Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

VPN on Cisco ASA doesnt work

Attached is the config for Cisco ASA. The VPN doesnt work. Please let me know whats wrong with this one. Also if anyone has a sample config, please send over.

Thanks

Amit

1 ACCEPTED SOLUTION

Accepted Solutions

Re: VPN on Cisco ASA doesnt work

Glad it all works fine, please be sure to rate this post

26 REPLIES

Re: VPN on Cisco ASA doesnt work

Amit,

Your config looks good, what is the error message you get on your client? Your outside shows a private ip address are you using nat in front? have you opened the needed ports? can you send the client log or the asa debugs?

New Member

Re: VPN on Cisco ASA doesnt work

what ports are required to be opened up?

Re: VPN on Cisco ASA doesnt work

Port UDP 500, port UDP 4500 and protocol ESP need to be opened, also after adding these, go ahead and enable the next command "crypto isakmp nat-t"

New Member

Re: VPN on Cisco ASA doesnt work

do I create access-list for 500 4500? WHat does the crypto isakmp do?

Re: VPN on Cisco ASA doesnt work

Those ports need to be opened yes, but not on the firewall that you have, but in the router that is in front providing NAT (if any) that command enables encryption over UDP 4500 to alleviate NAT environments

New Member

Re: VPN on Cisco ASA doesnt work

attached is the modified config.

Re: VPN on Cisco ASA doesnt work

Amit,

I saw you opened those ports on the ASA by adding an ACL, ASA does not need to have this opened since this guy will accept vpn client connections by enabling the following commands "crypto isakmp enable outside" and "crypto map XXXX interface outside" which... now that I look again at your config you don't have.

Please go ahead and add this line to your ASA:

crypto map outside_map interface outside

And try to connect again.

New Member

Re: VPN on Cisco ASA doesnt work

do i enter

crypto isakmp enable outside

crypto map outside_map interface outside

or just

crypto map outside_map interface outside

Re: VPN on Cisco ASA doesnt work

enter both to be sure

New Member

Re: VPN on Cisco ASA doesnt work

Do you think I need to make any more changes to the config? Could you please check the config again. Why I am saying this is because I have to go to client side to do this, and if it doesnt work then I will have to wait again for your response and then go again.

Thanks for all your help.

Re: VPN on Cisco ASA doesnt work

Understood, you can go ahead and remove these:

access-list port500 extended permit udp interface Outside eq isakmp interface in

side

access-list port4500 extended permit udp interface Outside eq 4500 interface ins

ide

Add those commands that I mentioned you and please check the following line:

route Outside 0.0.0.0 0.0.0.0 10.1.10.1 1

This does not make sense to the addressing scheme on the outside interface, just let me know if this was edited for privacy matters.

New Member

Re: VPN on Cisco ASA doesnt work

no this is how it is. It wasnt edited for privacy matters. But If I remove this route, I cannot get out to the internet. This is the IP of the Comcast Router.

Thanks

Re: VPN on Cisco ASA doesnt work

That's ok, I was just wondering why it was on a different subnet, leave it and apply what I asked.

New Member

Re: VPN on Cisco ASA doesnt work

Do I need to have any access-list for allowing the crypto map?

Re: VPN on Cisco ASA doesnt work

nope, as soon as you enable the crypto map traffic will be processed by the asa

New Member

Re: VPN on Cisco ASA doesnt work

I can connect to the VPN and also get the valid ip. I can ping the inside of the ASA but cant ping or get to the machines on the network. Also looks like split tunneling doesnt work as my internet connection stops working as soon as I connect to the vpn.

Re: VPN on Cisco ASA doesnt work

Please post the last config from your ASA.

New Member

Re: VPN on Cisco ASA doesnt work

Attached is the updated config.

Thanks

Re: VPN on Cisco ASA doesnt work

Ok, go ahead and add the next:

access-list nonat permit ip 10.1.1.0 255.255.255.0 10.1.1.0 255.255.255.0

nat (inside) 0 access-list nonat

access-list MooreVPN_splitTunnelAcl standard permit 10.1.1.0 255.255.255.0

and type:

no access-list MooreVPN_splitTunnelAcl standard permit any

no access-list port500 extended permit udp interface Outside eq isakmp interface inside

no access-list port4500 extended permit udp interface Outside eq 4500 interface inside

Remove this line from the group-policy MooreVPN:

no split-tunnel-network-list value port500

And change it to:

split-tunnel-network-list value MooreVPN_splitTunnelAcl

Also, your access list to allow RDP into your network, is not right, change it from:

access-list outside_access_in extended permit tcp any eq 3389 host 10.1.1.10 eq 3389

to

access-list outside_access_in extended permit tcp any host 10.1.1.10 eq 3389

Pretty much your config should look like the attached one.

New Member

Re: VPN on Cisco ASA doesnt work

Thanks a lot. The VPN works now and I can access the machines inside the network.

I Couldnt RDP to the server even after adding the access-list.

Thanks

New Member

Re: VPN on Cisco ASA doesnt work

What I am trying to do is NAT one of the public IP to 10.1.1.10 which is one of the servers, so that I can RDP to it.

So I am using x.x.139.162 to translate to 10.1.1.10.

Re: VPN on Cisco ASA doesnt work

yes, you need a static translation, I am glad to hear that the vpn works now

New Member

Re: VPN on Cisco ASA doesnt work

I added these lines for natting

static (inside,outside) x.x.139.162 10.1.1.10 netmask 255.255.255.255

access-list outside_access_in extended permit tcp any host x.x.139.162 eq 3389

access-group outside_access_in in interface Outside.

Still it doesnt work.

Re: VPN on Cisco ASA doesnt work

Can you paste the "show conn" when you are trying as well as the logs that you see when trying as well?

New Member

Re: VPN on Cisco ASA doesnt work

I tried again and its working now. As I was trying to get the sh conn results it started working.

Thanks a lot for all you prompt help.

Re: VPN on Cisco ASA doesnt work

Glad it all works fine, please be sure to rate this post

160
Views
5
Helpful
26
Replies