Cisco VPN :: Site-to-site VPN Not Working Between ASA 5505 And 5510
			Apr 15, 2012
				I have an ASA 5505 and a 5510 that had a VPN connection working until the external ip address of the 5510 changed. I deleted the existing VPN connection on the 5505 and recrerated it with the new address of the 5510. I can see that the vpn lin is established, but the 5505 isn't transmitting any bytes. I looked in the Monitoring > VPN > VPN Statistics > Sessions and I see that the link is established and the bytes Rx is working, but the bytes Tx stays at 0 (this is on the 5505, on the 5510 there are no Bytes Rx, but there are bytes Tx). I don't think the problem is with the 5510, because that router has a vpn connection to another 5505 which is working fine.
 
config for the 5505 where the VPN isn't working: The VPN in question is the one with the ip address 207.229.xx.xx the other VPN (208.118.xx.xx is working, but is no longer needed) [code]
	
	View 1 Replies
  
    
	ADVERTISEMENT
    	
    	
        Apr 18, 2013
        I am not very experienced with Cisco networking. 
Here is the situation. 
 
Site A - headquarters 192.168.1.x 
Site B - remote office 192.168.20.x
Site C - remote office 192.168.30.x
 
Site A - ASA 5510
Site B - ASA 5505
Site C - ASA 5505
 
Site-to-site VPN is established and works between A and B, A and C. Users would like to establish a tunnel between B and C to work on a common project and the data is on Site B. 
 
I tried configuring the S2S VPN with pre-shared keys on both firewalls at sites B and C but in the end it is not established (I cannot ping either side). I used the Wizard interface multiple times and one time the CLI. I generally followed the settings chosen between the headquarter and the individual remote sites and tried to replicate them. Obviously I have made a mistake somewhere. 
 
Could there be any limitation on the ASA 5505 in terms of licensing and the number of S2S tunnels?
	View 7 Replies
    View Related
  
    
	
    	
    	
        Dec 12, 2011
        We have a Cisco ASA 5510 at our main office that makes connection with a 5505 at our other office using site to site VPN. (works)
 
Now for the question,
 
we want to access our other office from the main office but we wont want them to have access to our servers etc. so basically we want to control them but they shouldn't have the rights to control us. 
Is this possible with a site to site VPN? and how to do it.
	View 7 Replies
    View Related
  
    
	
    	
    	
        Sep 29, 2012
        I just try to build a Site-to-Site VPN over IPSec between a ASA5505 and a ASA5510. But it don`t want to work. Here are the config`s of the ASA 5505 and ASA5510:
 
ASA5505:
 
: Saved
: Written by enable_15 at 20:02:51.175 UTC Wed Apr 7 2010
!
ASA Version 7.2(2) 
!
hostname asa5505
enable password 8Ry2YjIyt7RRXU24 encrypted
names
	View 22 Replies
    View Related
  
    
	
    	
    	
        Nov 23, 2011
        I have a 5505 connected to 5510 via a site to site VPN, the vpn has 5 subnets on the acl list at both ends, but 2 of the subnets are assigned for remote access on the main 5510, which means the flow of traffic on these 2 subnets are main to remote, but the VPN only works if the traffic starts from remote to main.
 
both sides are set to bidirectional and I'm not sure if this is the case for all 5 subnets has remote site always sends data to the other 3 subnets first.
	View 7 Replies
    View Related
  
    
	
    	
    	
        Oct 11, 2011
        I have a network of 5 different ASA 5505 they are all connected via site to site VPNs. 4 of the routers are working fine but the 5th one is only connecting to 2 VPNs when it should be connecting to 4 VPNs. I have verified that all the settings are correct on the routers (peer ip address, PSK, etc...) but the router still only connects to 2 VPNs. Is this a licensing issue? The license of the router in question looks like this:  [code]
	View 1 Replies
    View Related
  
    
	
    	
    	
        May 11, 2011
        I'm experiencing troubles in setting up a simple site-to-site VPN between two new ASA 5505. I tried several times with the ASDM tool entering configuration manually or using the wizard, resetting every time to factory defaults, but the tunnel wont work.
	View 3 Replies
    View Related
  
    
	
    	
    	
        May 18, 2012
        I have a requirement to create a site to site vpn tunnel on ASA 5510 from a remote site to my HO, ihave already other site-to-site tunnels are up and running on the ASA.The issue is my remote site has got the network address which falls in one of the subnet used in HO(192.168.10.0/24).My requirement is only  My remote site need to accees couple of my servers in HO which is in 192.168.200.0/24 subnet.
	View 2 Replies
    View Related
  
