10-19-2010 07:24 PM
looking for some help. going batty on this one.
I have ASA 5510 running 8.3
it acts as router, firewall and vpn.
the underlying network runs fine.
when i connect via VPN I can only access my .41 network and not the .42 network. when i try to ping .42 i get this error:
5 Oct 18 2010 00:33:13 192.168.42.11 3389 Asymmetric NAT rules matched for forward and reverse flows; Connection for tcp src Outside:192.168.43.200/2916 dst servers:192.168.42.11/3389 denied due to NAT reverse path failure
if i flip these rules in config order then i can access .42 via vpn but not .41
nat (servers,any) source static any any destination static obj-vpnpool obj-vpnpool
nat (iscsimgmt,any) source static any any destination static obj-vpnpool obj-vpnpool
i'm confused because this is all a new config and i used the wizard in asdm and couldn't access squat (maybe it doesn't know how to handle vlans)?
the ASA can ping all networks fine.
devices on the network can ping each other fine
just via ipsec vpn i can't access both networks.
thoughts?
Solved! Go to Solution.
10-19-2010 08:05 PM
Please configure a more specific NAT statements as follows:
object network obj-iscsimgmt
subnet 192.168.42.0 255.255.255.0
nat (servers,Outside) source static obj-servers obj-servers destination static obj-vpnpool obj-vpnpool
nat (iscsimgmt,Outside) source static obj-iscsimgmt obj-iscsimgmt destination static obj-vpnpool obj-vpnpool
And pls remove the following:
nat (servers,any) source static any any destination static obj-vpnpool obj-vpnpool
nat (iscsimgmt,any) source static any any destination static obj-vpnpool obj-vpnpool
Then "clear xlate" after the above changes.
Hope that helps.
10-19-2010 07:57 PM
Sorry, seems like you have attached configuration from a different ASA (it's version 8.0.3 instead of 8.3.x). Also, couldn't find interfaces that's named "servers" and "iscsimgmt"
10-19-2010 07:59 PM
posted the correct one.. whoops
10-19-2010 08:05 PM
Please configure a more specific NAT statements as follows:
object network obj-iscsimgmt
subnet 192.168.42.0 255.255.255.0
nat (servers,Outside) source static obj-servers obj-servers destination static obj-vpnpool obj-vpnpool
nat (iscsimgmt,Outside) source static obj-iscsimgmt obj-iscsimgmt destination static obj-vpnpool obj-vpnpool
And pls remove the following:
nat (servers,any) source static any any destination static obj-vpnpool obj-vpnpool
nat (iscsimgmt,any) source static any any destination static obj-vpnpool obj-vpnpool
Then "clear xlate" after the above changes.
Hope that helps.
10-19-2010 08:14 PM
this worked perfectly you are the BEST!!!!!!!!!
10-19-2010 08:16 PM
Excellent stuff.. thanks for the rating.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide