Cisco VPN :: Getting IPSec Tunnel Established Between 887VA And SRP527W Router?
			Jul 22, 2012
				I'm having some problems getting an ipsec tunnel established between a cisco 887VA router and a cisco srp527w router.I am working from a few text books and some example materials. I have worked through many combinations of what I have got and am still struggling a little bit.I look at debug results and it appears as though the policies do not match between the devices:
 
Jul 23 05:44:37.759: ISAKMP (0): received packet from XXX.XXX.XXX.XXX dport 500 sport 500 Global (R) MM_NO_STATE
 broute1# 
Jul 23 05:44:57.079: ISAKMP:(0):purging SA., sa=85247558, delme=85247558
 broute1# 
Jul 23 05:45:17.031: ISAKMP (0): received packet from XXX.XXX.XXX.XXX dport 500 sport 500 Global (N) NEW SA
[code]....
Some specific questions:
 
1) on the SRP in the example's I have used (and I have a few SRP->SRP VPN's that work) I see you need to enter the preshared key, I'm not seeing in the examples I have used anything about the IKE preshared key on the IOS box. Any examples where you use the preshared key for IKE? I wonder if this is my primary issue as it states clearly in the log that there is no Preshared key :|
 
2) I have used a mish mash of names between the various sections as on the SRP the naming convention isnt the same; ie: which parts of the IPSEC negotiation come from the IKE policy section and which from the IPSEC policy section. Do the names really matter across different ends of the VPN?
 
3) I notice when I perform this command in the(config-crypto-map)#:
 
set peer FQDN
It is converted to:
set peer XXX.XXX.XXX.XXX
 
Is this expected? I want the device to look at the FQDN as this particular host is using DDNS and not use a static IP address. 
	
	View 4 Replies
  
    
	ADVERTISEMENT
    	
    	
        Aug 2, 2012
        I have a IPSec tunnel that is working in one direction. Below is the router config from the side that can connect to the other  side perfectly. I believe the issue is with this router as while I was  waiting on delivery for the ASA I had an SRP527W sitting in it's place  and had exactly the same problem.On one side I have a 887VA router and the other an ASA5505.The network behind the 887VA can access the remote site perfectly, backup services are traversing the link as are web interfaces for applications. In the other direction I can ping hosts but cannot connect. What else is interesting is if from the remote site I attempt to connect to a particular device that performs a port redirect the remote site browser gets so far as being redirected to port 5000 but then hangs.
 
I am seeing some very generic packet drop debug notices on the 887va on the NAT-ACL access list but I think this is as it should be as it is dropping the tunnel traffic from the NAT'ing.The config for the router is here, I will post the ASA config when I get to the other site shortly but I am convinced the issues is on this device, all the crypto configurations match.I have looked at the MTU's on each side, the path MTU on both sides is 1492. The asa does say the media MTU is 1500 but I believe that is the ADSL link so shouldnt matter?I even went so far as installing CCP and testing the VPN. It says the tunnel is up. It did state a failure:A ping with data size of this VPN interface MTU size and 'Do  not Fragment' bit set to the other end VPN device is failing. This may  happen if there is a lesser MTU network which drops the 'Do not  fragment' packets. [code]
	View 1 Replies
    View Related
  
    
	
    	
    	
        Aug 2, 2011
        I have now the sa`s stablished between SRP527w and cisco 857, but If i ping from a host of Cisco side to a host of SRP side I get  only rx traffic on the tunnel, the stats keep tx at 0 and ping is not answered.My tunnel is to send some voice call into IPSEC tunnel keeping DSCP bits, It comunicate SRP voice vlan with Cisco lan.
I have on SRP 2 vlans:
1 Vlan for data  on ports 1,2 and 4
1 voice vlan on ports 1,2,3,4.
 
