• We've upgraded our forums. Please post any issues/requests in this thread.

vpn site-to-site issues with a cisco asa

Joined
Mar 31, 2007
Messages
1,895
Likes
162
Location
ontario canada
System Name home brew
Processor Intel Corei7 3770K OC @ 4.5Ghz
Motherboard ASUS P8Z77-V
Cooling Corsair H100
Memory 16GB DDR3 1600 GSKILL
Video Card(s) Powercolor Radeon 7970, MSI Radeon 7970
Storage Mushkin Chronos Deluxe 240gb. 2 TB Hdd.
Display(s) 3x24inch Dell Ultra IPS
Case CM storm trooper
Power Supply Antec Quattro OC ed. 1200w
Software Windows 7 Business x64
Benchmark Scores vantage: P43089
#26
It might be getting confused by the extended ACL you are using for the crypto map try using a regular ACL and apply that ACL to the outbound VLAN.
not a bad idea. but i do need to specify source and destination address. which you can only do source if i recall
 
Joined
Sep 1, 2009
Messages
860
Likes
117
Location
Manteca, Ca
System Name Rebirth
Processor Intel i5 2500k @4.5Ghz
Motherboard Asus P8P67 Pro
Cooling Megahalem 120x25 x2 GT AP-15 Push/Pull
Memory 2x4Gb Corsair Vengeance
Video Card(s) Sapphire HD7950 Vapor-X + MSI HD7950 TF3
Storage Samsung 840 Pro 120 SSD + Seagate 7200.12 1TB + 500gig WD + 3TB Hitachi
Display(s) X-Star Glossy DP2710
Case Antec 1200
Audio Device(s) Asus Xonar STX
Power Supply Antec CP-850
Software Microsoft Windows 8 Pro x64
#27
Yes on the interface that you wanted crypto map on then you are supposed to do the same on the other device, well thats the way ive ever known.
 
Joined
Mar 31, 2007
Messages
1,895
Likes
162
Location
ontario canada
System Name home brew
Processor Intel Corei7 3770K OC @ 4.5Ghz
Motherboard ASUS P8Z77-V
Cooling Corsair H100
Memory 16GB DDR3 1600 GSKILL
Video Card(s) Powercolor Radeon 7970, MSI Radeon 7970
Storage Mushkin Chronos Deluxe 240gb. 2 TB Hdd.
Display(s) 3x24inch Dell Ultra IPS
Case CM storm trooper
Power Supply Antec Quattro OC ed. 1200w
Software Windows 7 Business x64
Benchmark Scores vantage: P43089
#28
It might be getting confused by the extended ACL you are using for the crypto map try using a regular ACL and apply that ACL to the outbound VLAN.
HAH. just entered a standard ACL. And when i tried to match the crypto map to it, says access-list should be of type extended.
 
Joined
Mar 31, 2007
Messages
1,895
Likes
162
Location
ontario canada
System Name home brew
Processor Intel Corei7 3770K OC @ 4.5Ghz
Motherboard ASUS P8Z77-V
Cooling Corsair H100
Memory 16GB DDR3 1600 GSKILL
Video Card(s) Powercolor Radeon 7970, MSI Radeon 7970
Storage Mushkin Chronos Deluxe 240gb. 2 TB Hdd.
Display(s) 3x24inch Dell Ultra IPS
Case CM storm trooper
Power Supply Antec Quattro OC ed. 1200w
Software Windows 7 Business x64
Benchmark Scores vantage: P43089
#29
:banghead: ugh!!!. I changed the acl from outbound_tunnel to a number 101. AND IT WORKED!!!!!!!. I could connect and everything. So to solve the original problem i tried power cycling WITHOUT SAVING THE CONFIG. So i set it to a numbered ACL, but it still wont establish. Just says received encrypted packet with no matching SA, dropping.
 
Joined
Sep 1, 2009
Messages
860
Likes
117
Location
Manteca, Ca
System Name Rebirth
Processor Intel i5 2500k @4.5Ghz
Motherboard Asus P8P67 Pro
Cooling Megahalem 120x25 x2 GT AP-15 Push/Pull
Memory 2x4Gb Corsair Vengeance
Video Card(s) Sapphire HD7950 Vapor-X + MSI HD7950 TF3
Storage Samsung 840 Pro 120 SSD + Seagate 7200.12 1TB + 500gig WD + 3TB Hitachi
Display(s) X-Star Glossy DP2710
Case Antec 1200
Audio Device(s) Asus Xonar STX
Power Supply Antec CP-850
Software Microsoft Windows 8 Pro x64
#30
Sounds like the cisco ios is being picky in the extended ACLs
 
Joined
Mar 31, 2007
Messages
1,895
Likes
162
Location
ontario canada
System Name home brew
Processor Intel Corei7 3770K OC @ 4.5Ghz
Motherboard ASUS P8Z77-V
Cooling Corsair H100
Memory 16GB DDR3 1600 GSKILL
Video Card(s) Powercolor Radeon 7970, MSI Radeon 7970
Storage Mushkin Chronos Deluxe 240gb. 2 TB Hdd.
Display(s) 3x24inch Dell Ultra IPS
Case CM storm trooper
Power Supply Antec Quattro OC ed. 1200w
Software Windows 7 Business x64
Benchmark Scores vantage: P43089
#31
Yeah definately, i'd go as far to say thats a bug. The guides i followed, some used a number, others had a name. Just didnt think much of it, searching on the cisco support forums i found a suggestion for that.