Phones Behind 871 Rotuer through VPN via ASA not registering

Unanswered Question
Feb 27th, 2009

I have a VPN set up between an 871 router and an ASA 5505. VPN tunnel is up and I can pass traffic between the LANs. I can hit the phone system from the remote site (behind 871) as well as the main site via VPN tunnel. But, none of the phones will register. While looking at the phone system, I can see them registering/unregistering - Yes. The VPN tunnel is up.

I am getting the following message in the log:

Deny TCP (no connection) from 192.168.14.4 [remote LAN]/51373 to 10.10.10.1 [phone system]/2000 flags PSH ACK on interface outside

While the phones go through the register/unregister process. I have an ACL that permits all between the two sites as well as all of the other Nat/No-Nat etc etc.

Any thoughts would be much appreciated.

I have this problem too.
0 votes
  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Loading.
onazold Fri, 02/27/2009 - 14:21

Unfortunately, I am not using static NATs for either of the subnets...

My Nat

access-list inside_nat0_outbound extended permit ip object-group DM_INLINE_NETWORK_11 192.168.14.0 255.255.255.0

The DM_INLINE_NETWORK_11 includes the phone network (10.10.10.x) and the LAN on the other side of the ASA.

Ivan Martinon Fri, 02/27/2009 - 14:33

First you need to check if you need it, if your phones use stateless TCP sessions, then you need to use static nat and nailed.

Actions

This Discussion