cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
479
Views
0
Helpful
1
Replies

ASA 5505 as hw vpn client to PIX501 or ASA5505 w network extension mode

kumlait2004
Level 1
Level 1

Hi!

We have been using a PIX 501 for a couple of years now to access a

local network with Cisco VPN software client. However we now need

access from another site with multiple users so I decided to buy two

ASA 5505 UL bundle to do the job. First i tried to just hook up the

new ASA at the remote site and connect to the PIX 501 with easy vpn.

In went fine. I configured the new ASA right from the box with the old

vpn profile settings and it worked right away. But as we also need the

remote site to be accessed from the main site (PIX side) i tried to

enable "network extension mode" but then the tunnel didnt work

anymore. it connects but no traffic is coming through. I set it back

to normal mode (only client) and it worked again.

Is there anything else I need to do to be able to use network

extension mode than just enabling it in ASDM ?

The samt thing happens when using two ASA 5505 the same way.

Software versions are:

PIX: 6.3

ASA 5505: 7.2.1 (used to be 7.2.2 but I had to downgrade because of a bug in 7.2.2 - vpnclient fails after reboot)

I also did try the latest 8.2 with very little success. Seemed a bit buggy.

Thanks,

Bjorn

1 Reply 1

kumlait2004
Level 1
Level 1

Hi!

Thought I could add some info. Our Head unit is 192.168.1.1 and the connecting ASA 5505 is 192.168.10.1. When I try to ping a machine (192.168.1.201) from the remote site I get this in the ASA log:

With network extension mode

302020 192.168.1.201 192.168.10.2 Built ICMP connection for faddr 192.168.1.201/0 gaddr 192.168.10.2/512 laddr 192.168.10.2/512

With only client mode

302020 192.168.1.201 192.168.10.2 Built ICMP connection for faddr 192.168.1.201/0 gaddr 192.168.1.9/1 laddr 192.168.10.2/512

It seemes to me (quite the newbie here on ASA) that the unit does not handle the gateway address correctly when using network extension mode. The PC i use to ping from is 192.168.10.2.

Any ideas from the experts ?

Regards,

B

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: