Site to Site VPN issues between PIX506 and ASA5505

Hello all, I have a PIX506 running 635, and an ASA5505 running 722. The PIX is at corporate and is setup for remote vpn access. The remote user VPN is working. I have also attempted to do a site to site vpn to the ASA, but its not working correctly. I feel like I am missing something, but I can't figure it out. Your help would be greatly appreciated. Sanitized relevant config is below
Corporate
PIX Version 6.3(5)
access-list split_tunnel permit ip 192.168.119.0 255.255.255.0 10.20.20.0 255.255.255.0
access-list nonat permit ip 192.168.119.0 255.255.255.0 10.20.20.0 255.255.255.0
access-list nonat permit ip 192.168.119.0 255.255.255.0 172.16.2.0 255.255.255.0
access-list outside_cryptomap_20 permit ip 192.168.119.0 255.255.255.0 172.16.2.0 255.255.255.0
ip address outside xxx.yyy.170.160 255.255.255.0
ip address inside 192.168.119.1 255.255.255.0
global (outside) 1 interface
nat (inside) 0 access-list nonat
sysopt connection permit-ipsec
crypto ipsec transform-set ESP-AES-256-SHA esp-aes-256 esp-sha-hmac
crypto ipsec transform-set ESP-3DES-SHA esp-3des esp-sha-hmac
crypto dynamic-map dynmap 10 set transform-set ESP-AES-256-SHA
crypto map mymap 20 ipsec-isakmp
crypto map mymap 20 match address outside_cryptomap_20
crypto map mymap 20 set pfs group2
crypto map mymap 20 set peer aaa.bbb.175.218
crypto map mymap 20 set transform-set ESP-3DES-SHA
crypto map mymap 65535 ipsec-isakmp dynamic dynmap
crypto map mymap client authentication w2k3
crypto map mymap interface outside
isakmp enable outside
isakmp key ******** address aaa.bbb.175.218 netmask 255.255.255.255 no-xauth no-config-mode
isakmp identity address
isakmp keepalive 10
isakmp nat-traversal 10
isakmp policy 10 authentication pre-share
isakmp policy 10 encryption 3des
isakmp policy 10 hash sha
isakmp policy 10 group 2
isakmp policy 10 lifetime 86400
isakmp policy 30 authentication pre-share
isakmp policy 30 encryption aes-256
isakmp policy 30 hash sha
isakmp policy 30 group 5
isakmp policy 30 lifetime 86400
vpngroup vpners address-pool ippool
vpngroup vpners dns-server 192.168.119.11
vpngroup vpners default-domain mydomain.local
vpngroup vpners split-tunnel split_tunnel
vpngroup vpners idle-time 1800
vpngroup vpners password ********
Remote Site
ASA Version 7.2(2)
interface Vlan1
nameif inside
security-level 100
ip address 172.16.2.1 255.255.0.0
interface Vlan2
nameif outside
security-level 0
ip address aaa.bbb.175.218 255.255.128.0
access-list outside_20_cryptomap extended permit ip 172.16.2.0 255.255.255.0 192.168.119.0 255.255.255.0
access-list inside_nat0_outbound extended permit ip 172.16.2.0 255.255.255.0 192.168.119.0 255.255.255.0
global (outside) 1 interface
nat (inside) 0 access-list inside_nat0_outbound
crypto ipsec transform-set ESP-3DES-SHA esp-3des esp-sha-hmac
crypto map outside_map 20 match address outside_20_cryptomap
crypto map outside_map 20 set pfs
crypto map outside_map 20 set peer xxx.yyy.170.160
crypto map outside_map 20 set transform-set ESP-3DES-SHA
crypto map outside_map interface outside
crypto isakmp enable outside
crypto isakmp policy 10
authentication pre-share
encryption aes-256
hash sha
group 5
lifetime 86400
tunnel-group xxx.yyy.170.160 type ipsec-l2l
tunnel-group xxx.yyy.170.160 ipsec-attributes
pre-shared-key *

I just figured it out. I did not issue the sysopt connection permit-ipsec on the ASA5505. Issuing that command made it work.

