- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
05-08-2013 01:12 PM
Hello everyone. I'm hoping someone may be able to help me out with this. I am replacing Cisco ASAs with 5020s. I have a lab 3050 setup and I have an IPSEC VPN tunnel between the 3050 and the Cisco ASA. In my configuration, from the PA perspective, I have one local subnet and one remote subnet. I can pass traffic back and forth with no problem. I am now trying to configure from the PA one local subnet to two remote subnets. My original subnet is able to pass traffic, but the new subnet will not communicate. I added both subnets to the interesting traffic acl on the cisco side and I added a second set of proxy-ids on the IPSec Tunnel configuration on the PA side, I just can't seem to find any logs or any reason why I can't communicate with this second subnet. I also made sure to set up the second remote subnet the same as the first, but I'm still not having any luck. Any help would be much appreciated!
Dan
05-09-2013 06:36 AM
You made sure you've got your noNAT config set up on both sides of the tunnel correctly right? Usually that's the gotcha when traffic will mysteriously not pass across IPsec tunnels.
05-09-2013 06:25 AM
Checked VR to confirm we have a static route to new subnet utilizing that tunnel interface?
05-09-2013 06:36 AM
You made sure you've got your noNAT config set up on both sides of the tunnel correctly right? Usually that's the gotcha when traffic will mysteriously not pass across IPsec tunnels.
05-09-2013 06:48 AM
As soon as I read your reply I knew that was the issue. No NAT statement missing on the cisco side. Thanks for the suggestion.
05-09-2013 07:15 AM
Glad I could help! Thanks for the 'correct answer' mark too :smileygrin:
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!