I connect a netbook to port 3 and I can connect to internet but I cant reach by ping the other side of the tunnel?Maybe traffic from voice vlan is being natted with data vlan ip address?I need all traffic must go into the tunnel without being natted, on cisco side I have a policy to avoid nat but don know if SRP have any problem about it too.All gateways are ok ?
	View 2 Replies
    View Related
  
    
	
    	
    	
        May 12, 2013
        does a router Cisco 887 va k9 support EIGRP and IPsec ?
	View 2 Replies
    View Related
  
    
	
    	
    	
        May 2, 2012
        I have two 5510's that I am trying to get a tunnel established. One has an exsistinig tunnel to a 5505 that works but I cant get the next one to get past the first phase. I have sanitized the attached configs 
	View 5 Replies
    View Related
  
    
	
    	
    	
        Sep 23, 2012
        I'm in process of purchasing a new Cisco routers for our branches that will be used primary to enable IPSec virtual tunnel interfce with "tunnel mode ipsec ipv4". does the default IOS IP Base supports this feature? or i need to purchase DATA license or SECURITY license?
	View 4 Replies
    View Related
  
    
	
    	
    	
        Jan 20, 2013
        i successfully established site to site with 2 two ASA 5010. The problem is that traffic on not passing, This is current setup:1) Left side : only 1 private network 3) Right side : 1 private network, management network, 2 DMZ networks with public IP, On right ASA some netting is setup so servers in DMZ can be reached from private network. The goal would be that VPN client on left side can reach all resources on the right side (except management network, Just to get things going tunnel is built with only left and right private networks, but after tunnel is established i can't ping anything on other side.
	View 4 Replies
    View Related
  
    
	
    	
    	
        Apr 7, 2013
        I make a vpn site-to-site IPSEC tunnel between 2 RV110W  the above ,you will find the configuration
 
Site1 
Site 2
always the same message
	View 3 Replies
    View Related
  
    
	
    	
    	
        Sep 15, 2011
        I was hoping that the latest firmware would fix my (2) 'bugs', but it did not.  We are using the RV042s at our remote medical clinics as an end-point VPN router to our Nortel 1700 VPN router, replacing our old Nortel Contivity 100s.When I try and do a reset when connected remotely via the WAN interface, the RV042 hangs and will only reset by re-powering.
	View 1 Replies
    View Related
  
    
	
    	
    	
        Oct 27, 2012
        i have 2 RV048 and one RV016
 
I have established VPN gateway to gateway tunnels; all routers use functional DYNDNS
 
IPrange site 1  192.168.123.1-254 external adres x.y.z.w
IPrange site 2  192.168.124.1-254 external adres a.b.c.d
IPrange site 3  192.168.122.1-254 external adres e.f.g.h.i
 
site 1 with 192.168.123.x has two win 2008R2DC servers, running AD, DNS, DHCP, RRAS with  address 192.168.123.4-5 
 
i can ping the routers only if i add the route to it but cannot ping further  (route add command)
if i dont establish the route then nothing pings
 
How can i use the tunnel to connect to the servers in site 1 
	View 2 Replies
    View Related
  
    
	
    	
    	
        Oct 17, 2012
        I am using a Cisco RV110W (Firmware 1.2.09) in a branch and I would like to create a VPN Tunnel to another site that has a Cisco RV042 (firmware v4.2.1.02)
 
What would be the correct Configuration? the current configuration I am using is
 
in the RV042 i am using
 
Check Enable 
Local Group Setup
Local Security Gateway Type : IP Only
IP Address : RV042 Pulbic IP address 
[Code].....
	View 3 Replies
    View Related
  
    
	
    	
    	
        Jan 29, 2013
        We are using SRP527 routers with PPPoE ADSL connections. From the SRP527 we create an IPSec tunnel to our core routers (Cisco ASR). We are wanting to change the IPSec tunnels to L2TP, and I need to know if this can be done from the SRP527. I cannot find any L2TP configuration options in the setup options.Can the SRP527W act as an L2TP tunnel initiator over the ADSL PPPoE interface?
	View 1 Replies
    View Related
  
    
	
    	
    	
        Mar 3, 2011
        I have been struggling for a few days with getting site-to-site traffic working across a L2L IPSec tunnel.  At this point, I have the tunnel up, and I see packets being decrypted on the correct IPSec SA's when I ping from a local network computer on the ASA side to a local network computer on the router side.  I cannot ping from one side to the other, but those packets are getting through.  We have another L2L tunnel that is from that ASA to another remote site's ASA, and that is functional.  I have mirrored the configuration for ACLs, etc. from that site, so I believe that the issue is with the packets getting incorrectly translated by the NAT/NONAT statements/ACLs on the router side.
	View 8 Replies
    View Related
  
