Remote PIX tunnel - can't see hosts until they connect to me first
I have a remote 501 running an Easy VPN connection back to our HQ ASA 5520s but have noticed that even though the tunnel is built fine I cannot ping from the HQ side to the remote systems until one of them pings me first. I have tried the nem-st-autoconnect which has it's own problems (the dsl router on the remote side chops the connection in the middle causing the 501 to never rebuild the tunnel, I have recreated this in my lab) but in any case I simply want to be able to ping the remote hosts when the tunnel is up but cannot figure out how. I have tried the management-access inside flag which has the same issues. I have a valid tunnel but cannot "see" the remote network until they initiate a connection. Any ideas?
Re: Remote PIX tunnel - can't see hosts until they connect to me
I have that issue with DHCP remotes. No way for us to know what their outside address will be. They have to open the tunnel. I think I may have stumbled upon a possible solution by using the NTP protocol to work off a server at my HQ. This way, that will occasionally talk to my HQ servers and open the tunnel!
Table of ContentsIntroductionVersion HistoryPossible Future
UpdatesDocuments PurposeNAT Operation in ASA 8.3+ SectionsRule Types
Network Object NATTwice NAT / Manual NATRule Types used per SectionNAT
Types used with Twice NAT / Manual NAT and Network Obje...
Table of Contents Introduction:This document describes details on how
NAT-T works. Background: ESP encrypts all critical information,
encapsulating the entire inner TCP/UDP datagram within an ESP header.
ESP is an IP protocol in the same sense that TCP an...