networking-forum.com
Community BlogCommunity Wiki * Register  * Search  * Login
View unanswered postsView active topics

All times are UTC - 6 hours [ DST ]



Post new topic Reply to topic  [ 14 posts ] 
Author Message
PostPosted: Mon Apr 09, 2012 3:31 pm 
Offline
Post Whore
Post Whore
User avatar

Joined: Fri Apr 25, 2008 2:16 pm
Posts: 1361
Location: Jacksonville, FL
Certs: CCNP, CCNA:Sec, MCSE
I inherited an ASA5510 running 8.2(5)26. This ASA accepts AnyConnect connections, and has an IPSEC L2L tunnel back to our HQ. We have a need to have AnyConnect clients connect to this inherited ASA, and then traverse the IPSEC tunnel and hit a server at the HQ; not a big deal.

I didn't do the initial setup on this inherited ASA; I'm just tasked with making it work.

I have it setup where clients can connect with AnyConnect, and can ping a server at HQ; however, they can't hit it on port 80. When I try, I see the Sent counter increase on the client, but I don't see the Pkts counter increase on the IPSEC tunnel between the offices.

Can anybody suggest what to look for? I can ping the servers at HQ, just not hit TCP/80, which makes me think my NAT is correct.

_________________
"A problem well stated is a problem half solved". (Charles Kettering)


Top
 Profile  
 
PostPosted: Mon Apr 09, 2012 3:47 pm 
Offline
Moderator
Moderator
User avatar

Joined: Mon Apr 07, 2008 10:38 am
Posts: 9390
Location: Orlando, FL
Certs: CCNP RS, CCNP DC, CCDP, CCIP
sysopt connection permitvpn

or something like that

_________________
http://blog.alwaysthenetwork.com


Top
 Profile  
 
PostPosted: Mon Apr 09, 2012 3:58 pm 
Offline
Post Whore
Post Whore
User avatar

Joined: Fri Apr 25, 2008 2:16 pm
Posts: 1361
Location: Jacksonville, FL
Certs: CCNP, CCNA:Sec, MCSE
fw01# show run all | inc sysopt
sysopt connection timewait
sysopt connection tcpmss 1380
sysopt connection tcpmss minimum 0
sysopt connection permit-vpn
sysopt connection reclassify-vpn
sysopt connection preserve-vpn-flows
no sysopt nodnsalias inbound
no sysopt nodnsalias outbound
no sysopt radius ignore-secret
no sysopt noproxyarp outside
no sysopt noproxyarp inside
no sysopt noproxyarp management

_________________
"A problem well stated is a problem half solved". (Charles Kettering)


Top
 Profile  
 
PostPosted: Mon Apr 09, 2012 5:42 pm 
Offline
Moderator
Moderator
User avatar

Joined: Mon Apr 07, 2008 10:38 am
Posts: 9390
Location: Orlando, FL
Certs: CCNP RS, CCNP DC, CCDP, CCIP
hmmm

I agree with you on NAT being correct, but that's the only thing I can think of.

_________________
http://blog.alwaysthenetwork.com


Top
 Profile  
 
PostPosted: Mon Apr 09, 2012 8:57 pm 
Offline
Member
Member

Joined: Fri Nov 13, 2009 4:42 pm
Posts: 199
Certs: CCIE R&S
are you permitting intra-interface traffic?


Top
 Profile  
 
PostPosted: Mon Apr 09, 2012 9:05 pm 
Offline
Moderator
Moderator
User avatar

Joined: Mon Apr 07, 2008 10:38 am
Posts: 9390
Location: Orlando, FL
Certs: CCNP RS, CCNP DC, CCDP, CCIP
willroute4food wrote:
are you permitting intra-interface traffic?


Nice, I hadn't even considered that! You think he'd be able to ping without it though?

