ipad VPN to Cisco ASA 5520

Answered Question
Jul 21st, 2010

Hi,

I'm trying to get my ipad to VPN to our Cisco ASA5520.

I believe I have all of the settings correct on both ends (I am able to vpn to the asa using a cisco 871 as the remote client).

I suspect that for some reason the vpn client on the ipad isn't even getting to the asa. My question is: How can I monitor the ASA logs to see if the connection is even being attempted and possibly find the failure?

Thanks

M

I have this problem too.
0 votes
Correct Answer by manish arora about 6 years 6 months ago

try :-

debug crypto isakmp

debug crypto ipsec

sh vpn-sessiondb remote  ( to see if client is connected )

I configured ipad for remote vpn client , the user was able to connect to the 5520 but for reason i had to use ip addresses to access but i couldnt use internal dns names. trying to figure that out as of right now.

hope it helps

Manish

  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 5 (2 ratings)
Loading.
Correct Answer
manish arora Wed, 07/21/2010 - 16:59

try :-

debug crypto isakmp

debug crypto ipsec

sh vpn-sessiondb remote  ( to see if client is connected )

I configured ipad for remote vpn client , the user was able to connect to the 5520 but for reason i had to use ip addresses to access but i couldnt use internal dns names. trying to figure that out as of right now.

hope it helps

Manish

mireynol Fri, 07/23/2010 - 08:28

What does your dynamic crypto map use for it's transform set?  I ran into a similar issue where ipsec clients hw/sw could connect, but not IPad.  I had to configure the dynamic map to also use 3des/md5 to make it work.

But as last person mentioned, debug for crypto isakmp and ipsec to make sure the device can reach the ASA.

ciscocharger Tue, 07/27/2010 - 10:59

Hi,

Finally got it to work. Thanks for the tip on how to watch debug stuf for ipsec.

I saw that the problem was no address pool was assigned to the tunnel group.

This leads to a new question but I'll post another thread.

Tanks again!

M

Actions

This Discussion