After ASA 7.1(2) to 8.0(4) upgrade Remote VPN's not working correctly.

Answered Question
Mar 16th, 2009

I just upgraded my ASA's from 7 to 8 and now my Remote Access VPN's are working correctly. The tunnels connect and I can ping anything but I can't browse network shares or connect to exchange.

ANy idea as to what I am missing?

Thanks,

Dan

I have this problem too.
0 votes
Correct Answer by tkatsiaounis about 7 years 8 months ago

IPSec VPN packets are dropped when compression is enabled-When you configure the ip-comp enable command under the group-policy, then large packets that are eligible for compression are silently dropped by the security appliance. VPN compression is only useful for very slow Internet connections, so we suggest that you disable compression (ip-comp disable). Alternatively, you can upgrade to interim build 8.0(4.16) or later. (CSCsu26649)

From Cisco 8.0.4 release notes.

  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 5 (2 ratings)
Loading.
Correct Answer
tkatsiaounis Tue, 03/17/2009 - 01:47

IPSec VPN packets are dropped when compression is enabled-When you configure the ip-comp enable command under the group-policy, then large packets that are eligible for compression are silently dropped by the security appliance. VPN compression is only useful for very slow Internet connections, so we suggest that you disable compression (ip-comp disable). Alternatively, you can upgrade to interim build 8.0(4.16) or later. (CSCsu26649)

From Cisco 8.0.4 release notes.

ddevecka Tue, 03/17/2009 - 05:42

Thanks! I found that you had this problem last night in a prior post and have already diasbled IP-comp.

Thanks.

Actions

This Discussion