ThePreShareKey address XXX.YYY.ZZZ.232 crypto map SDM_CMAP_1 1 ipsec-isakmp description Tunnel toXXX.YYY.ZZZ.232set peer XXX.YYY.ZZZ.232set transform-set [code]......
 
Site 2
Cisco 881 running Version 15.2(3)T1  
crypto isakmp policy 2encr 3desgroup 2crypto isakmp key ThePreShareKey address TTT.UUU.VVV.224
[code].....
 
For additional troubleshooting I established a VPN tunnel from Site2 to our office Site3 with no issues at all. Site3 happens to be one of the VPN tunnels that connects to Site1 with no issues. I have seen a number of articles on this on the net and gone through the troubleshooting steps of an article such as [URL]. The tunnel is confirmed as up when I have done all my troubleshooting.

View 20 Replies View Related

Cisco VPN :: ASA 5520 - IPSEC Tunnel / Error When Ping Protected Network

Nov 2, 2009

On my ASA5520 I am trying to do a IPSEC tunnel between two sites. When I ping the protected network on the other side I get this when debugging IPSEC:
 
IPSEC(crypto_map_check): crypt o map man map 20 does not hole match for ACL man1
 
Not too sure what this means...

View 11 Replies View Related

Cisco VPN :: Configuring L2TP IPSEC VPN On ASA 5505 / Can’t Ping Or Access Resources

May 2, 2011

I’m configuring a L2TP IPSEC VPN on a 5505 asa so that windows 7 clients can natively connect. It connects correctly during Phase 1 and 2, but I can’t ping anything or access resources on the internal network. This is my first time working with an ASA.

Master# sh run
: Saved
:
ASA Version 8.2(2)
!
hostname Master
domain-name service.local

[code]....

View 2 Replies View Related

Cisco Security :: 1941 - Unable To IPsec

Oct 10, 2012

I did purchase a router 1941 universal k9 but i can not do ipsec on it, i took a smart net for that router in order to have or download ipsec on it.

View 1 Replies View Related

Cisco :: Unable To Ping In Dos?

Mar 9, 2013

*I have 2 cisco routers 2811 router A&B*using 0/0 for WAN and 0/1 for LAN on both routers*both routers are connected together with crossover cable to 0/0. recieve link and activity*both routers are on the same subnet Router A:0/0 192.168.1.1/24 - router A:0/1 192.168.2.1/24 ; Router B:0/0 *192.16.1.2/24 router B:0/1 192.168.3.1/24*I can ping the inside and outside address of both router from PCs connected at its respectable end. *PC A 192.168.2.2/24 PC B 192.168.3.2/24 *when connected to router A 0/1 and I try to ping router B 0/0 it times out in DOS* but I AM (CAN) able to ping from PC A to router B 0/0 in hyperterminal, telnet and Cisco SDM. I just CANNOT ping in DOS?

View 10 Replies View Related

Cisco VPN :: Cannot Ping From Outside To Inside Site To Site IPsec 5505

Oct 28, 2012

I have a very basic lab site to site vpn setup where I have a ASA 5505 running v7.2(4) on one side and a cisco 2811 on the other side.

What's my issue?

I can't seem to ping from cisco router to the 'inside' network of ASA (see config below) and can't seem to ping from ASA packets leaving the 'inside' interface to cisco router even w/ an ICMP ACL permit outside in. However I'm able to ping within ASA inside network & ping cisco 2811 side w/ packets leaving ASA 'outside' interface just fine.
 
example:
-------
ciscoasa# ping inside 10.20.20.1 (to cisco loopback1 from ASA inside)
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 10.20.20.1, timeout is 2 seconds:
[Code].....

View 6 Replies View Related

Cisco Routers :: SRP541W Unable To Create IPSEC Policy To ANY (0.0.0.0)

Feb 26, 2012

Unfortunately, it does not appear as if the SRP500 series will allow you to create an ipsec policy where the local or remote traffic selection is 0.0.0.0/0.0.0.0. It wants a specific network. I have a scenario where I want to send all traffic over the vpn tunnel.
 
Is there a workaround to this or a special way to input "ANY" as the remote network?

