site-to-site tunnel not forming please help

vreddy

Junior Member
Nov 27, 2014
2
0
0
Last week we had MPLS circuit down and there was no redundancy. I have been trying to establish the IPSEC site to site vpn as the backup once the MPLS circuit goes down I can bring up the IPSEC tunnel. Since the MPLS circuit is up now. I configured on both the local and remote ASAs all the ipsec site to site configs but was not able to test it by passing the interesting traffic since all the traffic is now routing through MPLS circuit. I need to figure out what needs to be done so that I can test IPSEC tunnel by passing interesting traffic even though MPLS circuit is up. Right now the MPLS traffic is going through WAN router. I tried 192.168.1.0 subnet point to ASA's internal interface in the Core but can't generate the interesting traffic. Getting ping request timeout.
Here's the config for Local ASA
object network NETWORK_OBJ_10.1.14.0_24
subnet 10.1.14.0 255.255.255.0

object network NETWORK_OBJ_192.168.1.0_24
subnet 192.168.1.0 255.255.255.0

nat (Inside,Outside) source static NETWORK_OBJ_10.1.14.0_24 NETWORK_OBJ_10.1.14.0_24 destination static NETWORK_OBJ_192.168.1.0_24 NETWORK_OBJ_192.168.1.0_24 no-proxy-arp route-lookup

crypto ipsec ikev1 transform-set MySet esp-3des esp-md5-hmac

crypto ikev1 enable Outside
crypto ikev1 policy 120
authentication pre-share
encryption 3des
hash sha
group 2
lifetime 86400

tunnel-group x.x.x.x type ipsec-l2l
tunnel-group x.x.x.x ipsec-attributes
ikev1 pre-shared-key *****

access-list VPN_ALLOWED_ACCESS extended permit ip 10.1.14.0 255.255.255.0 192.168.1.0 255.255.255.0
access-list VPN_ALLOWED_ACCESS extended permit icmp 10.1.14.0 255.255.255.0 192.168.1.0 255.255.255.0

crypto map Outside_map 2 match address VPN_ALLOWED_ACCESS
crypto map Outside_map 2 set peer x.x.x.x
crypto map Outside_map 2 set ikev1 transform-set MySet
crypto map Outside_map interface Outside

-------------------------------------------------
Remote ASA config:
object network obj-10.1.14.0
subnet 10.1.14.0 255.255.255.0


object network obj-192.168.1.0
subnet 192.168.1.0 255.255.255.0

nat (MFG,outside) source static obj-192.168.1.0 obj-192.168.1.0 destination static obj-10.1.14.0 obj-10.1.14.0 no-proxy-arp route-lookup
crypto ipsec ikev1 transform-set MySet esp-3des esp-md5-hmac
crypto ikev1 enable outside

crypto ikev1 policy 10
authentication pre-share
encryption 3des
hash sha
group 2
lifetime 86400

tunnel-group x.x.x.x type ipsec-l2l
tunnel-group x.x.x.x ipsec-attributes
ikev1 pre-shared-key *****

access-list outside_cryptomap extended permit ip 192.168.1.0 255.255.255.0 10.1.14.0 255.255.255.0
access-list outside_cryptomap extended permit icmp 192.168.1.0 255.255.255.0 10.1.14.0 255.255.255.0

crypto map External_map 2 match address outside_cryptomap
crypto map External_map 2 set peer 8.29.106.10
crypto map External_map 2 set ikev1 transform-set MySet

crypto map External_map interface outside
This is the config I put on both ASAs . Right now both are reaching each other through MPLS circuit.
Can I bring the tunnel up even though MPLS circuit is up and running.
Any advice would be really appreciated.
 

cheap5.0

Member
Jan 9, 2010
92
0
0
You would be better off taking this to experts-exchange.com or cisco support forums. Not that someone here is incapable of figuring this out, I think you would have a better chance over there.
 

lif_andi

Member
Apr 15, 2013
173
0
0
I am not aware of any way to test this without directing traffic through the tunnel. You could include a new IP range in the access-lists and direct that traffic through to see if the tunnel forms, but otherwise, traffic will always follow the rules and go through the MPLS path as that is more preferred.
 
Last edited:

drebo

Diamond Member
Feb 24, 2006
7,034
1
81
It looks like you haven't excluded the VPN interesting traffic from your NAT on each direction...unless you just didn't copy that line in.
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |