Cisco VPN :: 2801 - Unable To Route Traffic Over IPsec / GRE Tunnels

Jan 12, 2013

I have an issue where I can get traffic to pass from HDQ to two branch offices over our ipsec/gre tunnels even though the tunnels appear to be UP. The HDQ is a 2811, branch is a home office using an 871W and branch runs a 2801 router. I initially had HDQ working fine with the 871W but when I configured branch2 (2801), they both broke. The tunnels appear to be up but traffic is not routing across them. The two 2801 routers run 12.4 (c2800nm-adventerprisek9-mz.124-24.T2.bin). These are gre over ipsec tunnels. Currently traffic flows over an exsting MPLS network that we are getting away from due to cost. As soon as I change the routes to point to the Tunnels, it breaks. Traffic doesn't appear to pass through the tunnel. I have attached my sanitized configs.

HDQ#sh crypto sessCrypto session current status
Interface: FastEthernet0/1Session status: UP-ACTIVEPeer: 205.205.205.21 port 500  IKE SA: local 204.204.204.66/500 remote 205.205.205.21/500 Active  IPSEC FLOW: permit 47 0.0.0.0/0.0.0.0 0.0.0.0/0.0.0.0        Active SAs: 4, origin: crypto map  IPSEC FLOW:

[Code]....

View 3 Replies


ADVERTISEMENT

Cisco VPN :: ASA5510 - Slow Traffic On IPSec Tunnels

May 2, 2013

We have many VPN tunnels back to our corporate office.  All of these tunnels are very slow (same with our client VPN's).  Our main firewall device at the corporate office is an ASA5510.  We have a 100 Mb/sec Metro Ethernet internet connection here.  We do not allow split-tunneling.

Our remote sites vary.  We have DSL connections, cable internet connections, and other types of broadband that vary in speeds from 5 to 100 Mb/sec (up and down).  The remote sites mostly have PIX 501's, but we have an ASA 5505 in one of the locations.

To take an example.  On one of our remote sites that has a 100 Mb/sec connection, if I ping device to device, I'm getting ping times of about 50ms.  And I'm pinging back through another 100 Mb/sec connection.  If I get on a computer down there and run a speed test, I'm showing down speeds of about 1.5 Mb/sec... nowhere near 100.  Some of that could be due to the lack of split tunneling, but I also suspect this could be an MTU issue. 

Right now, all my MTU's are just set to the default 1500.  Perhaps this is too high.  I used this site to check my max: [URL]
 
I did a few tests from behind several of my firewalls.  I pinged from a machine on one side of the tunnel to the firewall on the other end.  I'm assuming the max MTU I come up with is the max MTU for the firewall I'm behind while pinging, right?  The max amounts I came up with for some of my devices were as follows: Corporate ASA 5510 > 1272 (if you add the 28 byte packet header that would make it 1300) Remote PIX 501 > 1416 (if you add the 28 byte packet header that would make it 1444) Remote ASA 5505 > 1418 (if you add the 28 byte packet header that would make it 1446)

So, do I just need to set my MTU values to the appropriate amounts?  I have tried changing the value, but I don't see any change in speed/performance.  But I also don't know if I need to reboot the firewalls after changing the MTU.  I know with Catalyst switches, you have to reload.  But I didn't see any messages about needing to reboot on the ASA's/PIX's.

View 10 Replies View Related

Cisco VPN :: 881 / Route Traffic Thru IPSec Tunnel To DMZ

Jun 29, 2011

I need to route traffic to DMZ (and internal) from the branch office thru the IPSec tunnel. How do I manage that with my Cisco 881?

View 1 Replies View Related

Cisco VPN :: 881 / Route All Traffic Over IPsec Tunnel?

Jan 30, 2012

We have 7 remote offices and 10 tower locations that utilize IPsec tunnels back to our HQ. We now want to force all traffic including web surfing through the tunnels. What would be the easiest way to acomplish this? I have tried utilizing the crypto map policy to do this, but was unable to acomplish this.
 
Each of our office locationss utilize a Cisco 2811 router and the tower locations utilize a Cisco 881.

View 21 Replies View Related

Cisco Wireless :: WRVS4400N Won't Route All Traffic Over IPsec

Dec 15, 2011

All of my remote sites use various routers to route all of their traffic via IPsec.  However, I have one WRVS4400N w/firmware 2.0.2.1 configured with a working tunnel.  My issue is I need to set the Remote Group to 0.0.0.0 0.0.0.0 so all traffic is forced via IPsec tunnel and not out the local gateway.  When I do the error, Remote Security Group and Local Security Group cannot be in the same network. However, it works with Cisco/Linksys RV042.