Similar Messages

  • Issue with VPN compatibility between 2811 and 2911

         hello
    I would like to ask anyone have had any issues with setting up a VPN tunnel between 2811 and 2911?
    The IPSec VPN is established but for some reason I cannot ping the LAN side to the other LAN side of the other end of the VPN Router?
    Any experience would be much appreciated
    Thanks           

    IPSec VPN can be with no problem set up between any cisco routers (and not nesesserely cisco),  so there are should be no issues in your case.
    If you say that tunnel is established successfully, then problem most probably related to routing issues between sites or incorrect crypto-acl configured. Check if hosts on both sites have correct routing information on how to get to subnets on the other site.
    To make more accurate assumptions it would help if you provide config on both sites and describe your topology.

  • Why can't I use WebCT chat with my computer?  I get the 'spiral of death' every time I try to type in my chat.  I have a feeling it has to do with compatibility issues between Java and Tiger.

    Why can't I use WebCT chat with my computer?  I get the 'spiral of death' every time I try to type in my chat.  I have a feeling it has to do with compatibility issues between Java and Tiger.

    Hi Elizabeth,
    Do your Mac meet any of these requirements?
    http://www.wvnet.edu/services/webct/requirements.html
    From this it appears to be PC only!???
    http://sourceforge.net/projects/awebctcclient/files/Pancake%20%28it%20own%20proj ect%20now%29/Pancake%20Console%20V1.0.0/PancakeConsole-1.0.0-src.zip/download
    Can you provide any more info on which bersion or file you have?
    Can you tell us why you need this for your use?

  • Compatibility issues between R12 and report builder 2.5

    Hi,
    I just want to know if there are issues between R12 and (Forms 4.5 and Reports 2.5)? I have been using 6i since I started in the oracle so I'm a little new to this.
    Thanks
    peopsquik

    As my understanding there is no issue for Forms 4.5 and Reports 2.5 with R12.
    You can develop report with Report 6i can be deployed with R12.You cannot use Forms 4.5, Reports 2.5 or Developer (Forms/Reports) 6i with Oracle EBs R12 as it is not certified. The only supported version is Developer 10g
    Using the OracleAS 10.1.2 Forms and Reports Builders with Oracle Applications Release 12 [ID 444248.1]
    Thanks,
    Hussein

  • White space issues between content and footer.

    I am having white space/page length issue between the end of my content and the footer.
    I have read the forums and tried changing the page length minium height to 800 and then I
    unchecked the sticky footer in page properties on both the master page and the content page itself.
    Here's a link to one of my pages.  http://www.ueonline.com/rohs-info.html
    This page has very little content and you can see the white space.
    Any help is appreciated.

    This may be a little dated for a reply, and I'm not 100% sure your issue is the same as mine, but I discovered that unchecking the sticky footer option in site properties solved the problem. I should note that the website I was building for a client was über simple, and while disabling that function solved the headache in my own project, it may incur unwanted results in others, depending on the complexity.
    DTA

  • Alignment Issues between dreamweaver and browser

    Hi
    Hoping someone can help, i'm trying to learn how to make
    better sites with advanced tools like apDIV's but seem to be
    running into an alignment issue. When I make the html file in
    dreamweaver I seem to have to off set the images and div tags
    inorder for the site to show up aligned properly in firefox,
    explorer, etc. I'm thinking there might be a problem in the actual
    code causing this but am not good enough yet to find it or the
    problem, any ideas or guidence would be greatly accepted. below if
    the links work is the difference I see between dreamweaver and when
    its launched in a browser.
    DreamweaverScreen
    BrowserScreen

