Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

ipsec spoofing VPN

Got no errors in the logs but when I try in packet tracer, I get IPSec Spoofing error

From 192.168.0.10 to 192.168.1.2

Heres the config

: Saved
: Written by enable_15 at 13:18:17.890 UTC Thu Feb 16 2012
!
ASA Version 7.2(4)
!
hostname ciscoasa
domain-name default.domain.invalid

!
interface Vlan1
nameif inside
security-level 100
ip address 192.168.1.1 255.255.255.0
!
interface Vlan2
nameif outside
security-level 0
?????????????
!
interface Ethernet0/0
switchport access vlan 2
!
interface Ethernet0/1
!
interface Ethernet0/2
!
interface Ethernet0/3
!
interface Ethernet0/4
!
interface Ethernet0/5
!
interface Ethernet0/6
!
interface Ethernet0/7
!
ftp mode passive
dns server-group DefaultDNS
domain-name default.domain.invalid
object-group protocol TCPUDP
protocol-object udp
protocol-object tcp
access-list vpn-impact_splitTunnelAcl standard permit 192.168.1.0 255.255.255.0
access-list inside_nat0_outbound extended permit ip any 192.168.0.0 255.255.255.192
access-list inside_nat0_outbound extended permit ip host 192.168.1.2 192.168.0.0 255.255.255.192
access-list outside_access_in extended permit tcp any any eq smtp
access-list outside_access_in extended permit object-group TCPUDP any any eq www
access-list outside_access_in extended permit tcp any any eq https
access-list outside_access_in extended permit tcp any any eq 3389
access-list outside_access_in extended permit ip 192.168.0.0 255.255.255.192 192.168.1.0 255.255.255.0
access-list inside_access_in extended permit object-group TCPUDP any any
access-list inside_access_in extended permit ip 192.168.0.0 255.255.255.192 192.168.1.0 255.255.255.0
access-list inside_access_in extended permit ip 192.168.1.0 255.255.255.0 192.168.0.0 255.255.255.192
pager lines 24
logging enable
logging asdm informational
mtu inside 1500
mtu outside 1500
ip local pool ImpactVPN 192.168.0.10-192.168.0.40 mask 255.255.255.0
icmp unreachable rate-limit 1 burst-size 1
asdm image disk0:/asdm-524.bin
no asdm history enable
arp timeout 14400
global (outside) 1 interface
nat (inside) 0 access-list inside_nat0_outbound
nat (inside) 1 0.0.0.0 0.0.0.0
static (inside,outside) tcp interface smtp 192.168.1.2 smtp netmask 255.255.255.255
static (inside,outside) tcp interface www 192.168.1.2 www netmask 255.255.255.255
static (inside,outside) tcp interface https 192.168.1.2 https netmask 255.255.255.255
static (inside,outside) tcp interface 3389 192.168.1.2 3389 netmask 255.255.255.255
access-group inside_access_in in interface inside
access-group outside_access_in in interface outside
timeout xlate 3:00:00
timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02
timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00
timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00
timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute
http server enable
http 192.168.1.0 255.255.255.0 inside
no snmp-server location
no snmp-server contact
snmp-server enable traps snmp authentication linkup linkdown coldstart
crypto ipsec transform-set ESP-3DES-SHA esp-3des esp-sha-hmac
crypto dynamic-map outside_dyn_map 20 set pfs group1
crypto dynamic-map outside_dyn_map 20 set transform-set ESP-3DES-SHA
crypto dynamic-map outside_dyn_map 40 set pfs group1
crypto dynamic-map outside_dyn_map 40 set transform-set ESP-3DES-SHA
crypto map outside_map 65535 ipsec-isakmp dynamic outside_dyn_map
crypto map outside_map interface outside
crypto isakmp enable outside
crypto isakmp policy 10
authentication pre-share
encryption 3des
hash sha
group 2
lifetime 86400
telnet timeout 5
ssh timeout 5
console timeout 0

dhcpd dns 192.168.1.2
dhcpd auto_config outside
!
dhcpd address 192.168.1.5-192.168.1.36 inside
dhcpd dns 192.168.1.2 interface inside
dhcpd enable inside
!

group-policy DfltGrpPolicy attributes
banner none
wins-server none
dns-server none
dhcp-network-scope none
vpn-access-hours none
vpn-simultaneous-logins 3
vpn-idle-timeout 30
vpn-session-timeout none
vpn-filter none
vpn-tunnel-protocol IPSec l2tp-ipsec webvpn
password-storage disable
ip-comp disable
re-xauth disable
group-lock none
pfs disable
ipsec-udp disable
ipsec-udp-port 10000
split-tunnel-policy tunnelall
split-tunnel-network-list none
default-domain none
split-dns none
intercept-dhcp 255.255.255.255 disable
secure-unit-authentication disable
user-authentication disable
user-authentication-idle-timeout 30
ip-phone-bypass disable
leap-bypass disable
nem disable
backup-servers keep-client-config
msie-proxy server none
msie-proxy method no-modify
msie-proxy except-list none
msie-proxy local-bypass disable
nac enable
nac-sq-period 300
nac-reval-period 36000
nac-default-acl none
address-pools none
smartcard-removal-disconnect enable
client-firewall none
client-access-rule none
webvpn
functions url-entry
html-content-filter none
homepage none
keep-alive-ignore 4
http-comp gzip
filter none
url-list none
customization value DfltCustomization
port-forward none
port-forward-name value Application Access
sso-server none
deny-message value Login was successful, but because certain criteria have not been met or due to some specific group policy, you do not have permission to use any of the VPN features. Contact your IT administrator for more information
svc none
svc keep-installer installed
svc keepalive none
svc rekey time none
svc rekey method none
svc dpd-interval client none
svc dpd-interval gateway none
svc compression deflate
group-policy vpn-impact internal
group-policy vpn-impact attributes
vpn-tunnel-protocol IPSec
split-tunnel-policy tunnelspecified
split-tunnel-network-list value vpn-impact_splitTunnelAcl
default-domain value impactdetail
nac enable
address-pools value ImpactVPN


