Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

NAT rule is denying traffic through S2S vpn tunnel on 5510 (8.02)

I swapped out our PIX with an ASA 5510 v8.02 and one of tunnels won't allow traffic through. The dynnamic NAT rule shows up as the culprit in packet tracer. Our traffic has to be NATed to get to their site DMZ servers. Not sure what I missed in the conversion from PIX to ASA

3 REPLIES

Re: NAT rule is denying traffic through S2S vpn tunnel on 5510 (

I think you missed "sysopt connection permit-vpn"

New Member

Re: NAT rule is denying traffic through S2S vpn tunnel on 5510 (

That was missing. So I issued the command but it dinn't change anything. I also see the following error for traffic that should be allowed through the tunnel

Sep 10 2007 08:45:09 106001 192.168.72.102 Stibo_HTQuark Inbound TCP connection denied from 192.168.72.102/2898 to Stibo_HTQuark/11207 flags SYN on interface Inside

New Member

Re: NAT rule is denying traffic through S2S vpn tunnel on 5510 (

Found the problem. It was in the ACL used for Group Policy on the Tunnel Group.

119
Views
0
Helpful
3
Replies