    
	
    	
    	
        Oct 11, 2011
        cisco products and am struggling getting a VPN going between an ASA 5505 and 5510.  I have a VPN created (using the VPN wizward on both) and it shows the VPN is up, but I can't ping the remote site (from either side).
	View 11 Replies
    View Related
  
    
	
    	
    	
        Feb 7, 2011
        I have ASA 5505, i configured site to site vpn between central site and remote site and is working. Now the problem is we use remote site for troubleshooting purpose, so we need to create a tunnel from remote site to central site. I need to configure such a way that remote site can craete a tunnel to central site, but central site not able to create a tunnel, it just respond to remote site.
	View 3 Replies
    View Related
  
    
	
    	
    	
        Mar 6, 2011
        i have 2 router asa 5505 with base license i wanna make site to site vpn connection and remote site using vpn client to connect first i have hdsl router with 5 public ip i wanna try it by giving 1 public ip to each router and try the vpn but nothing work?
	View 1 Replies
    View Related
  
    
	
    	
    	
        Sep 12, 2011
        I configurated Ipsec vpn at asa 5510. my inside ip 192.168.10.156my public ip: 85.x.x.xmy peer ip : 62.x.x.x
 
the project is that:
the remote site want the interesting traffic like that:
source ip 172.16.1.104 can access destination ip 10.0.154.27
My inside ip is 192.168.10.0/0 and i can not to change it 172.16.1.0/24 and i can not to add this ip at my network.
	View 3 Replies
    View Related
  
    
	
    	
    	
        Mar 6, 2013
        Our Headquarter (asa 5510) is running a site to site vpn connection with a Branch office (router 2811). All remote users are accesing the internet through the VPN and also accesing headquarter file servers.I want to know if there is a way for some remote users to be able to use the vpn for accesing the file servers but to access the internet through the branch office.  The rest of the remote users will be still accessing the internet through VPN. 
	View 2 Replies
    View Related
  
    
	
    	
    	
        Apr 22, 2012
        I've setup a site to site vpn on an ASA 5510 using ASDM (as I have many times before) and the tunnel appears to be up but I am not able to pass traffic.  When I run the packet tracer from my inside network to the remote destination network, it shows that it is blocked by the implicit deny ip any any rule on my inside incoming access list.
	View 5 Replies
    View Related
  
    
	
    	
    	
        Jul 15, 2012
        we have two ASA 5510s one in 8.4(4) and one in 8.2(5) in a site-to-site VPN setup. All internal traffic is working smoothly.Site/Subnet A: 192.160.0.0 - local (8.4(4)) Site/Subnet B: 192.260.0.0 - remote (8.2(5)) VPN Users: 192.160.40.0 - assigned by ASA When you VPN into the network, all traffic hits Site A, and everything on subnet A is accessible.
Site B however, is completely inaccessible for VPN users. All machines on subnet B, the firewall itself, etc... is not reachable by ping or otherwise.There are also some weird NAT rules that I am not happy with that were created after I upgraded Site A ASA to 8.4
Site A internal: 192.160.x.x     External: 55.55.555.201(main)/202(mail)
Site B (over site-to-site) is 192.260.x.x     External: 66.66.666.54(all)
I pretty much just have the basic NAT rules for VPN, Email, Internet and the site-to-site.What do I need to add for the VPN to be able to access the site-to-site network?
Here is my NAT config:
nat (inside,Outside) source static DOMAIN_LOCAL DOMAIN_LOCAL destination static VPN_Network VPN_Network no-proxy-arp route-lookup
nat (inside,Outside) source static DOMAIN_LOCAL DOMAIN_LOCAL destination static DOMAIN_REMOTE DOMAIN_REMOTE no-proxy-arp route-lookup
!
object network DMZ_Network
 nat (DMZ,Outside) dynamic interface
object network DOMAIN_LOCAL
[code]....
	View 3 Replies
    View Related
  
    
	
    	
    	
        Jul 21, 2011
        I setup RA-VPN under local asa 5510 IP pool (192.168.127.0/24) and all was working fine. I got internet and local network access.
Then i have 5 site to site VPN working fine but when im traying to access to those L2L VPNs from the remote acces client im not able to do that. So after that i decided to obtain IP addresses from my DHCP server so i can obtain IPs from my local network (172.17.16.0/16) and then access normally to the VPN site to site. But the surprise was that the VPN cisco client is getting local IP address (172.17.16.222) perfectly but im not able to access even to my local network.
I have the same-security-traffic permit inter-interface  same-security-traffic permit intra-interface enable.
	View 6 Replies
    View Related
  