View 3 Replies View Related

Cisco VPN :: ASA 5505 - Unable To Browse Web With IPad / IPhone Using Ipsec?

Apr 6, 2013

I really worked hard not to write this question here but here I am. I am trying to route all traffic through vpn but I cant browse the web. It seems no traffic goes through the vpn tunnel. Split tunneling works but it doesnt route the traffic through vpn tunnel.  I have a cisco asa5505 with base license,
 
When I try to browse the web with one of the clients  I see lots of 
 
6Apr 07 201309:40:5510.10.50.136088410.10.10.153Built inbound UDP connection 834 for outside:10.10.50.13/60884 (10.10.50.13/60884) to outside:10.10.10.1/53 (10.10.10.1/53) (xxxx
  
messages but at the end I see " Safari could not open the page because the server stopped responding" message or smth similar. 
 
My setup is 
 
Vpn Clients         ======  asa5505   ==========   CiscoLinksysEA4500 Router   ========  ISPProvidedFiberConverterDevice(huawei)
10.10.30.10-10.10.30.50            10.10.10.2(outside int)               10.10.10.1(inside)  PPOE(outside)

[Code].....

View 1 Replies View Related

Cisco VPN :: 1800 - IPSec Remote VPN Clients Unable To Communicate Each Other

Jan 28, 2013

We are configured the Remote IPSec VPN on cisco  1800 series router.The Clients are able to login to VPN and access the local corporate network Servers . But VPN Clients are not able to communicate with  other VPN clients using their VPN Adapter IP.

Components used :
 CISCO VPN Client 5.7
Router 1800 Series

View 9 Replies View Related

Cisco VPN :: 2801 - Unable To Route Traffic Over IPsec / GRE Tunnels

Jan 12, 2013

I have an issue where I can get traffic to pass from HDQ to two branch offices over our ipsec/gre tunnels even though the tunnels appear to be UP. The HDQ is a 2811, branch is a home office using an 871W and branch runs a 2801 router. I initially had HDQ working fine with the 871W but when I configured branch2 (2801), they both broke. The tunnels appear to be up but traffic is not routing across them. The two 2801 routers run 12.4 (c2800nm-adventerprisek9-mz.124-24.T2.bin). These are gre over ipsec tunnels. Currently traffic flows over an exsting MPLS network that we are getting away from due to cost. As soon as I change the routes to point to the Tunnels, it breaks. Traffic doesn't appear to pass through the tunnel. I have attached my sanitized configs.

HDQ#sh crypto sessCrypto session current status
Interface: FastEthernet0/1Session status: UP-ACTIVEPeer: 205.205.205.21 port 500  IKE SA: local 204.204.204.66/500 remote 205.205.205.21/500 Active  IPSEC FLOW: permit 47 0.0.0.0/0.0.0.0 0.0.0.0/0.0.0.0        Active SAs: 4, origin: crypto map  IPSEC FLOW:

[Code]....

View 3 Replies View Related

Cisco VPN :: ASA 5520 / IPSec Over TCP - IKE Initiator Unable To Find Policy?

Jun 9, 2012

I've tried to set up IPSec over TCP with a VPN-Client V5.0.07.0440 on Win 7 64b to my ASA 5520 (Version 8.2(2)16) regarding to
 
[URL]
 
IPSec over TCP activated at the ASA
crypto isakmp ipsec-over-tcp port 10000
 
and in the transport tap of the VPN connection 'enable transport tunneling' with IPSec over TCP an port 10000 instead of 'IPSec over UDP' The connect timed out with error code 412 And this is my log from the ASA:
 
%ASA-7-710005: TCP request discarded from 178.x.x.x/53225 to INTERNET:212.x.x.x/10000
%ASA-3-713042: IKE Initiator unable to find policy: Intf INTERNET, Src: 212.x.x.x, Dst: 178.x.x.x
%ASA-7-710005: TCP request discarded from 178.x.x.x/53225 to INTERNET:212.x.x.x/10000
%ASA-3-713042: IKE Initiator unable to find policy: Intf INTERNET, Src: 212.x.x.x, Dst: 178.x.x.x
 
