Home | Site Map | How To | Windows Vista | Case Studies | Articles | Forums | Services | Donations | Careers | About Us | Contact Us|

Web ChicagoTech
 

 

VPN between ASA 5510 and NetVanta 2054 - Case Study

Situation: The client creates a site to site VPN between Cisco ASA5510 and NetVanta 2054, but it doesn't work. The links to check the ASA configuration and NetVanta 2054 configuration.  

Troubleshooting: 1. When using trace route 192.168.0.230 command in NetVanta 2054, it stops in 192.168.0.1.

2. From Cisco ASA, you can the remote WAN but not any private IP.\

3. debug crypto isa and debud crypto ipsec show that the ASA rejects any traffic from 192.168.11.x.

4. The below two lines cause the problem:

access-list Outside_cryptomap_20 extended permit ip 192.168.0.0 255.255.255.0 host 206.81.53.106

access-list Inside_nat0_outbound extended permit ip 192.168.0.0 255.255.255.0 host 206.81.53.106

Resolution: cleared the tunnel and then send an extended ping to a 192.168.11.1 host on the remote end like below.

access-list Inside_nat0_outbound extended permit ip 192.168.0.0 255.255.255.0 192.168.11.0 255.255.255.0

access-list Outside_cryptomap_20 extended permit ip 192.168.0.0 255.255.255.0 192.168.11.0 255.255.255.0

Related Topics

Cisco router firewall

Symptom: You are using Cisco VPN client to establish VPN connection on Cisco PIX. The PIX assigns ip 192.168.1.1 but you can't ping LAN ip like 10.0.0.10. ...
www.chicagotech.net/ciscorouter.htm

Cisco VPN client errors

Cisco VPN Client error - The remote peer is no longer responding ... You receive not connected when running Cisco VPN client ...
www.chicagotech.net/ciscoclienterrors.htm

VPN Issues

Q: I uses Cisco VPN client at home to access my company VPN. ... To setup VPN for MS VPN clients on Cisco PIX, you need to add the following lines. ...
www.chicagotech.net/vpn.htm

can't access remote computer with Cisco vpn

3. By default, Cisco VPN doesn't allow VPN clients access the internet. however, you can setup split tunnel. Bob Lin, MS-MVP, MCSE & CNE. Related Topics ...
www.chicagotech.net/Q&A/vpn10.htm

VPN Setup

What statements are required to allow a VPN inbound past my Cisco PIX? ... For example, to add DNS and WINS on a Cisco Firewall PIX, add vpdn group 1 client ...
www.chicagotech.net/vpnsetup.htm

 

 

 

  This web is provided "AS IS" with no warranties.
Copyright © 2002-2007 ChicagoTech.net, All rights reserved. Unauthorized reproduction forbidden.