    
	
    	
    	
        Mar 9, 2011
        I am try to configure ASA 5510 with 8.3 IOS version.My internal users are 192.168.2.0/24 and i configured dynamic PAT and are all internet .
 i want configure identity NAT for remote access VPN.Remote users IP pool is 10.10.10.0 to 10.10.10.10
 
i know to configure NAT exemption in IOS 7.2 version. But here IOS 8.3 version. configure NAT exemption for 192.168.2.0/24 to my remote pool( 10.10.10.0 to 10.10.10.10).
	View 6 Replies
    View Related
  
    
	
    	
    	
        Apr 16, 2011
        I have a ASA 5510 actve/standby and create one site to site VPN with remote peer ip address xx.xx.xx.xx, Our VPN traffic running on 6 mb internet link for video conferancing traffic.Now client give another link 2 mb internet and client told to us our data traffic runnig on 2 mb link but this data traffic running on the same remote peer IP xx.xx.xx.xx.
 
Secondly request also they need failover over the ISP link.
 
how we immplement the same on ASA 5510.
	View 0 Replies
    View Related
  
    
	
    	
    	
        Oct 10, 2012
        I have a ASA 5510 at our corporate HQ that has one site to site VPN. I need to add 6 additional site to site VPN's to this ASA for our remote branches. How can I add them without affecting the existing site to site VPN?  The 6 site to site VPN's will all have the same settings however these settings are different from the existing site to site that I already have set up. How can I set it up so the 6 additional VPN's use their own crypto map and all use the same settings?
	View 1 Replies
    View Related
  
    
	
    	
    	
        May 28, 2012
        I have a ASA 5510 that has multiple site to site VPNs. I need to create an additiona site to site VPN but only allow 1 host to access and traverse the tunnel. The network is on a 192.168.5.x but the host that will need to access this tunnel needs to be on a 172.16.33.x network. I dont want any other traffic allowed to access or traverse the VPN tunnel for this host.  How can I set this up?
	View 33 Replies
    View Related
  
    
	
    	
    	
        Apr 30, 2013
        I have an ASA 5510 8.2(5) in Site1 and a ASA 5505 8.2(1) Site2 they are setup with a site to site tunnel.Each site has VPN clients that connect and I would like to allow clients from both sides access to servers on the other side of the site-to-site tunnel.
 
I enabled same-security-traffic permit intra-interface I also added the remote networks to access-list that is doing the split tunneling. [code]
	View 33 Replies
    View Related
  
    
	
    	
    	
        Feb 14, 2011
        I have a cisco ASA 5510 at the branch here. It terminates about 8 vpn tunnels and also it supports remote access clients. I just have a quick question. Can my remote sub-net group access the other remote access site-site VPN subnet group. If yes then how should i configure it.
	View 6 Replies
    View Related
  
    
	
    	
    	
        Sep 30, 2012
        I have a dynamic VPN site to site between ASA 5510 vs C880 with segment 172.23.191.0/25 for ASA side and some host in C880 side (e.g. 128.1.100.211, 128.1.115.181, 128.1.104.212) . The VPN is up, but only have communication with a host (128.1.115.181).
 
In the logs appears the next message when I try communication for all aother IP in the policy map configuration: IKE Initioator unable to find policy: Intf Inside, Src: 172.23.191.87, Dst: 128.1.115.182..ONLY WHEN I PINGING FROM SOME HOST IN C880 SIDE (e.g. 128.1.100.211) the communication is successfull.
What happen with this VPN, because I need to pinging from C880 IP host to ASA segment for establish communication?
	View 7 Replies
    View Related
  
    
	
    	
    	
        May 30, 2013
        I would like to know both Cisco 2901 or 2921 router and Cisco 5505 ASA can build site to site VPN.
 
1) what is the different to build site to site VPN between router and firewall ?
2) which is the best choice if using in site to site VPN connection ? 
	View 9 Replies
    View Related
  
    
	
    	
    	
        Nov 27, 2011
        We've just deployed a site-to-site VPN using a 5505 ASA on the client's site and a checkpoint Nokia FW on our site. Everything seems to be fine except that the user's connections to their file shares seem to be intermittently dropping. One minute the connection to the shares is there, next thing it's lost. There is no logic to it because no two users are experiencing issues at the same time, as a matter of fact even on the same PC where a user has access to 3 shares on 3 different servers, one could be showing as connected whereas the other two be dropping. [code]
 
As you can see the Duplex and Speed are set to auto, I've rectified this since then and I'm keeping a close eye on the output errors, and collisions. However, I'm afraid that this did not rectify the issue and the users are still experiencing intermittent connection dropping to their file shares over the VPN!
	View 1 Replies
    View Related
  
    
	
    	
    	
        Jul 28, 2011
        I have a request to establish a site to site VPN with a customer. While collecting the information I give them our local network subnet which is a private subnet (192.168.5.0). They asked me if I could give them a public address instead. They can not work with the 192.168.5 subnet. Is this possible?
 