    
	
    	
    	
        Mar 2, 2011
        I have been struggling for a  few days with getting site-to-site traffic working across a L2L IPSec  tunnel.  At this point, I have the tunnel up, and I see packets being  decrypted on the correct IPSec SA's when I ping from a local network  computer on the ASA side to a local network computer on the router side.   I cannot ping from one side to the other, but those packets are  getting through.  We have another L2L tunnel that is from that ASA to  another remote site's ASA, and that is functional.  I have mirrored the  configuration for ACLs, etc. from that site, so I believe that the issue  is with the packets getting incorrectly translated by the NAT/NONAT  statements/ACLs on the router side. 
The ASA is: Cisco Adaptive Security Appliance Software Version 8.2(2)Hardware:   
ASA5520, 512 MB RAM, CPU Pentium 4 Celeron 2000 MHz The router is:Cisco IOS Software, 3800 Software (C3845-ADVENTERPRISEK9_SNA-M), Version 12.4(20)YA3, RELEASE SOFTWARE (fc2) Router Config:!version 12.4!card type t1 0 0!no ip cef!ip multicast-routing no ipv6 cef!crypto isakmp policy 10 encr 3des authentication pre-share group 2crypto isakmp key xxxxxxx address nn.nn.12.130!crypto ipsec security-association lifetime seconds 86400!crypto ipsec transform-set 3DES-SHA esp-3des esp-sha-hmac !crypto map NOLA 11 ipsec-isakmp  set peer nn.nn.12.130 set transform-set 3DES-SHA  set pfs group2 match address VPN-ACL!controller T1 0/0/0 fdl both cablelength long 0db channel-group 1 timeslots 1-24!interface Loopback0 ip address 1.1.1.1 255.255.255.252 ip virtual-reassembly no ip route-cache crypto map NOLA!interface GigabitEthernet0/0 no ip address duplex auto speed auto media-type rj45!interface 
[code]....
	View 15 Replies
    View Related
  
    
	
    	
    	
        Feb 23, 2011
        Successfull in setting up an L2TP/IPsec tunnel through NAT-T against a Windows 2008/ R2 RRAS server? I am using an 881 router and the layout is someting like this:Client -> 881 -> NAT -> internet -> Windows 2008 RRAS.The tunnel goes form the 881 to the Windows server (not from the client...).
	View 4 Replies
    View Related
  
    
	
    	
    	
        Mar 19, 2012
        how can you configure remote vpn ipsec tunnel on a Cisco 800 router?
	View 12 Replies
    View Related
  
    
	
    	
    	
        Aug 28, 2012
        I am configuring a vpn ipsec tunnel with cisco isr 2921 router and Watchguard edge 1250e. I have the watchguard configured so I just need to make sure I have everything setup on the cisco side. At this point, there is no communication as I am not sure if I configured it correctly. Should I do the crypto map on g 0/0 or dialer 1? 
 
aaa new-model
!
!
!
!
!
!
!
aaa session-id common
!
!
no ipv6 cef
[code]......
	View 4 Replies
    View Related
  
    
	
    	
    	
        Aug 30, 2012
        difference of CISCO887VA-K9 and CISCO887VA-SEC-K9.I thought it because of the Advanced Security and Advanced IP Licenses, but it isn't, I've got the -SEC- Version now just with the Advanced Security license. So I asking myself why I bought the more expensive CISCO887VA-SEC-K9 if I have to buy the additional Advanced IP Services licenses extra..
	View 14 Replies
    View Related
  
    
	
    	
    	
        Oct 19, 2011
        - Ipsec tunnell between two 881's
- An Aruba access point trying to set up a tunnell back to controller through the ipsec tunnell, on udp 4500
- Even though traffic shouldn't be NAT'ed (and other traffic is not), udp 4500 is NAT'ed
 
I guess this might be default behaviour, thing is that it used to work when it was set up as a route based easy vpn.
	View 1 Replies
    View Related
  
    
	
    	
    	
        May 4, 2011
        how to create ip sec tunnel using these parameters.  customer ip where tunnel has to be connected 1.1.1.1
ISAKMP Parameters:  (Phase I)
Encryption:                              AES-256 or 3DES
Authentication Mode:                          Pre-shared key
[Code]......
	View 4 Replies
    View Related
  
