Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

Concurrent pings between VPN subnets using ASA (8.4) not working as intended


I have already setup the L2L VPN between two ASAs and successfully ping from a host of a subnet of one site to another host of a subnet on the other site; but, it fails if I 've two concurrent pings between subnets of either site.

2 concurrent pings from one subnet to another.PNG

2 concurrent pings.PNG

It appears that auto-nat is not in effect and when I checked sh crypto ipsec sa I found only one association. I have this vibe as private IPs are not being used for routing purpose that's why it's not being translated. Rather public IPs are being used for trunnel building purpose and once there is a "sa" packets from private IPs are encrypted and sent via tunnel to the peer (public IP), which then decrypts and places to the right host (private IP) via switch.

Basic setup commands are attached for reference. I intend to simuate need for NAT-T. I 've used ikev1 for that purpose. In connection to this down the road I 'll will 've a NAT device before Brnach ASA.