View 3 Replies View Related

Cisco VPN :: ASA 5520 IPSec Overlap - How To Route Traffic

Nov 13, 2011

We have multiple vpn tunnels coming to our cisco asa 5520 , the problem is that when we create another tunnel with the same network as another network on the firewall , it does not know how to route the traffic to which interface or sub interface.

View 2 Replies View Related

Cisco VPN :: ASA 5500 - Restored Failed Unit Now Unable To Pass Traffic Over VPN Tunnels

Nov 11, 2012

I restored the HA pair back to Active/Standby.
 
1 remaining issue.
 
I have 3 IPsec Site-to_SIte tunnels.
 
I noticed that when the NEW UNIT becomes ACTIVE that I am unable to pass traffic over the VPN tunnels.When I failback I am able to pass traffic.

View 7 Replies View Related

Cisco VPN :: 5505 Unable To Route Traffic Through VPN Tunnel

Mar 17, 2011

We have a VPN setup and here's the configuration on the Cisco ASA 5505: [code] The problem is that i'm able to ping the otherside of the tunnel i.e. 192.168.23.14 from the dmz IP 172.16.1.2 but i'm unable to ping from the hosts behind the ASA.Also the other side is able to ping 172.16.1.2 IP but no IP's behind the ASA.

View 9 Replies View Related

Cisco Routers :: 527W Unable To Route Traffic Via APN Backup Without Disabling VPN Tunnel

Oct 9, 2012

I have a Cisco 527w which we are wanting to deploy to our remote sites however i've found a bug. We use ADSL with an IPsec tunnel as primary and 3G APN for failover . When the ADSL goes down the route via the IPSec tunnel remains and i am unable to route the traffic via the APN backup without disabling the VPN tunnel .

View 0 Replies View Related

Cisco WAN :: 1921 - Route Between VPN Tunnels

Jul 7, 2011

I have a Cisco 1921 and it has 2 VPN IP-sec site-to-site tunnels up and running. Lets say the tunnels goes from the Cisco to Site A and Site B.

Now i want Site A to reach Site B through the existing tunnels. I'm guessing that static routes maybe the answer but i cant seem to get it working.

The LAN networks is as follows:
Cisco: 192.168.15.0/24Site A: 192.168.0.0/24Site B: 10.27.27.0/24
 
At Site A i have set up a static route as follows:
Traffic destined for 10.27.27.0/24 Go to gateway 192.168.15.1 (the default gateway of Cisco LAN)

At Site B i have set up a static route as follows:
Traffic destined for 192.168.0.0/24 Go to gateway 192.168.15.1 (the default gateway of Cisco LAN)

View 9 Replies View Related

Cisco WAN :: 2801 Route-Map Not Seeing DHCP Next-Hop

Dec 23, 2011

I have a 2801 with dual ISP connections, and I have configured route-maps to direct voice traffic over ISP1 (working just fine), and I'm attempting send all other traffic over ISP2 (traffic is load-balancing instead).  The connection to ISP2 is DHCP, and I have configured a route-map to route this traffic using the 'ip next-hop dynamic dhcp' command, but when I look at the route-map, it states the following: ip next-hop dynamic dhcp - current value is UNKNOWN..Is there something that I need to enable in order to see the next-hop, and properly send traffic over the ISP2 connection? [code]

View 9 Replies View Related

Cisco WAN :: 2801 Route-map For Static NAT Translation

Dec 6, 2010

I have a nat and vpn setup on my Cisco 2801 router.Everything is working as expected except the NAT.  I have a single static nat translation but it only works for inbound and not outbound.  Going outbound, it uses the default overload nat address of the outside interface. [code] I want to add another mailserver.  But I fear if one mailserver were to get black-listed, they would both be reporting there ip address as the same address (the one on the ethernet interface) which would blacklist both mail servers.Again, inbound nat works ok, but outbound is just using the IP of the ethernet0/0 address.

View 2 Replies View Related

Cisco VPN :: Configure IPSec Tunnels On 941SEC/K9?

May 26, 2013

My company paid a Cisco 1941 SEC/K9. There is no VPN SSL Licence. I would like to know if I can configure IPSec tunnels basically on my router?
 
