- I have setup a VPN through my ASA for my branch routers, Branch routers are on ADSL link and they are initiating the connection and they are able to connect to HO.On my ASA i have created dynamic-map which accepts connection dynamically.The problem is i can't initiate a connection from ASA to Branch router and also when branch routers are connected to HO when the tunnel is up though i m not able to telnet or ping to the remote branch routers??????
- I also face this issue with site-site VPN.
Below is packet tracer for ping:
in 0.0.0.0 0.0.0.0 outside
service-policy global_policy global
nat (inside,outside) source static obj-192.168.0.0 obj-192.168.0.0 destination static ABC-subnet ABC-subnet no-proxy-arp route-lookup
Static translate 192.168.100.1/0 to 192.168.100.1/0
Drop-reason: (acl-drop) Flow is denied by configured rule
I dont understand why result is drop due to acl, i have kept open from HO to Branch on specific subnets and this packet tracer is from the subnet which is permited everything to the remote branch.