I don't have a clue what's here missing.I have static crypto maps for the L2L tunnels and the default dynamic crypto map for the VPN clients which come over NAT-T
 
crypto map INTERNET_map 65535 ipsec-isakmp dynamic SYSTEM_DEFAULT_CRYPTO_MAP
crypto dynamic-map SYSTEM_DEFAULT_CRYPTO_MAP 65535 match address INTERNET_cryptomap_65535.65535
crypto dynamic-map SYSTEM_DEFAULT_CRYPTO_MAP 65535 set pfs
crypto dynamic-map SYSTEM_DEFAULT_CRYPTO_MAP 65535 set transform-set ESP-AES-256-SHA ESP-AES-256-MD5 ESP-3DES-SHA ESP-3DES-MD5
crypto dynamic-map SYSTEM_DEFAULT_CRYPTO_MAP 65535 set reverse-route

View 1 Replies View Related

Cisco :: Unable To Ping From Static IP?

Oct 26, 2012

I am connecting a 2600 router to an ISP. Interface 0/0 is connected to the ISP using DHCP. Interface 0/1 is connected to the inside providing DHCP services to the inside. At least it should only be providing DHCP services to the inside. I also have a public static IP that is NAT to a private static IP. Everything is working except the computer on the static IP. From the router I am able to ping inside and out from each interface. I am able to ping both interfaces of the router from the computer on the static IP but I cannot ping outside the router. If I do a debug all I see a reject for the gateway of the static IP but it has “mobile IP” in the text string. Not sure what mobile IP is relating to. Networks are as follows:

0/0 DHCP 10.X.X.X
0/1 192x.x.x
Static 75.X.X.X

[Code].....

View 13 Replies View Related

Cisco WAN :: 2911 Unable To Ping From LAN To WAN

Apr 26, 2012

I have the following setup where the Cisco ME 3400 provided by the ISP.
 
My Cisco 2911 is configured as below:
 
CORE_Router#sh run
Building configuration...
 Current configuration : 6075 bytes

[Code].....

View 6 Replies View Related

Cisco VPN :: ASA 5505 - Unable To Ping Or Use DNS On LAN

Aug 18, 2011

I've been called upon to fix the  SSL VPN issues in our ASA5505.  The issue I am having is that I am able  to log into the vpn, access the internet, but I'm unable to access  anything on the LAN.  I can't use ping or use DNS. 
 
I'm using ASDM v. 6.2(1) and ASA verison 8.2(1).  I'm not comfortable using the CLI and prefer the GUI.

View 13 Replies View Related

Unable To Ping Any System In LAN?

Mar 9, 2011

We have many CT/MRI etc. machines and Servers in the Hospital LAN. Now intermittently we are loosing the LAN connectivity i.e we are not able to ping any system from any node inside the hospital network for sometimes, after some time it will start working and then again it will stops again.We are using procurve switches and also we are not using any router

View 2 Replies View Related

Unable To Ping From One Another With OS XP And Windows 7

Sep 14, 2012

I m not able to ping from one to another with the os win XP n other with win 7.

View 1 Replies View Related

D-Link DIR-615 :: Unable To Ping It

Jul 29, 2011

I'm trying to do port forwarding on my DIR-615...first of all I need to be able to ping the router from outside! I did enable the ping options to allow request from WAN...still don't work!!I removed the router and plug my laptop directly on my cable modem adapter and I'm able to ping my IP address (did put the same address the router had)...so, the IP is OK and it is possible to get in the modem from outside.I did plug back the router, and still not working...I did some trick like enable all IP with the Inbound filter...give access to few MAC address that I have to give more chances to get in and still not working!!!

View 6 Replies View Related

Cisco Routers :: RV110W IPSec - Unable To Set Local Endpoint To FQDN

Jan 5, 2013

I am trying to connect my RV110W from my home office to our office IPSec router.  I have a dynamic IP address and am using DDNS, therefore the RV110W local endpoint needs to be configured with my FQDN, not the IP address as this will change.
 