    > over a centered frame
    You are not using frames - that's a table.
    Yes - there's a way to do this, but it will involve your
    working in code.
    Make your page left aligned by removing any centering.
    Then position your layer so that it is properly located over
    the table.
    Change this -
    </head>
    to this -
    <style type="text/css">
    #wrapper { width:760px; margin:0 auto;position:relative; }
    /* 760px will display on an 800px screen maximized browser
    window without */
    /* horizontal scrollbars. */
    </style>
    </head>
    (you may need to adjust this width so that it's consistent
    with the width of
    your centering table)
    change this -
    <body ...>
    (the ellipsis represents any other attributes that might be
    mentioned in the
    body tag, and SHOULD NOT BE INCLUDED EXPLICITLY!)
    to this -
    <body ...>
    <div id="wrapper">
    and this -
    </body>
    to this -
    <!-- /wrapper -->
    </div>
    </body>
    and see if that helps.
    Murray --- ICQ 71997575
    Adobe Community Expert
    (If you *MUST* email me, don't LAUGH when you do so!)
    ==================
    http://www.projectseven.com/go
    - DW FAQs, Tutorials & Resources
    http://www.dwfaq.com - DW FAQs,
    Tutorials & Resources
    ==================
    "Vinx21" <[email protected]> wrote in
    message
    news:ge9t3e$92s$[email protected]..
    > thanks for the help osgood, I see now what my problem is
    and am just
    > wondered
    > if there was a way to place the absolute layer over top,
    in the right
    > position,
    or will have i have to remake one of the elements a
    > different way???
    >
    > thanks again, dave
    >

  • VPN connection between ASA5520 and RV215w

    Hello everyone,
    I am trying to setup a vpn connection between ASA5520 with 9.1.(3) and rv215w 1.1.0.6
    Here is my setup ...
    But the vpn connection fails with an error message on ASA.
    RV215w shows ipsec established but i cannot ping the network behind.
    You can find asa-config and show-tech as attachment. I have added also some screenshots from RV215w.
    Any hint or help is appreciated.
    Cengiz

    Hi Cengiz,
    Dynamic CRYPTO maps mostly used in a Remote Access or Client to site VPN because end users working from home can have IP address new every time or like different whcn connect from home or from Internet cafe , hence ASA cant make a fix IP as Peer.
    But for site to site also Dynamic Crypto Map can be used but only at one side , else if you use Dynamic crypto map at both ends , both peer will wait for each other to initiate a tunnel Request as the device n this case ASA) configured with Dynamic Crypto map can only REPLY for a tunnel initiation , it can never send tunned initilaization request as it never know the IP address of the peer. Hence never make both device as dynamic crypto map or else they both never initiate and wait for each pther and tunnel will never happen.
    The main steps to be configured on the ASA end in order to establish dynamic tunnel:
        Phase 1 ISAKMP related configuration
        Nat exemption configuration
        Dynamic crypto map configuration
    The Cisco IOS router has a static crypto map configured because the ASA is assumed to have a static public IP address. Now this is the list of main steps to be configured on the Cisco IOS Router end to establish dynamic IPSEC tunnel.
        Phase 1 ISAKMP related configuration
        Static crypto map related configuration
    !---1. Configure the IPsec transform-set
    crypto ipsec transform-set myset esp-des esp-md5-hmac
    !--- 2. Configure the dynamic crypto map. Always rememeber to bind a dynamic crypto map to a blank static crypto map and then call that static crypto map to a ASA OUTSIDE Interface as Dynamic Crypto maps cannot be bind directly to ASA OUTSIDE Interface or say any interface.
    crypto dynamic-map MY_DYNAMIC_MAP 1 set transform-set myset
    crypto dynamic-map MY_DYNAMIC_MAP 1 set reverse-route
    !--- Enable Reverse Route Injection (RRI), which allows the ASA
    !--- to learn routing information for connected clients hence the static route will come above defaut route and hence
    !... will make the routing decision fast else every time for the other side router dynamic IP , default route have to get a hit but only after checking the entire routing table and when no match then use default route , so to save this entire route matchin process always good to use reverse route enjection so that other side non dynamic crypt peer can insert a static route enrty in ASA.
    !--- 2A. Always Bind dynamic crypto map named MY_DYNAMIC_MAP to a static crypto map named STATIC_MAP_CALLING_DYMANIC_MAP using a keyword dynamic in the last 
    crypto map STATIC_MAP_CALLING_DYMANIC_MAP 10 IPSec-isakmp dynamic MY_DYNAMIC_MAP
    !--- 2B.now apply static map on ASA OUTSIDE Interface
    crypto map STATIC_MAP_CALLING_DYMANIC_MAP interface outside
    !--- 3. Configure the phase I ISAKMP policy
    crypto isakmp policy 10
    authentication pre-share
    encryption des
    hash md5
    group 2
    lifetime 86400
    !--- 4. Configure the default L2L tunnel group parameters
    tunnel-group DefaultL2LGroup IPSec-attributes
    pre-shared-key *
    Plase rate if you like my post.
    Best Regards
    Sachin Garg

