Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
Community Member

ASA 5510 Routing issues with IPSec client on second external interface

I am gradually migrating from one ISP to another, because this unit is live I have created a second outside interface (outside-2) and I have successfully exposed all server services needed i.e. SMTP, WEB and so on, however the VPN client is causing me grief. I suspect that the errors are routing related with the ipsec traffic coming in on outside-2 and then being routed out on the original outside interface generating the following messages:

Group = VPN-Users-RR, IP= x.x.x.x, Duplicate Phase 1 packet detected. Retransmitting last packet.

Group = VPN-Users-RR, IP = x.x.x.x1, P1 Retransmit msg dispatched to AM FSM

Routing failed to locate next hop for udp from NP Identity Ifc:RR_External_1/62465 to outside-2:x.x.x.x/4

I have attached a condensed version of our config.

Regard Graham

Everyone's tags (5)
302
Views
0
Helpful
0
Replies
CreatePlease to create content