    
	
    	
    	
        Mar 9, 2011
         We have a Cisco 2820 that serves as a hub and our spokes are Cisco 871s.  Its been working for a while and for some reason last week.  Http and https traffic over the tunnel is having connection issues.  I can Remote desktop or PCanywhere into the remote PCs.  From that PC I can ping internal IP address or IP of the webmail server or internal webserver with no issue.  But if I access it over the browser it times out or it will work and stop working again.  Basically ica, icmp, pcanythere, rdp traffic works over the tunnel but not http or https.
	View 2 Replies
    View Related
  
    
	
    	
    	
        May 4, 2011
        can I force an IPSEC L2L tunnel to use NAT-T encapsulation no matter what? Automatic detection says none of the endpoints are behind NAT. I know I can disable it by the "crypto map XXX set nat-t-disable" command, but I want the exact opposite.
 
I have a very strange issue where asynchronos routing is making my life as a technician very hard.
 
A side question; Can I do something about an ISP that is policy-base-routing its ESP traffic (and/or translating it)?
 
ASA5505 ===>===>===> ISAKMP traffic ===>===>===> ASA5510
212.178.155.73                                                                 80.62.yyy.xxx (traffic source IP: 212.178.155.73)
[Code].....
	View 3 Replies
    View Related
  
    
	
    	
    	
        Aug 8, 2012
        i am curently troubleshooting a ipsec l2l VPN between
 
1. ASA 7.2(4) to SSG-140
2. Cisco 871W to SSG-140
 
In both scenario's the tunnel is nicely established, and traffic goes into the tunnel, but nothing comes out. All encap's, but no decap's                     
 
It seems like a routing issue, but we can not find anything on both sites. 
 
So maybe i m running into a (known) issue between cisco VPN equipment and the SSG-140? 
 
Could it be a proxy-id issue? Cause they configure stuff like 10.1.1.0/24 and i configure 10.1.1.0 0.0.0.255
	View 7 Replies
    View Related
  
    
	
    	
    	
        Mar 24, 2011
        I'm attempting to configure a tunnel on a PIX-501 version 6.3. It's an old device that's due to be replaced soon, but unfortunately we need a tunnel now... I have been using this document as a reference (6211): URL ,The remote end is a sonicwall.
 
The problem seems to be that the pix never sees the interesting traffic for the tunnel, and never tries to initiate a connection. I have enabled crypto ipsec and crypto isakmp debugs, but no data is ever displayed, even when attempting to access a device on the remote side of the tunnel! Someone had tried to set up this device with some tunnels in the past, but was never successful, so I'm thinking there might be remaining commands in the running-config causing problems.
	View 7 Replies
    View Related
  
    
	
    	
    	
        Oct 29, 2012
        configuring some static NAT entries on a remote site 887 router which also has a IPSec tunnel configured back to our main office. 
 
I have been asked to configure some mobile phone "boost" boxes, which will take a mobile phone and send the traffic over the Internet - this is required because of the poor signal at the branch.  These boxes connect via Ethernet to the local network and need a direct connection to the Internet and also certain UDP and TCP ports opening up.
 
There is only one local subnet on site and the ACL for the crypto map dictates that all traffic from this network to our head office go over the tunnel.  What I wanted to do was create another vlan, give this a different subnet.  Assign these mobile boost boxes DHCP reservations (there is no interface to them so they cannot be configured) and then allow them to break out to the Internet locally rather than send the traffic back to our head office and have to open up ports on our main ASA firewall.  
 
[URL]
 
So I went ahead and created a separate vlan and DHCP reservation and then also followed the guidelines outlined above about using a route-map to stop the traffic being sent down the tunnel and then configured static NAT statements for each of the four ports these boost boxes need to work.  I configure the ip nat inside/outside on the relevant ports (vlan 3 for inside, dialer 1 for outside) The configuration can be seen below for the NAT part;
 
! Denies vpn interesting traffic but permits all otherip access-list extended NAT-Trafficdeny ip 172.19.191.0 0.0.0.255 172.16.0.0 0.3.255.255deny ip 172.19.191.0 0.0.0.255 10.0.0.0 0.255.255.255deny ip 172.19.191.0 0.0.0.255 192.168.128.0 
[Code].....
	View 1 Replies
    View Related
  