In this case, how many IPSec Tunnels I can configure?
 
how configuring IPSec Tunnels on my router?

View 3 Replies View Related

Cisco VPN :: IPSec Tunnels Between ASA 5510 And 5555

Nov 13, 2012

I have an ASA 5510 running ver 8.0(2) that has (4) Ipsec tunnels going from it to various other locations.  I am having an issue with data transfer speed on only one of the Tunnels.  This tunnel is between the 5510 and the 5555, on that link I am getting a dat transfer rate of a little over 120k a second, whereas if I pull the same set of files from another location I am seeing a transfer rate of 5m per second. 
 
I have verified that it is not a capacity issue on the Internet bandwidth on both locations, and I can pull the same data from the same location to various other locations via Ipsec tunnels, I am only having an issue with a specific tunnel going from the 5510 to the 5555. 
 
Since it is not affecting other tunnels on the 5510 nor is it affecting tunnels on the 5555 going to other locations, I am leaning toward a routing issue within the ISP?  I will say the ISP is taking me a long way around to stay in the same Metropolitan area.

View 1 Replies View Related

Cisco VPN :: 2801 VPN IPSEC Is Restarted

Oct 14, 2012

I have a Cisco 2801 with flash: c2801-advipservicesk9-mz.124-16.bin where I use to doing VPN IPSEC.My problem is where I do a connection with a client, if my VPN dont have a traffic, the tunnel are closed. If a receive or send any traffic, the tunnel get up again.If  don't have traffic, this tunnel is closed and after is opened other tunnel where is changed the conn-id to 999 for example.This comportament is normal? Exist a form that my tunnel never close? I enabled the parameters below: [code] But the tunnel continues closing if a don't have traffic.

View 5 Replies View Related

Cisco VPN :: 2801 IPSec VPN Not Working

Mar 21, 2012

We are setting up a new VPN from an ASA to a cisco 2801 router (behind a third parties checkpoint firewall).  We seem to be almost there with the setup but the tunnel is not working correctly.  I have included a debug from the 2801 router and its config and a diagram of the setup. [code]

View 2 Replies View Related

Cisco :: IPSec GRE Tunnels And Traditional Site VPNs

Mar 21, 2011

I've been reading this site for a while, and finally decided to post I'm really interested to see what everyones opinion on this is.My company currently uses what i would call traditional site to site VPN's using crypto maps, main site has a pair of ASA's in HA and remote sites use ISR's like 1801's.I've recently been playing in my lab with GRE tunnels using IPSec protection (note this is config from my labs, so ip's and key's are just randomly selected)

View 17 Replies View Related

Cisco VPN :: 1921 Router Q - How Many IPsec Tunnels Will It Support

Nov 8, 2011

I need to know how many IPsec VPN tunnels one Cisco1921 can support reliably. Haven't had any luck sifting through documentation on the web.

View 2 Replies View Related

Cisco WAN :: How Many Ipsec Tunnels Are Supported In 3900 Routers

Jul 30, 2011

How many ipsec tunnels are supported in Cisco 3900 routers(with & without the hardware processors)?How much is the throughput of the 3900 routers?

View 1 Replies View Related

Cisco WAN :: Config ASA5510 For Multiple IPsec Tunnels

May 13, 2013

How to configure CISCO ASA 5510 for multiple IPsec tunnels?On other side is CISCO 2801.

View 20 Replies View Related

Cisco VPN :: ASA 5550 And 5510 / SNMP For IPsec Tunnels?

Jan 23, 2011

I tried to monitor via SNMP my ASA 5550&5510 my Active IPSEC tunnels , I want to receive Bandwidth for each tunnel interface.I’m running Version 8.2(1)?  which OID to use?

View 3 Replies View Related

Cisco Routers :: How Many IPSec Tunnels WRVS4400N Can Passthrough

Jan 31, 2012

I'm trying to find a reference for how many IPSEC tunnels the WRVS4400N can passthrough. 

View 0 Replies View Related

Cisco Firewall :: How Many IPSec Tunnels An ASA 5500 Series Supports

Aug 4, 2012

I tried looking in ASA documentations but unable to find out that how many IPSec Tunnels can be terminated to an ASA cluster. I have 5545 running only two IPSec Tunnels so far but need to terminate 18 sites all up and would like to confirm how many tunnels we could terminate? Is there a limitaion to it?

