Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

VPN IPSEC Tunnel error routing packets

I am setting up a VPN for multiple users remotley with cisco client v3.0 to PIX firewall 525. I have managed to get the client to connect and get an IP address however I am unable to route traffic to the inside interface network.

Looking at the debuig info I get this message

305006 regular transaction creation failed for tcp src inside 10.205.24.22 dst inside 172.16.1.1

Here is they main config of my setup

Building configuration...

: Saved

:

PIX Version 6.3(1)

nameif ethernet0 outside security0

nameif ethernet1 inside security100

access-list inside_outbound_nat0_acl permit ip any 172.16.1.0 255.255.255.0

access-list outside_cryptomap_dyn_20 permit ip any 172.16.1.0 255.255.255.0

ip address outside 195.x.x.218 255.255.255.248

ip address inside 10.205.24.20 255.255.252.0

ip verify reverse-path interface outside

ip verify reverse-path interface inside

ip audit info action alarm

ip audit attack action alarm

ip local pool SWTUsers 172.16.1.1-172.16.1.255

arp timeout 14400

global (outside) 1 195.x.x.222

nat (inside) 0 access-list inside_outbound_nat0_acl

nat (inside) 1 10.205.0.0 255.255.0.0 0 0

static (inside,outside) 195.x.x.220 10.205.24.22 netmask 255.255.255.255 0 0

route outside 0.0.0.0 0.0.0.0 195.166.18.217 1

route inside 10.205.0.0 255.255.0.0 10.205.24.1 1

sysopt connection permit-ipsec

crypto ipsec transform-set ESP-3DES-MD5 esp-3des esp-md5-hmac

crypto dynamic-map outside_dyn_map 20 set transform-set ESP-3DES-MD5

crypto dynamic-map outside_dyn_map_1 20 match address outside_cryptomap_dyn_20

crypto dynamic-map outside_dyn_map_1 20 set transform-set ESP-3DES-MD5

crypto map outside_map 65535 ipsec-isakmp dynamic outside_dyn_map_1

crypto map outside_map interface outside

crypto map inside_map client authentication RADIUS

crypto map inside_map interface inside

isakmp enable outside

isakmp policy 20 authentication pre-share

isakmp policy 20 encryption 3des

isakmp policy 20 hash md5

isakmp policy 20 group 2

isakmp policy 20 lifetime 86400

vpngroup vpnin address-pool SWTUsers

vpngroup vpnin dns-server 10.205.24.8

vpngroup vpnin idle-time 1800

vpngroup vpnin password ********

can anyone help please?

5 REPLIES
New Member

Re: VPN IPSEC Tunnel error routing packets

If you remove this from the configuration

no crypto dynamic-map outside_dyn_map_1 20 match address outside_cryptomap_dyn_20

no crypto dynamic-map outside_dyn_map_1 20 set transform-set ESP-3DES-MD5

no crypto map inside_map interface inside

no crypto map inside_map

and overwrite this command

crypto map outside_map 65535 ipsec-isakmp dynamic outside_dyn_map 20

test this again, you should be able to pass traffic....

the command which points over to the access list outside_cryptomap_dyn_20, is not doing anything

you are telling the client to tunnel everything

access-list outside_cryptomap_dyn_20 permit ip any 172.16.1.0 255.255.255.0

If you will like to setup split tunneling, your access list will look like this:

access-list outside_cryptomap_dyn_20 permit ip 10.205.0.0 255.255.0.0 172.16.1.0 255.255.255.0

As you have a route inside 10.205.0.0/16, I imagine you have additional networks on this subnet

and you will add:

vpngroup vpnin split-tunnel outside_cryptomap_dyn_20

That should do it

R,

Arthur

New Member

Re: VPN IPSEC Tunnel error routing packets

Arthur

Thanks for helping tidy up the rules, however I am still getting the same error.

Incidently typing

crypto map outside_map 65535 ipsec-isakmp dynamic outside_dyn_map 20

The 20 on the end of the line does not get entered into the pix config, I type it in and it leaves it off.

I have further tried to get from the inside network 10.205.0.0 to the vpn network 172.16.1.0 and I still see the same message

305006: regular translation creation failed for tcp src inside:10.205.24.x dst inside:172.16.1.1

Any further ideas/help ?

Thanks

New Member

Re: VPN IPSEC Tunnel error routing packets

Hi,

Remove the same and try to add this way

crypto dynamic-map outside_dyn_map set transform-set ESP-3DES-MD5

crypto map outside_map 65535 ipsec-isakmp dynamic outside_dyn_map

if ur trying to connect the VPN from outside , try to bind the crypto to the outside interface

crypto map outside_map interface outside

try to connect with this set of config

Regards

Natty

New Member

Re: VPN IPSEC Tunnel error routing packets

Thanks for the suggestion. I updated the config but I am still getting the same error.

Any other ideas?

Regards,

Matthew

New Member

Re: VPN IPSEC Tunnel error routing packets

It turned out that the problem was not the firewall configuration but rather our router configuration. It was already routing 172.16.0.0 network packets elsewehere. I instead changed the dhcp pool to 192.168.10.0 and now everything works fine.

115
Views
8
Helpful
5
Replies