  • Sync issues between Mac and Mobile Me

    Hi all,
    I'm having issues syncing between MobileMe and my Macbook Pro. It used to work perfectly, but I haven't been able to get it to sync since early August. All the changes I make between my iPhone and MobileMe work fine, but they just wont update with any changes I make on my Macbook. Equally, changes made on iPhone or MobileMe don't show on my laptop anymore.
    I've tried force syncs and resetting sync data (and transferring info from MobileMe) but none work. Is there anything else I can try?
    Thanks,

    You should ask in the MobileMe forums as this forum (iSync) has nothing to do with syncing Macs to MobileMe.

  • Curious... Syncing Issues Between iPhone and iTunes?

    Just curious... the past several months I have noted various concerns around "syncing" between iPhone and iTunes... yet don't recall any mention of whether it occurs between MAC OS or WIN hardware (desktops and or laptops). Furthermore, I am interested if anyone can comment whether these sync issues occurs mostly on TIGER or LEOPARD OS when accessing iTUNES. (Guess I should pay more attention to the noted OS field.
    I ask because I am considering an upgrade to LEOPARD by end of month and don't want to jeopardize my syncing to my iPhone if it is a LEOPARD related issue. Thank you

    I'm running Leopard and I've never experienced any sync issues.
    These discussions include mostly problems, which is what these discussions are for - a user to user support forum for technical support issues and questions.
    Which particular issue are you referring to?
    Before installing a major OS X upgrade such as Leopard over a previous OS X version, it is a good idea to create or update your existing backup of important data stored on your computer's hard drive - including your iTunes library, photos, contact info, calendar events, documents, etc. I've never experienced any problems installing a major OS X upgrade over a previous OS X version, but I always update my computer's backup immediately beforehand to be on the safe side.

  • A big issue between LR2 and PSE6?

    Hello;
    Im experiencing a strange situation between PSE6 and LR2. What about to tell you it happens to me twice, so I was able to recreate and document the issue. Before I go on I want to warn you that the only way to fix it was uninstalling and installing PSE6. The repair process did not work.
    Before I describe and specify the Test Script I want to describe my system:
    Vista Home Premium SP1, PSE6 and the 30 day trial of LR2.
    Processor: Dual 2.89 MHz, 4GB of RAM, 512MB ATI Graphic Card
    2 Internal HD; 250 GB and 650 GB
    1 External HD 500GB.
    Description: After I edited a RAW picture in PSE and saved as PSD I closed PSE6 and went to LR2 to continue editing, then after some editing in LR2 I decide to do more editing in PSE6 from LR2. I closed PSE6 and get back to LR2. I opened PSE6 from the Desktop and went to the Organizer-Edit-Preferences and BOOM; I get the message Adobe Photoshop Elements 6.0 (Organizer) has stopped working CLOSE THE PROGRAM.
    Test Script:
    WARNING: If you decide to go on and test this I want to warn you that both times I had to uninstall and install PSE6.
    1. Edit a RAW picture in PSE6 and saved as PSD, exit PSE6.
    2. Edit the same PSD picture in LR2, do anything you want.
    3. Edit the PSD picture in PSE6 directly from LR2: Develop->Photo->Edit in PSE6.
    4. Chose the Default Option: Edit a Copy with Lightroom Adjustments
    5. When in PSE6 do anything or nothing to the picture and CLOSE exit from PSE6.
    6. Start PSE6 and from the Organizer go to EDIT->Preferences and chose General
    7. Now, if the problem its repeatable and its not only me you should get the message that the Organizer has Stopped working and you must have to close the program.
    Organizer has Stopped working and you must have to close the program.
    8. Since everytime that I tried to get into the Preferences PSE6 Crash I had to unistalled and installed again, I try to do the repair but in my case did not work.
    Note: I don't know if the same it's going to happen with JPG's or TIFF's, at least I don't want to test it.
    If somebody has any comments or knowledge about this please let me know. For now my Trial of LR2 has come to a stop.
    Thanks in advance.

