Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
New Member

SA520 VPN Routing issue - No traffic

Hello,

SA520 (Firmware 2.1.71).

I have a Site-To-Site VPN tunnel established but I can't get my traffic to go through the tunnel.

I setup 4 IP alias on my WAN interface (my 4 public IPs).

I setup a firewall rule (see attachment) from my LAN to WAN using one of the IP Alias.

Now from my 172.17.1.54 machine, I try to ping/telnet/etc to the external 144.194.x.x machine but I don't get anything back nor can I see any traffic going through the tunnel (Tx is 0)

Am I doing anything wrong?

Thanks for helping,
Best regards,

Alex

Everyone's tags (1)
7 REPLIES
Gold

SA520 VPN Routing issue - No traffic

Alex,

Is 172.17.1.54 in the same VLAN for which the tunnel was established? If so, there is no need for any firewall rules.

Can other hosts on the LAN pass traffic through the tunnel?

Can you ping through the tunnel from the router Diagnostics page?

Where is 144.194.x.x? Is that part of your block of WAN IPs or is it at the other side of the tunnel?

I'm sure it's clear to you but I'm having a hard time understanding what exactly you wish to accomplish. Can you draw a simple topology?

- Marty

New Member

SA520 VPN Routing issue - No traffic

Hello,

I didn't create a VLAN for the Tunnel. Should I?

No other host pass through the tunnel. The VPN tunnel is freshly setup.

I cannot ping through the tunnel from the Diagnostics page.

144.194.x.x is on the other side of the tunnel.

Here is the topology I am trying to achieve.

Snap_934.jpg

Thanks for your help.

Alex

Gold

SA520 VPN Routing issue - No traffic

Alex,

Thanks for the topology, that helps. What kind of router is at the Remote side? Do the servers actually have a WAN IP or are you using One-to-One NAT on that side as well?

Did you create an Access Rule to allow inbound traffic to Server 1 Local using one of the other public IPs?

- Marty

New Member

SA520 VPN Routing issue - No traffic

THe router on the other side is a Cisco ASA 5550.

The servers on the remote side use OneToOne NAT as well.

I created an inbound rule as well, allowing the external IP to my Server 1 Local . It doesn't change anything.

Snap_937.jpg

Gold

SA520 VPN Routing issue - No traffic

Alex,

You shouldn't create any rules on the SA520 in regards to the VPN. It will allow all traffic to and from any device on the LAN that the tunnel is set up for. It sounds like maybe there is some problem with your tunnel settings, either on the ASA or SA520.

Can you post screenshots of the SA520 tunnel configuration?

- Marty

New Member

SA520 VPN Routing issue - No traffic

Hello,

here is the IKE configuration

IkeConfig.png

here the VPN Policy

VPNConfig.png

Could it have something to do with the local/remote traffic selection section?

Gold

SA520 VPN Routing issue - No traffic

Alex,

Try Local Traffic Selection Subnet Mask 255.255.255.0 instead of 255.255.252.0 on the VPN Policy.

Everything else looks normal to me.

- Marty

323
Views
0
Helpful
7
Replies
CreatePlease to create content