_________________
http://blog.alwaysthenetwork.com


Top
 Profile  
 
PostPosted: Mon Apr 09, 2012 9:06 pm 
Offline
Member
Member

Joined: Fri Nov 13, 2009 4:42 pm
Posts: 199
Certs: CCIE R&S
Ive seen it work like that, especially if your not inspecting icmp.


Top
 Profile  
 
PostPosted: Mon Apr 09, 2012 9:08 pm 
Offline
Moderator
Moderator
User avatar

Joined: Mon Apr 07, 2008 10:38 am
Posts: 9390
Location: Orlando, FL
Certs: CCNP RS, CCNP DC, CCDP, CCIP
I bet that's it then.

_________________
http://blog.alwaysthenetwork.com


Top
 Profile  
 
PostPosted: Tue Apr 10, 2012 8:35 am 
Offline
Post Whore
Post Whore
User avatar

Joined: Fri Apr 25, 2008 2:16 pm
Posts: 1361
Location: Jacksonville, FL
Certs: CCNP, CCNA:Sec, MCSE
same-security-traffic permit intra-interface

yup, its in there. I'm gonna play a bit more and then give up and call TAC.

_________________
"A problem well stated is a problem half solved". (Charles Kettering)


Top
 Profile  
 
PostPosted: Tue Apr 10, 2012 8:41 am 
Offline
Member
Member

Joined: Fri Nov 13, 2009 4:42 pm
Posts: 199
Certs: CCIE R&S
post your subnets, and your nat statements, if possible.


Top
 Profile  
 
PostPosted: Tue Apr 10, 2012 12:42 pm 
Offline
Junior Member
Junior Member

Joined: Fri Jun 25, 2010 7:55 am
Posts: 89
Certs: CCNP
I am assuming the subnet for your anyconnect clients is included in the crypto acl on both sides of your L2L tunnel back to HQ?


Top
 Profile  
 
PostPosted: Tue Apr 10, 2012 12:56 pm 
Offline
Post Whore
Post Whore
User avatar

Joined: Fri Apr 25, 2008 2:16 pm
Posts: 1361
Location: Jacksonville, FL
Certs: CCNP, CCNA:Sec, MCSE
Yes, it is; I can ping the server at HQ via the tunnel, which in my experience, means the crytomaps and ACLs and NATs are all correct.

When I 'ping $server_ip' I see the pkt counters on the L2L tunnels increase, but I don't see it increase when I try to 'telnet $server_ip 80', which to me feels like a VPN filter, but I have none specified.

_________________
"A problem well stated is a problem half solved". (Charles Kettering)


Top
 Profile  
 
PostPosted: Wed Apr 11, 2012 6:17 pm 
Offline
Member
Member

Joined: Sun Apr 17, 2011 3:28 pm
Posts: 213
Certs: CCSP/CCNP:Security GIAC GPEN
Have you tried running any packet captures?

Never tried running one while a tunnel was up so I'm not sure if you will see it before or after the encryption (gut tells me after encryption) but it might be helpful to see if you have any egress traffic on the client when trying to run a telnet for example.

Same on the ASA if you can make a filter to single out your IP address. See if you are receiving anything etc.

_________________
The Cubicle Wizard
http://cubiclewizard.blogspot.com/


Top
 Profile  
 
PostPosted: Tue May 08, 2012 9:36 am 
Offline
Post Whore
Post Whore
User avatar

Joined: Fri Apr 25, 2008 2:16 pm
Posts: 1361
Location: Jacksonville, FL
Certs: CCNP, CCNA:Sec, MCSE
Cisco TAC says this is a bug in ASA 8.2(5.26) with AnyConnect hair-pinning; bugid CSCty32412.

_________________
"A problem well stated is a problem half solved". (Charles Kettering)


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 14 posts ] 

All times are UTC - 6 hours [ DST ]


Who is online

Users browsing this forum: Exabot [Bot], Google [Bot] and 10 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Powered by phpBB® Forum Software © phpBB Group