Phones Behind 871 Rotuer through VPN via ASA not registering

Unanswered Question
Feb 27th, 2009
User Badges:

I have a VPN set up between an 871 router and an ASA 5505. VPN tunnel is up and I can pass traffic between the LANs. I can hit the phone system from the remote site (behind 871) as well as the main site via VPN tunnel. But, none of the phones will register. While looking at the phone system, I can see them registering/unregistering - Yes. The VPN tunnel is up.

I am getting the following message in the log:

Deny TCP (no connection) from [remote LAN]/51373 to [phone system]/2000 flags PSH ACK on interface outside

While the phones go through the register/unregister process. I have an ACL that permits all between the two sites as well as all of the other Nat/No-Nat etc etc.

Any thoughts would be much appreciated.

  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
onazold Fri, 02/27/2009 - 14:21
User Badges:

Unfortunately, I am not using static NATs for either of the subnets...

My Nat

access-list inside_nat0_outbound extended permit ip object-group DM_INLINE_NETWORK_11

The DM_INLINE_NETWORK_11 includes the phone network (10.10.10.x) and the LAN on the other side of the ASA.

Ivan Martinon Fri, 02/27/2009 - 14:33
User Badges:
  • Cisco Employee,

First you need to check if you need it, if your phones use stateless TCP sessions, then you need to use static nat and nailed.


This Discussion