    Hello Antonio;
    After many, many test I discovered that the problem, at least in my case it is caused by the new ACR 4.5. Please read the Thread that I post under Camera Raw. I include the link below.
    I also open two Bug Reports about this, but as usual Adobe (and other Software Companies) will never take responsability for this, until one day they release a new version with "enhancements".
    PSE6 Organizer Crash with ACR 4.5 (Vista Only?)
    http://www.adobeforums.com/webx/.3bb6a869.59b60d3e

  • Data type conversion issues between Oracle and SQL Server

    Hi there, I am using Heterogeneous Services to insert into a SQL Server database. I am running into an issue between data types regarding Oracle's VARCHAR2 and trying to insert that into a SQL Server MONEY data type. I tried using the TO_NUMBER() function to convert my VARCHAR2 to a number, but that didn't seem to help.
    Does anyone have any advice on how to work around this??
    Thanks for any help,
    ivalum21

    ORA-02047: cannot join the distributed transaction in progress
    ORA-06512: at "MY_PACKAGE_NAME", line 263
    ORA-28500: connection from ORACLE to a non-Oracle system returned this message:
    [Generic Connectivity Using ODBC]DRV_Execute: DB_ODBC_ENGINE (1645): ;
    [Microsoft][ODBC SQL Server Driver][SQL Server]Disallowed implicit conversion
    from data type varchar to data type money, table 'tableA',
    column 'total_amount'. Use the CONVERT function to run this query. (SQL
    State: 37000; SQL Code: 260)
    ORA-02063: preceding 2 lines from SQLSERVER_LINK
    ORA-06512: at "RCDTPUMP.CAMPUSCALL_DATAPUMP_UNI", line 875
    ORA-06512: at "RCDTPUMP.CAMPUSCALL_DATAPUMP_UNI", line 791
    ORA-06512: at "RCDTPUMP.CAMPUSCALL_DATAPUMP_UNI", line 1156
    ORA-06512: at line 1
    That is what I get when I take out the TO_NUMBER()
    Message was edited by:
    ivalum21

  • TE tunnel issues between IOS and IOS-XR

    Hi Guys
    I have a situation. The scenario (see the attached diagram) has to PE01 (IOS) connecting via a port-channel to P01 (IOS-XR), turn P01 connect to PE02 (IOS-XR). So we've configured a pseudowire between PE01 and PE02, this works fine! then we've configured a TE tunnel between PE01 and PE02, but when we chose the TE tunnel as preferred path for the PW, happens the following:
    PC-A mac address appears on PE02 mac address table, however PC-B mac address doesn't appears on PE01 mac address table, so there is not connectivity between PC's at all.
    It seems like the TE tunnel is causing some issue (thought TE tunnel status is okay at all), and the problem seems to be between PE01 and P01, when we take the TE tunnel from the PW preferred path, everything works fine! I'm not sure if this problem is caused by the port-channel too.
    I've been looking for some software bugs in IOS 12.2(33)SRE6 and IOS-XR 4.3.1 but there is not such.
    Anyone of you had this problem as well?
    Marcelo

    Hello.
    Did you try ping inside vc between PE devices?
    Could you provide relevant configuration from PE1,P,PE2 routers?
    And the output you got during troubleshooting?

  • Is there an issue between EXSP24mkII and MOTU Symphonic Instrument?

    I'm using Logic Express 7.2 for three large projects right now. Admittedly I'm pretty new to LE 7.2, since just recently switching over from Digital Performer.
    So, far, LE has been very stable -- UNTIL last week when I loaded in MOTU's Symphonic Instrument. Now, if I have just one or two tracks of Symphonic instrument and nothing else, I'm fine, but if I start adding tracks that have different virtual instruments on them -- say, 2 tracks of Symphonic Instrument and 2 tracks of EXSP24 mkII, then I get frequent crashes.
    The crashes occur as I record my first take on the first new track.
    I can't seem to nail down a particular sequence of events yet, although I think I might be getting pretty close to figuring it out.
    However, before I put in all the effort to figure out the bug, do you know if it's already been discovered? Are there known issues between Symphonic Instrument and Logic or MacIntels, or something?
    Thanks!

