cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
316
Views
0
Helpful
2
Replies

ASA ping host to host

p.maillot
Level 1
Level 1

Hello,

I have a problem with this configuration.

172.16.1.2 > ASA5510 > Router 2811 > ASA5505 > 172.16.2.2

ASA5510 can ping host 172.16.1.2 and host 172.16.2.2

ASS5505 can ping host 172.16.2.2 and host 172.16.1.2

but host 172.16.2.2 cannot ping host 172.16.1.2, why?

See the attached file.

Regards

2 Replies 2

p.maillot
Level 1
Level 1

Nobody have an idea?

Regards

My config is.

Host 172.16.1.0/x > ASA 5510 > Router 2811 > Router 871 > ASA5505 > Host 172.16.2.0/x

I have a VPN between Router 2811 and 871

When I ping host 172.16.2.2 from host 172.16.1.2, I can see on router 2811

%CRYPTO-4-IKMP_BAD_MESSAGE: IKE message from 10.52.72.135 failed its sanity check or is malformed

From host 172.16.1.2 to host 172.16.2.2, I can see on router 871

%CRYPTO-4-IKMP_BAD_MESSAGE: IKE message from 10.52.72.129 failed its sanity check or is malformed

What is the problem? VPN encryption is blocked by the ASA?

Regards

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: