IPSEC with Cisco ASA

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

IPSEC with Cisco ASA

Not applicable

Hello everyone.  I'm hoping someone may be able to help me out with this.  I am replacing Cisco ASAs with 5020s.  I have a lab 3050 setup and I have an IPSEC VPN tunnel between the 3050 and the Cisco ASA.  In my configuration, from the PA perspective, I have one local subnet and one remote subnet.  I can pass traffic back and forth with no problem.  I am now trying to configure from the PA one local subnet to two remote subnets.  My original subnet is able to pass traffic, but the new subnet will not communicate.  I added both subnets to the interesting traffic acl on the cisco side and I added a second set of proxy-ids on the IPSec Tunnel configuration on the PA side, I just can't seem to find any logs or any reason why I can't communicate with this second subnet.  I also made sure to set up the second remote subnet the same as the first, but I'm still not having any luck.  Any help would be much appreciated!

Dan

1 accepted solution

Accepted Solutions

L4 Transporter

You made sure you've got your noNAT config set up on both sides of the tunnel correctly right? Usually that's the gotcha when traffic will mysteriously not pass across IPsec tunnels.

View solution in original post

4 REPLIES 4

L6 Presenter

Checked VR to confirm we have a static route to new subnet utilizing that tunnel interface?

L4 Transporter

You made sure you've got your noNAT config set up on both sides of the tunnel correctly right? Usually that's the gotcha when traffic will mysteriously not pass across IPsec tunnels.

As soon as I read your reply I knew that was the issue.  No NAT statement missing on the cisco side.  Thanks for the suggestion. 

Glad I could help! Thanks for the 'correct answer' mark too :smileygrin:

  • 1 accepted solution
  • 5335 Views
  • 4 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!