    I do have the latest version -- the one that's compatible with the MacIntels. And, when it's the only plug-in, it works great.
    Well, maybe not quite as great as EXSP24mkII, but pretty good. There are still some wierd clicks that happen during playback occasionally, but, VERY fortunately, don't happen when I bounce the tracks down.
    It doesn't seem like there's a known issue, so I'll see if I can isolate a series of actions that cause the problem. If I can nail it down, I'll let you all know.

  • DB Link issue between 8i and 11g

    Hi, We have developed the shell script to connect oracle 11g database and do something and then update the oracle 8i database tables using the DB link. We have created the Public DB link in Oracle 11g database.
    When we execute the script manually everything works fine. But while executing the same script using the LINUX - crontab the script failed to execute the DB link and throws the below error message
    Error Message:
    =========
    ORA-12154: TNS:could not resolve the connect identifier specified Error loading the files
    Anyone come accross this error before? please help
    Thanks in advance

    user4883361 wrote:
    Hi sb92075:
    How about Easysoft ODBC-Oracle Driver?
    http://www.easysoft.com/products/data_access/odbc_oracle_driver/index.html
    does this driver will permit me to create a DB link between 11g and 8i?
    Thanks
    Since it is not possible to prove a negative, you are left with the challenge to prove me wrong.
    If you can make it work, then I was incorrect.
    Please post your conclusion here, after you determine the answer to your question.

  • Differences between SR520 and ASA5505?

    Q: What is the feature parity and differences between SR520 Security Router and ASA5505?
    A: [Addis Hallmark]: The SR520 is a secure router that is made for SBCS deployments. It's interfaces, dynamic routing capabilities, CCA support, etc make it a great fit for many customers. The SR520 is much more commonly compared against 87x platforms. The ASA5505 is a security appliance (and a very good one).
    [Luke Lambert]: Basically in order of capabilities (IMHO):
    UC500 - If you want a basic entry level firewall
    SR520 - If your a small office but want some advanced firewall functions e.g. SSL VPN, DMZ, IPS
    ASA - High performance required, large amount of remote users, advanced features/ monitoring required.
    Reasons for ISR (SR520):- Basic FW
    - One device does it all e.g. Need to terminate ADSL w/ Security in one box.
    Reasons for ASA
    - More advanced firewall
    - Ease of configuration of advanced features
    - Better scaling with VPN (more users)
    - Better SSL (Clientless) VPN

    Good info.
    Richard

Maybe you are looking for

  • Hi reg date

    hi all i want to give a date range to int table. my higher value is sy-datum, lower value must be less than 2 yrs , how can i code for this. any suggesstion

  • Problems uploading photos (Raw) to imac

    I recently tried uploading raw (nef) photos from my Nikon d5100. My imac (leopard osx 10.5) would only except a few jpegged images. Does anyone know why the raw images were not accepted? Thanks!

  • Mermory full - error??

    HI all, I do have quite a big LV project with over 100 VIs involved. Recently, I added one new VI. After that was added I encounterd error messages and LV exited. The error message was: "Memory Full VI "Main_FP.vi" was stopped at NamedMuxDCO 0x14754

  • Airport Extreme n & Airport Express g

    hi there I currently have the airport express g model and I am using it with a belkin g router and it works fine. I am looking to buy the new airport extreme n base station. I will use the express to play airtunes and print wirelessly. I will use the

  • T61p 3Gbps SATA workaround

    Theory: DOS boot process to enable 3Gbps mode Posted on NBR. Hoping to get some feedback on if this enabled the 3Gbps mode to workaround the bios imposed T61p 1.5Gbps SATA capping. 12.5" HP 2560P i5-2540M 2.6 8GB 60GB Renice X3.SSD 500GB/DVD HD3000 +