On page 100 the manual states
 
Step 4 -
 
• Local WAN (Internet) IP Address—Enter the public IP address or domain name of the local endpoint (Cisco RV110W).
 
This option is not available in my router - I am running firmware 1.2.0.9

View 10 Replies View Related

Cisco Firewall :: ASA 5505 Unable To Ping

Sep 9, 2011

I just tried to configure my ASA but unable to ping.  My setup is as follows:
 
Cable Modem (DHCP from IPS)---> ASA (192.168.1.1)--->Belking Router (192.168.5.1)--->Switch (192.168.5.14)--->
 
ASA Version 8.2(3)
!
hostname WoodHomeASA-1

[Code].....

View 30 Replies View Related

Cisco WAN :: Unable To Ping Across Subinterface On 1941w

Oct 10, 2011

I am currently working on a 1941w router. The problem that I am having is that I am unable to ping the switch that is directly connected to it and I am unable to ping from the switch to the router. If I take the address off of vlan 1 and move it to gi0/0.1 the pings work, but then client traffic on the wireless ap inside the 1941w fails.
  
Here is the releveant config off of the 1941w
 
version 15.0
no service pad
service timestamps debug datetime msec localtime show-timezone

[Code].....

View 3 Replies View Related

Cisco :: 3750 Unable To Ping Server

Jun 5, 2012

im trying to connect a dell MD3000i to a Cisco 3750-s but i am not abel to ping the server.the status is up and Protocol is up. but still nothing.i configerd the port to be a acces port and also at trunk port but still nothing is happening.

View 1 Replies View Related

Cisco WAN :: 3560 / Unable To Ping Out From LAN Via PIX Firewall

Mar 29, 2012

I have the following setup.
 
host PC (192.168.9.3) -----> gateway (192.168.9.2) ----- Pix E1 (192.168.9.1)/Pix E0 (81.x.x.250) ------ Internet
 
The 192.168.9.2 gateway is a 3560 switch connected to the PIX. I can ping out to the Internet via IP from the PIX, but not via the host PC (192.168.9.3) on the LAN. PIX and gateway configs below. Am I missing something that's preventing me pinging out to the Internet from the internal LAN?
 
PIX config
 
test-cal-pix01# sh run
: Saved
:
PIX Version 8.0(3)
!
hostname test-cal-pix01
enable password btf1YD.Vq7mE6vEA encrypted

[code]....

View 1 Replies View Related

Cisco VPN :: 5520 - Unable To Ping To NAT Address Over VPN

Dec 14, 2011

i have a site to site vpn stablished, the vpn works fine (while is up), i have a cisco asa 5520 and the other end of the vpn is a jupiter device that for technical reasons needs to send a continuos ping and when it does not receive a reponse back it brings down the vpn tunnel and reestablish it again. while the vpn is up traffic flows perfectly but because i m unable to repond to the ping the vpn is brought down as reestablished by the jupiter device. the jupiter device pings the encryption domain which is an ip that is natted to the real ip in the inside network. this is my configuration of the vpn:

AAA.AAA.AAA.AAA is the ASA public ip in the outside
BBB.BBB.BBB.BBB is the jupiter device ip (part of the object group IP_LIST)
CCC.CCC.CCC.CCC is the nat ip on the ASA
10.21.0.164 is the real address in the inside(code)

View 1 Replies View Related

Cisco WAN :: 2620 - Unable To Ping DSL Modem

Nov 25, 2011

I have 3 2620xm routers connected via dte/dce serial connections In a lab.One of the routers Is also connected to a 2950 switch.

The 2950 switch connects to an unmanaged tp-link switch that Is connected to a dsl modem/router.I have Internet access via the 2950 to my laptop.

I have ripv2 enabled on all the routers and It's working fine.The dsl modem, switch and connected router are on the same subnet.

  When I ping the dsl modem via the 2950 or via the router connected to the 2950 , It works 100%.If I ping the 2950 from either of the other two routers , It also works 100%.I can't ping the dsl modem however from the other two routers.I've only been studying for the ICND1 so maybe there's something I'm missing here.

View 4 Replies View Related







Copyrights 2005-15 www.BigResource.com, All rights reserved