vpn-group-policy vpn-impact
tunnel-group vpn-impact type ipsec-ra
tunnel-group vpn-impact general-attributes
address-pool ImpactVPN
default-group-policy vpn-impact
tunnel-group vpn-impact ipsec-attributes
pre-shared-key Impvpn0102
!
class-map inspection_default
match default-inspection-traffic
!
!
policy-map type inspect dns preset_dns_map
parameters
message-length maximum 512
policy-map global_policy
class inspection_default
inspect dns preset_dns_map
inspect ftp
inspect h323 h225
inspect h323 ras
inspect rsh
inspect rtsp
inspect esmtp
inspect sqlnet
inspect skinny
inspect sunrpc
inspect xdmcp
inspect sip
inspect netbios
inspect tftp
!
service-policy global_policy global
prompt hostname context
Cryptochecksum:aae550a99445ddf6003f295946219f59
: end

10 REPLIES
Bronze

ipsec spoofing VPN

You can't spoof IPSec traffic.  You will always see the 'Ipsec spoof detected' from packet tracer because the ASA sees unencrypted traffic on an interface on which it should be encrypted.

Bronze

ipsec spoofing VPN

Can't edit my last post from my iPhone.  What I meant to say is that you cannot mimic IPSec traffic with packet tracer.

ipsec spoofing VPN

But my pings does not pass... and I get no errors in the logs...

ipsec spoofing VPN

Still no errors in logs, no Windows firewall are On, pings does not pass.

Thanks for the help!

ipsec spoofing VPN

Hello Jean,

On packet tracer, are you doing in it from the outside, if you do it packet-tracer input inside you will get that ip-sec spoof error.

Looking for some Networking Assistance? Contact me directly at jcarvaja@laguiadelnetworking.com I will fix your problem ASAP. Cheers, Julio Carvajal Segura http://laguiadelnetworking.com

Re: ipsec spoofing VPN

Doing it with the outside interface

Can anyone look at the config and tell me why the pings are blocked with no errors in the log ?

Thanks

Sent from Cisco Technical Support iPhone App

Re: ipsec spoofing VPN

Hello Jean,

Ups! I said it backwards, its packet-tracer input inside ( that is the one should work)

Looking for some Networking Assistance? Contact me directly at jcarvaja@laguiadelnetworking.com I will fix your problem ASAP. Cheers, Julio Carvajal Segura http://laguiadelnetworking.com
Bronze

Re: ipsec spoofing VPN

When you ping from the client workstation, do you see decaps on the phase 2 SA for that host?

Was sysopt connection permit-vpn disabled? 

ipsec spoofing VPN

Where can I see that?

When I ping, The syslog tells me that the packets were created and then destroyed, like there were no problems

ipsec spoofing VPN

Hello Jean,

So you do connect to the ASA via the remote IPsec client, but you cannot ping the host behind the ASA.

This looks good

group-policy vpn-impact internal
group-policy vpn-impact attributes
vpn-tunnel-protocol IPSec
split-tunnel-policy tunnelspecified
split-tunnel-network-list value vpn-impact_splitTunnelAcl
default-domain value impactdetail
nac enable
address-pools value ImpactVPN


vpn-group-policy vpn-impact
tunnel-group vpn-impact type ipsec-ra
tunnel-group vpn-impact general-attributes
address-pool ImpactVPN
default-group-policy vpn-impact
tunnel-group vpn-impact ipsec-attributes
pre-shared-key Impvpn0102

Now lets talk about the No_nat

nat (inside) 0 access-list inside_nat0_outbound

access-list inside_nat0_outbound extended permit ip any 192.168.0.0 255.255.255.192

access-list inside_nat0_outbound extended permit ip host 192.168.1.2 192.168.0.0 255.255.255.192

Please remove them with

clear configure access-list inside_nat0_outbound

and then create :

access-list inside_nat0_outbound permit ip 192.168.1.0 255.255.255.0 192.168.0.0 255.255.255.0

nat (inside) 0 access-list inside_nat0_outbound

Give it a try and let me know!

Regards,

Julio

Looking for some Networking Assistance? Contact me directly at jcarvaja@laguiadelnetworking.com I will fix your problem ASAP. Cheers, Julio Carvajal Segura http://laguiadelnetworking.com
2029
Views
0
Helpful
10
Replies
CreatePlease login to create content