My side of the VPN is an ASA 5505 running 8.2(2). The other side i believe is a Checkpoint.
	View 5 Replies
    View Related
  
    
	
    	
    	
        Aug 13, 2012
        Got an ASA5505 connected to another endpoint running IPsec and being NAT'd at each end to a 10.0.0.0/24 network. I can pass other types of traffic through the ASA 5505 but not RTP traffic. The moment it is NAT'd and hits the firewall rules it gets denied by the default deny at the bottom of the list.
Currently the rules are as follows
 
 Incoming External
allow ip any any
allow tcp any any
allow udp any any
default deny
 [code].....
 
It wont allow us to setup a voip call...however when the same call manager sets up a voip call NOT using this ipsec tunnel it works just fine.
	View 2 Replies
    View Related
  
    
	
    	
    	
        May 26, 2011
        I'm trying to figure out how to get two 5510 ASA's to establish a Site-to-Site VPN.The version with two static IP's is working perfectly and stable but I haven't figured out how to get a VPN running between a static and a dynamic IP
	View 12 Replies
    View Related
  
    
	
    	
    	
        Jun 28, 2012
        I am attempting to configure Radius authentication accross a site-to-site VPN for my ASA 5510-01 for remote access.
 
 ASA5510-1 currently has a live site to site to ASA5510-2. 
 
ASA 5510-1 - 10.192.0.253
 
ASA 5510-2 - 172.16.102.1
 
DC - 172.16.102.10
 
ASA5510-01 can ping the DC and vica versa but is unable to authticate when i perform a test. ASA5510-01 can authenticate to a DC on it;s own LAN but not on the remote LAN that DC sits on.
 
I have double checked the 'Server Secret Key' and ports as well as various users which all work locallly. ASA5510-02 authenticates to DC with no problems.
	View 3 Replies
    View Related
  
    
	
    	
    	
        Aug 14, 2012
        Got an ASA5505 connected to another endpoint running IPsec and being NAT'd at each end to a 10.0.0.0/24 network. I can pass other types of traffic through the ASA 5505 but not RTP traffic. The moment it is NAT'd and hits the firewall rules it gets denied by the default deny at the bottom of the list.
Currently the rules are as follows
Incoming External
allow ip any any
allow tcp any any
allow udp any any
default deny
[code]....
It wont allow us to setup a voip call...however when the same call manager sets up a voip call NOT using this ipsec tunnel it works just fine.
	View 3 Replies
    View Related
  
    
	
    	
    	
        Jan 16, 2013
        We have a client that has a Cisco 1801W Firewall that is setup as a site to site VPN terminating to a Cisco ASA 5505. The tunnel is up and established, I can ping from both sides of the tunnel.
 
The problem is the clients behind the Cisco ASA (192.168.2.x) cannot reach certain ports behind the Router (192.168.1.x). The main thing we're trying to do is browse via UNC path (ex: \192.168.1.120 from a 192.168.2.x machine).
 
I got 3389 working after I changed the - ip nat inside source static tcp 192.168.1.120 3389 y.y.x.x 3389 route-map DM_RMAP_1 extendable Modified the command to include the public IP instead of interface FastEthernet0
 
I believe it has something to do with the way NAT and route-maps are setup currently but I'm not familar enough with them to make the changes. I worked with Cisco to ensure the VPN tunnel was fine and it's something security related on the Router.
 
Here is the configuration (removed a few lines not necessary. y.y.x.x = WAN IP of Router x.x.y.y = WAN IP of ASA).
  
Building configuration...
  
Current configuration : 23648 bytes
!
version 12.4
no service pad
[Code].....
	View 1 Replies
    View Related
  
    
	
    	
    	
        Aug 8, 2011
        im drawing a blank trying to setup a site to site connection with a 5505 ASA using ipsec and isakmp.i have the pre shared key as well as the external address of the other end of the tunnel but do not remember what the commands are to setup the crypto map and isakmp.
	View 7 Replies
    View Related
  
    
	
    	
    	
        Apr 30, 2012
        Need to know the step by step procedure for monitoring site-to-site VPN tunnel (up/down) using SNMP on Cisco ASA 5505. 
	View 1 Replies
    View Related