Site to Site VPN . Cant Connect To Inside Router Interfaces

Site to Site VPN . Cant Connect To Inside Router Interfaces

NewsGroups | Search | Tools
 comp.dcom.sys.cisco  Post an article  get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content  add this group's latest topics to your Google content  YahooMyWeb Yahoo!  Google Google  Windows Live Favorites Windows Live  del.icio.us del.icio.us  digg digg  Add to Netscape Netscape
Subject Author Date
Site to Site VPN . Cant Connect To Inside Router Interfaces GNY 08-05-2007
Posted by GNY on August 5, 2007, 11:24 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Hello..

I have a lan to lan tunnel between 2 sites. Lets say the internal
networks are 10.10.70.0/24 and 10.10.80.0/24. All hosts on each side
can talk, ping, connect and everything with one another. However I
cant get the router inside interfaces where each lan lives.

So from a host on 10.10.70.0/24 I can't get to 10.10.80.1 .. and vice
versa (10.10.80.0/24 --> 10.10.70.1).. These are both ASA devices. I'm
thinking this has to do directly with the ASA interface security, but
i cant figure it out.

All NAT rules, and IP traffic is allowed between these LANs. There
shouldnt be any reason, but again I think it has to do with security.
Any help is appreciated!

GNY


Posted by Chris on August 5, 2007, 2:56 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
On Sun, 05 Aug 2007 15:24:02 -0000, GNY wrote:

> Hello..
>
> I have a lan to lan tunnel between 2 sites. Lets say the internal
> networks are 10.10.70.0/24 and 10.10.80.0/24. All hosts on each side
> can talk, ping, connect and everything with one another. However I
> cant get the router inside interfaces where each lan lives.
>
> So from a host on 10.10.70.0/24 I can't get to 10.10.80.1 .. and vice
> versa (10.10.80.0/24 --> 10.10.70.1).. These are both ASA devices. I'm
> thinking this has to do directly with the ASA interface security, but
> i cant figure it out.
>
> All NAT rules, and IP traffic is allowed between these LANs. There
> shouldnt be any reason, but again I think it has to do with security.
> Any help is appreciated!
>
> GNY

This is quite normal with Pix/ASA. Traffic that enters on interface must
exit another and so you won't be able to access the LAN interface on the
remote device as that would require hairpinning the traffic which the ASA
will not do. It't the same reason that with a Pix/ASA on the LAN, you can
ping the LAN interface (nearest to you) but not the WAN interface.

Chris.

Posted by Merv on August 5, 2007, 3:31 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Have a peek at:

PIX/ASA 7.x: SSH/Telnet on the Inside and Outside Interface
Configuration Example

http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a008069bf1b.shtml


Posted by GNY on August 5, 2007, 3:44 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
> Have a peek at:
>
> PIX/ASA 7.x: SSH/Telnet on the Inside and Outside Interface
> Configuration Example
>
> http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_config...

Merv,

I have all of this configured and worked up already. The problem is
what Chris pointed out.


Posted by GNY on August 5, 2007, 3:43 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
> On Sun, 05 Aug 2007 15:24:02 -0000, GNY wrote:
> > Hello..
>
> > I have a lan to lan tunnel between 2 sites. Lets say the internal
> > networks are 10.10.70.0/24 and 10.10.80.0/24. All hosts on each side
> > can talk, ping, connect and everything with one another. However I
> > cant get the router inside interfaces where each lan lives.
>
> > So from a host on 10.10.70.0/24 I can't get to 10.10.80.1 .. and vice
> > versa (10.10.80.0/24 --> 10.10.70.1).. These are both ASA devices. I'm
> > thinking this has to do directly with the ASA interface security, but
> > i cant figure it out.
>
> > All NAT rules, and IP traffic is allowed between these LANs. There
> > shouldnt be any reason, but again I think it has to do with security.
> > Any help is appreciated!
>
> > GNY
>
> This is quite normal with Pix/ASA. Traffic that enters on interface must
> exit another and so you won't be able to access the LAN interface on the
> remote device as that would require hairpinning the traffic which the ASA
> will not do. It't the same reason that with a Pix/ASA on the LAN, you can
> ping the LAN interface (nearest to you) but not the WAN interface.
>
> Chris.

Chris,

Good to see you again :-)

Thanks for the info.. I guess I'm out of luck then. I was hoping to
store some configs using tftp on a server on the other side of the
tunnel from the client box. So I guess I'll have to store them locally
on a server or allow the tftp traffic from the client to the outside
interface and dump it over the outside interface on the remote side
also (Static NAT)... Yuck!

See any other solutions?

Thanks again Chris!

GNY


Similar ThreadsPosted
831 connect to secondary site in the event of primary site failure August 6, 2004, 7:54 am
Site to Site VPN routing - Cisco 1841 to Nortel VPN Router 1010 September 21, 2007, 1:46 pm
Site to Site VPN error on Cisco ASA5500 and router 1800 January 4, 2008, 1:55 pm
Site to Site VPN Issues w/ Cisco Router/NAT - I'm 90% of the way there. :) June 23, 2006, 1:43 pm
Cisco ASA 5500 to Router site to site VPN November 11, 2008, 11:57 am
Allow vpn client down a site to site tunnel from router A to router B July 29, 2008, 3:23 pm
IPSEC: reserved not zero on payload message when connecting site-to-site October 13, 2005, 12:29 am
Vpn site to site + vpn cisco client access list problem. August 7, 2006, 10:35 am
Site-to-site tunnel w/NAT, return packets decap but not routed? December 13, 2006, 7:52 pm
I want to create Site to Site VPN with Cisco PIX501 and Linksys RV082 September 10, 2007, 3:46 am

other useful resources:
The Federal Communications Commission (FCC)
Telecommunications Industry Association
Electronic and Software Security Products and Services
International Telecommunication Union

Custom CGI Perl and PHP programming by 1-Script.com

Contact Us | Privacy Policy
The site map in XML format XML site map