View 2 Replies View Related

Cisco VPN :: ASA 5505 - Configure Allowed Bandwidth On IPSec Tunnels?

Oct 25, 2011

ASA 5505 8.2.1
ASA 5520 8.4 
 
We currently have a tunnel configured between 2 ASAs
 
1-  Is it possible to assign 1.5 Mbits of Bandwidth(BW) to this tunnel?. Then if Tunnel number 2 is configured I could assign 2 Mbits to that one for example?
 
I am not referring to prioritizing certain type of traffic over the IPsec tunnel, I am referring to Tunnel 1 has 1.5 Mbits of BW guaranteed for all traffic that goes thru it. Same for tunnel 2
 
Then
 
2- How to monitor the amount of BW in an IPsec tunnel?

View 1 Replies View Related

Cisco VPN :: Create Multiple IPsec Tunnels On 837 ADSL Router?

Nov 4, 2011

I need to create multiple ip-sec vpn tunnels on A Cisco 837 ADSL Router. I am able to create one tunnel but the second connection is asking for the outside interface which is atm and already taken by the first tunnel. How can i create more tunnels?
 
Secondly, after creating the first tunnel i am able to access the remote lan network but when i tried tracert "remote lan ip of a pc" from my pc i got "request timed out" after passing my 837 but succeeded to reach the target. Does tracert needs something to be opened in the router?

View 2 Replies View Related

Cisco Switching/Routing :: 881 - IPsec VPN Tunnels / Ping From Workstations

Sep 25, 2012

We have a number of sites running Cisco 881 routers. A few of the sites are connected by IPSec VPN tunnels that have been configured using Cisco CCP without any issues until now.  On one location I can ping from a workstations on  Site1 to Site2, however I cannot ping from the same workstation on Site2 back to Site1.
 
Here is a strange behavior.  If I have a continuous ping going from Site1 - Site2 and then start a continuous ping from Site2 - Site1 then I get a response  until I stop the ping from Site1 - Site2.  Site 1 has approximately 5 successful tunnels with absolutely no issues. 
 
Here is some site specific Info:

Site1
Cisco 881 running Version 15.0(1)M7
crypto isakmp policy 1encr 3desauthentication pre-sharegroup 2crypto isakmp key ThePreShareKey address XXX.YYY.ZZZ.232 crypto map SDM_CMAP_1 1 ipsec-isakmp description Tunnel toXXX.YYY.ZZZ.232set peer XXX.YYY.ZZZ.232set transform-set [code]......
 
Site 2
Cisco 881 running Version 15.2(3)T1  
crypto isakmp policy 2encr 3desgroup 2crypto isakmp key ThePreShareKey address TTT.UUU.VVV.224
[code].....
 
For additional troubleshooting I established a VPN tunnel from Site2 to our office Site3 with no issues at all. Site3 happens to be one of the VPN tunnels that connects to Site1 with no issues. I have seen a number of articles on this on the net and gone through the troubleshooting steps of an article such as [URL]. The tunnel is confirmed as up when I have done all my troubleshooting.

View 20 Replies View Related

Cisco WAN :: 2801 - Gather Netflow Data Over IPsec VPN?

Feb 14, 2011

I'm trying to gather netflow data over an IPSEC VPN and through my research I've learned that I need to configure Flexible Netflow.  However, I have a Cisco 2801 router with the latest ROMMON and IOS and the Flexible Netflow options aren't available. 
 
For instance:
 
flow exporter dwtmonitor
destination 10.0.16.172
source Loopback0
transport udp 2055
output-features

When I type "flow exporter <name>" it only allows me to enter "flow <name>" and there's no "destination" options or anything else.
 
ROMMON: 12.4(13r)TIOS:  12.4(25d)

View 2 Replies View Related

Cisco VPN :: Establish IPSec Tunnel Between 2801 And Cyberoam Equipment At End Point?

Mar 31, 2011

i'm triyng to establish a vpn ipsec tunnel between my cisco2801 and a cyberoam equipment, at the end point.Debugging isakmp, i have this output, where xxx.xxx.xxx.xxx is the remote peer address, and yyy.yyy.yyy.yyy is mine.What can i try?
 
