networking-forum.com
Community BlogCommunity Wiki * Register  * Search  * Login
View unanswered postsView active topics

All times are UTC - 6 hours [ DST ]



Post new topic Reply to topic  [ 6 posts ] 
Author Message
 Post subject: vpn tunnel issue
PostPosted: Thu Apr 26, 2012 3:23 am 
Offline
Junior Member
Junior Member

Joined: Wed Dec 10, 2008 6:09 am
Posts: 85
I have VPN tunnel issue at one of my site. suddenly vpn traffic becomes ureachable where as tunnel are up. After resetting tunnels it start working fine. VPN device is cisco ASA,

Thanx


Top
 Profile  
 
 Post subject: Re: vpn tunnel issue
PostPosted: Thu Apr 26, 2012 7:35 am 
Offline
Post Whore
Post Whore
User avatar

Joined: Tue Aug 21, 2007 2:15 pm
Posts: 8457
Location: Frederick MD
Certs: Instanity
what do the logs say ?

_________________
"If you're good at anticipating the human mind. It leaves nothing to chance."
-Jigsaw


Top
 Profile  
 
 Post subject: Re: vpn tunnel issue
PostPosted: Thu Apr 26, 2012 10:14 am 
Offline
Senior Member
Senior Member
User avatar

Joined: Mon Feb 14, 2011 10:28 pm
Posts: 401
Certs: CCNA
debug crypto isakmp
debug crypto ipsec

Version of asa code?
How is your nat0 (no-nat) configuration?


Top
 Profile  
 
 Post subject: Re: vpn tunnel issue
PostPosted: Fri Apr 27, 2012 2:25 am 
Offline
Junior Member
Junior Member

Joined: Wed Dec 10, 2008 6:09 am
Posts: 85
hi asa version is 8.4. & static exempt natting is configured.


Top
 Profile  
 
 Post subject: Re: vpn tunnel issue
PostPosted: Fri Apr 27, 2012 3:08 am 
Offline
Junior Member
Junior Member

Joined: Wed Dec 10, 2008 6:09 am
Posts: 85
below is the output of sh crypto ipsec sa .....


Crypto map tag: ABC, seq num: 1, local addr: X.X.X.X

access-list ABC-vpn extended permit ip 10.81.X.X 255.255.255.0 172.X.X.X 255.240.0.0
local ident (addr/mask/prot/port): (10.81.x.x/255.255.255.0/0/0)
remote ident (addr/mask/prot/port): (172.x.x.x/255.240.0.0/0/0)
current_peer: x.x.x.x

#pkts encaps: 67490, #pkts encrypt: 67532, #pkts digest: 67532
#pkts decaps: 68288, #pkts decrypt: 68288, #pkts verify: 68288
#pkts compressed: 0, #pkts decompressed: 0
#pkts not compressed: 67490, #pkts comp failed: 0, #pkts decomp failed: 0
#pre-frag successes: 42, #pre-frag failures: 0, #fragments created: 84
#PMTUs sent: 0, #PMTUs rcvd: 0, #decapsulated frgs needing reassembly: 99
#send errors: 0, #recv errors: 0

local crypto endpt.: x.x.x.x/0, remote crypto endpt.: x.x.x.x/0
path mtu 1500, ipsec overhead 74, media mtu 1500
current outbound spi: 105EA463
current inbound spi : FD3B37FC

inbound esp sas:
spi: 0xFD3B37FC (4248516604)
transform: esp-aes esp-sha-hmac no compression
in use settings ={L2L, Tunnel, PFS Group 2, }
slot: 0, conn_id: 466944, crypto-map: ABC
sa timing: remaining key lifetime (sec): 3404
IV size: 16 bytes
replay detection support: Y
Anti replay bitmap:
0xFFFFFFFF 0xFFFFFFFF
outbound esp sas:
spi: 0x105EA463 (274637923)
transform: esp-aes esp-sha-hmac no compression
in use settings ={L2L, Tunnel, PFS Group 2, }
slot: 0, conn_id: 466944, crypto-map: ABC
sa timing: remaining key lifetime (sec): 3403
IV size: 16 bytes
replay detection support: Y
Anti replay bitmap:
0x00000000 0x00000001


Top
 Profile  
 
 Post subject: Re: vpn tunnel issue
PostPosted: Mon May 14, 2012 6:23 am 
Offline
Junior Member
Junior Member

Joined: Wed Dec 10, 2008 6:09 am
Posts: 85
hi this quite serious issue and I tried my everything to resolve it.now expert solution is required. so experts come forward and provide the solutions.

Thank,


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 6 posts ] 

All times are UTC - 6 hours [ DST ]


Who is online

Users browsing this forum: FaceBook [Linkcheck] and 10 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Powered by phpBB® Forum Software © phpBB Group