Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
New Member

"Failed to locate egress interface" error

good day,

I am setting up a site-to-site VPN between a SonicWALL NSA2400 and a Cisco ASA5505. I am in a test lab with a simple setup:

  1. "Server" computer with IP address 192.0.99.1/24, connected to NSA2400 on its LAN interface, IP address 192.0.99.40/24
  2. NSA2400 WAN interface has IP address 205.192.0.1/24, and is connected through a switch to ASA5505 port 0 ("outside"), vlan2, IP address 205.192.0.2/24.
  3. "Client" computer with IP address 192.16.99.1/24, connected to ASA5505 port 1 ("inside"), vlan1, IP address 192.16.99.40/24.

I have never configured Cisco devices, and the reason I am playing with the ASA5505 is the the SonicWALLs are causing a problem that the Ciscos seem to resolve. So my lack of experience will certainly show in the question:

I have used the ASCM Startup Wizard to configure the "inside" and "outside" interfaces.

I have used the IPsec VPN Wizard to configure the VPN tunnel, and it does come up.

I am missing some internal routing, though, and am having trouble finding documentation on how to fix this: I need for the Client and Server computers to see each other

  1. If I ping from the Server (NSA2400) to the Client (ASA5505), it doesn't work (Request timed out), and the ASA5505 gives me the following messages:
    1. Built inbound ICMP connection for faddr 192.0.99.1/1 gaddr 192.16.99.1/0 laddr 192.16.99.1/0
    2. Teardown ICMP connection for faddr 192.0.99.1/1 gaddr 192.16.99.1/0 laddr 192.16.99.1/0
  2. If I ping from the Client to the Server, it also doesn't work, and the ASA5505 gives me the following message:
    1. Failed to locate egress interface for ICMP from inside: 192.16.99.1/1 to 192.0.99.1/0

what puzzles me is that in the "Connection profile" for the VPN, I have specified that the Local Network is the 192.16.99.0/24, and the Remote Network is the 192.0.99.0/24, which I would expect to be enough to tell the ASA5505 to associate the two. But 2.1 above seems to indicate that I am missing some routing...

configuration attached. thanks,

Pedro

Everyone's tags (2)
1 REPLY
New Member

"Failed to locate egress interface" error

Am I missing something here or the config attached is missing the VPN config??

Wishes,

Mo.

1567
Views
0
Helpful
1
Replies
CreatePlease to create content