    
	
    	
    	
        Nov 28, 2012
        since a few days I'm trying to solve a problem. I've successfully established an IPSec tunnel between two local LANs. In the main office I'm working with a ASA5510 CLI 8.4 and a static public IP address. The branches are using different Cisco 8xx routers and dynamic public IP address. The following picture shows the current configuration:As I mentioned an IPSec Tunnel between the main office "Intern"-LAN 192.168.1.0/24 and an outside LAN 10.10.0.0/24 is successfully established. Now there is a new intern "Admin"-LAN 192.168.2.0/24 at the main office. The users from the outside LAN 10.10.0.0/24 need the possibility to reach this new intern "Admin"-LAN.Can I simply route the traffic from 10.10.0.0/24 to 192.168.2.0/24 via the existing IPSec-Tunnel? Or need I a new IPSec tunnel between the outside 10.10.0.0/24 LAN and the new "Admin"-LAN 192.168.2.0/24?
	View 5 Replies
    View Related
  
    
	
    	
    	
        Aug 24, 2012
        I'm going to implement a S-2-S VPN IPSec connection between 2 locations and I've to NAT incomming and outgoing traffic.
	View 4 Replies
    View Related
  
    
	
    	
    	
        May 20, 2013
        I have an ASA5510 configuration that I'd like to add to.In this configuration there is a site to site IPSEC VPN tunnel to a remote location.It is tunneling a particular subnet for me and everything is working.In the remote subnet, there is an ASA 5525-x connected on the outside interface. Let's say for argument's sake, the outside IP is 210.0.0.1.On the Inside interface, i've configured 10.240.32.0/24 network.The only static route I have configured on the 5510 is the default gateway that goes to the ISP.I assumed that I have to add: route Outside 10.240.32.0 255.255.255.0 210.0.0.1 1.I did this, but i'm not able to reach the destination 10.240.32.0/24 network. I can't see anything hitting the 5525-x and the only thing I see on the 5510 is the building outbound ICMP and the teardown for the ICMP.
	View 6 Replies
    View Related
  
    
	
    	
    	
        Aug 22, 2011
        I´m getting a dynamic public IP from my provider and what I´m trying to do is to establish a remote vpn tunnnel using IPSec which I achieve but every time the sessions resets or the ASA 5505 resets I get a new public IP and I need to put the new IP on the remote client so I can establish the vpn... How can I establish an ipsec vpn  using DNS?  For this scenario the remote vpn client is a vpn phone but it could be for any vpn client. 
 
Private IP                       Public IP                                       Private IP
PBX ---- (LAN) ---- ASA 5505 ---( Internet ) --- Remote Site ( Router ) --- (LAN) -- VPN Phone
	View 3 Replies
    View Related
  
    
	
    	
    	
        May 7, 2012
        I have a site to site IPSec tunnel setup and operational but periodically the remote site goes down, because of a somewhat reliable internet connection. The only way to get the tunnel to re-establish is to go to the remote site and simply issue a ping from a workstation on the remote network. We were having this same issue with a Cisco PIX 506E but decided to upgrade the hardware and see if that resolve the issue. It ran for well over a year and our assumtions was that the issue was resolved. I was looking in the direction of the security-association lifetime but if we power cycle the unit, I would expect that it would kill the SA but even after power cycling, the VPN does not come up automatically.
	View 1 Replies
    View Related
  
    
	
    	
    	
        Nov 18, 2011
        I configured an IPSec VPN tunnel between two ASA 5505 firewalls. I would like to make sure that the IPSec tunnel (hence the security association) is permanent and do not drop due to idle condition.
	View 2 Replies
    View Related
  
    
	
    	
    	
        Jun 29, 2011
        I need to route traffic to DMZ (and internal) from the branch office thru the IPSec tunnel. How do I manage that with my Cisco 881?
	View 1 Replies
    View Related
  
    
	
    	
    	
        Mar 29, 2011
        I have running more the 30 VPN tunnels on my ASA5540 release 8.3(x).I want to disable one VPN tunnel(temporarily) without removing the configuration either Phase 1 or Phase 2.let me to know the command to disable IPSec VPN tunnel on CLI or ASDM.
	View 1 Replies
    View Related