Apr  1 14:48:12.542: ISAKMP:(0): SA request profile is (NULL)Apr  1 14:48:12.542: ISAKMP: Created a peer struct for xxx.xxx.xxx.xxx, peer port 500Apr  1 14:48:12.542: ISAKMP: New peer created peer = 0x661C2D4C peer_handle = 0x80000003Apr  1 14:48:12.542: ISAKMP: Locking peer struct 0x661C2D4C, refcount 1 for isakmp_initiatorApr  1 14:48:12.542: ISAKMP: local port 500, remote port 500Apr  1 14:48:12.542: ISAKMP: set new node 0 to QM_IDLE      Apr  1 14:48:12.542: insert sa successfully sa = 66DF4F5CApr  1 14:48:12.542: ISAKMP:(0):Can not start Aggressive mode, trying Main mode.Apr  1 14:48:12.542: ISAKMP:(0):found peer pre-shared key matching xxx.xxx.xxx.xxxApr  1 14:48:12.542: ISAKMP:(0): constructed NAT-T vendor-07 IDApr 

[URL]

View 2 Replies View Related

Cisco VPN :: 1803 ISR - Restrict Traffic Through EasyVPN Tunnels

Feb 16, 2011

We are using a 1803 ISR for remote vpn users. They use Cisco VPN clients with the EasyVPN server functionality of the ISR. I would like to restrict the ports/protocols which they can use to the remote network they connect to.
This is the (edited) client config in the ISR:
 
crypto isakmp client configuration group RemoteVPN key remoteaccess dns 192.168.0.1 domain domain.local pool POOL_1 acl 140 netmask 255.255.255.240,access-list 140 remark EasyVPN ACLaccess-list 140 permit ip 192.168.0.0 0.0.0.255 any
 
I tried to edit the acl 140 with access rules, but they do not seem to have any effect. If I edit acl 140 with deny ip any any, for example, the remote users can still use any protocol to access the remote network.

View 2 Replies View Related

Cisco VPN :: Multiple Site To Site IPSec Tunnels To One ASA5510

Dec 4, 2012

Question on ASA VPN tunnels. I have one ASA 5510 in our corporate office, I have two subnets in our corporate office that are configured in the ASA in a Object group. I have a site to site IPSEC tunnel already up and that has been working. I am trying to set up another site to site IPSEC tunnel to a different location that will need to be setup to access the same two subnets. I'm not sure if this can be setup or not, I think I had a problem with setting up two tunnels that were trying to connect to the same subnet but that was between the same two ASA's. Anyways the new tunnel to a new site is not coming up and I want to make sure it is not the subnet issue. The current working tunnel is between two ASA 5510's, the new tunnel we are trying to build is between the ASA and a Sonicwall firewall.

View 3 Replies View Related

Cisco WAN :: Unable To Upgrade ROMmon On 2801

Sep 7, 2011

I would like to upgrade rommon on my Cisco 2801 but this is what I get: [code]The router stops here and I am forced to power off and on again and the upgrade does not succeed.

View 10 Replies View Related

IPsec GRE Tunnel Versus Just Static Route?

Aug 14, 2012

i measured with Iperf over two Cisco 1811 router, that bandwidth speed is higher then is used IPsec+GRE tunnel between two routers, than just using a static routes.Bandwidth over GRE in average is about 91389Kbit/sec Over static routes is about 88474Kbit/sec.

View 1 Replies View Related

Cisco WAN :: 2801 Unable To Boot Image Wrong System Software

Feb 28, 2011

128 compact flash got corrupted and suddenly not working after i reboot the 2801 router. now i have a new 256 compact flash and 512 compact flash but i cannot still to boot the 2801 properly.  it always do looping like booting in rommon and  will be the image decompress but in the end theres an error, Wrong system software for this hardware.  ive tried different ios but still the same.
 
System Bootstrap, Version 12.3(8r)T9, RELEASE SOFTWARE (fc1)Technical Support: [URL] Copyright (c) 2004 by cisco Systems, Inc.PLD version 0x10GIO ASIC version 0x127c2801 processor with 262144 Kbytes of main memoryMain memory is configured to 64 bit mode with parity disabled
 
Readonly ROMMON initializedprogram load complete, entry point: 0x8000f000, size: 0xc100
 
Initializing ATA monitor library.......program load complete, entry point: 0x8000f000, size: 0xc100
 
Initializing ATA monitor library.......
 
program load complete, entry point: 0x8000f000, size: 0x2fae3d4Self decompressing the image : ##################################################################################################################################################################################[Code]....

View 1 Replies View Related







Copyrights 2005-15 www.BigResource.com, All rights reserved