getting the following errors between lan2lan VPN: %PIX-2-106001

Unanswered Question
May 30th, 2007
User Badges:

Hi I am getting the following errors when trying to ssh between 2 servers over the VPN tunnel. I see it is going out of my acl_inside access-list but I do not see it reaching the VPN acess list. There is no natting between the 2 ips.

# no natting for subnet to subnet

access-list nonat extended permit ip

# acl_in access list

access-list acl_in line 4 extended permit tcp host host (hitcnt=28)

access-list acl_in line 31 extended permit ip (hitcnt=462)

# VPN access list

access-list XO_access_in line 5 extended permit tcp host eq ssh host (hitcnt=0)

%PIX-2-106001: Inbound TCP connection denied from to flags SYN on interface inside

# show version

Cisco PIX Security Appliance Software Version 7.0(4)

Device Manager Version 5.0(4)

Compiled on Thu 13-Oct-05 21:43 by builders

System image file is "flash:/pix704.bin"

  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
acomiskey Wed, 05/30/2007 - 15:12
User Badges:
  • Green, 3000 points or more

Any chance of getting more complete configs?

Mrkaprino Thu, 05/31/2007 - 07:04
User Badges:

Here is the config minus the private information. I am just trying to ssh to from via the UK VPN tunnel. There should be no NATing, as well.





This Discussion