IPSEC with Cisco ASA

Reply
Highlighted
Not applicable

IPSEC with Cisco ASA

Hello everyone.  I'm hoping someone may be able to help me out with this.  I am replacing Cisco ASAs with 5020s.  I have a lab 3050 setup and I have an IPSEC VPN tunnel between the 3050 and the Cisco ASA.  In my configuration, from the PA perspective, I have one local subnet and one remote subnet.  I can pass traffic back and forth with no problem.  I am now trying to configure from the PA one local subnet to two remote subnets.  My original subnet is able to pass traffic, but the new subnet will not communicate.  I added both subnets to the interesting traffic acl on the cisco side and I added a second set of proxy-ids on the IPSec Tunnel configuration on the PA side, I just can't seem to find any logs or any reason why I can't communicate with this second subnet.  I also made sure to set up the second remote subnet the same as the first, but I'm still not having any luck.  Any help would be much appreciated!

Dan

L6 Presenter

Re: IPSEC with Cisco ASA

Checked VR to confirm we have a static route to new subnet utilizing that tunnel interface?

L4 Transporter

Re: IPSEC with Cisco ASA

You made sure you've got your noNAT config set up on both sides of the tunnel correctly right? Usually that's the gotcha when traffic will mysteriously not pass across IPsec tunnels.

Not applicable

Re: IPSEC with Cisco ASA

As soon as I read your reply I knew that was the issue.  No NAT statement missing on the cisco side.  Thanks for the suggestion. 

L4 Transporter

Re: IPSEC with Cisco ASA

Glad I could help! Thanks for the 'correct answer' mark too :smileygrin:

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!