Hi!
I've been playing with Cisco ASA 5505 for 2 weeks now. I've been trying to set up an VPN remote connection to my friend without no luck. First I wasn't even able to make the connection. Now the connection happens, and I can get IP address for my friend's remote computer, but the remote machine doesn't get Default gateway settings. Also it's netmask is 255.255.255.255.
Because of this, I think, it's impossible to get the remote computer access my network. How can I fix this with ASDM interface? I'm using ASDM ver 6.2. The chart how to connect is as follow:
Local network
Internet access via ppoe - Cisco - local lan computers
Remote network
Internet access on windows machine.
Connection able to establish: L2TP, MS Chap V2, IPsec: AES 128, compression (none) PPP multilink framing Off, Client IP comes fine from Cisco, Server IP is my internet IP address, NAP State not capable.
The remote computer gets connection but IPv4 shows no internet access and on IPv6 row there's mention no network access. (on window's connection status, general page).
Also, it shows on remote computer that no DHCP is enabled, altough the ip address is gotten from ciscos IP pool for VPN conenction. NetBIOS is enabled. I have also forced DNS servers to these I use to connect internet. Wonder if this is ok. Remote VPN connections are only intented to access my local area network, they still would use internet by their own internet connection.
Do I need to add a static route of some kind? How can I have Default Gateway pushed to the remote client? My Cisco server ip in lan is 192.168.1.1 and remote gets ip 192.168.1.90 (to 99). My local network is under DHCP and gets ip from 192.168.1.2 (to 10). My internet connection is configured by ppoe for internet default gateway and dns servers and ip address.
Also, what's the deal here that I cannot use other than 3DES or AES-128 with windows built-in client (have not tried any other either). And if I disable 3DES, I cannot even establish the VPN connection. :)
thanks!
ASA Version 8.2(1)
!
hostname ciscoasa
names
name 192.168.1.2 A-192.168.1.2 description palvelin
!
interface Vlan1
nameif inside
security-level 100
ip address 192.168.1.1 255.255.255.0
!
interface Vlan2
nameif outside
security-level 0
pppoe client vpdn group PSOAS
ip address pppoe setroute
!
interface Ethernet0/0
switchport access vlan 2
!
interface Ethernet0/1
!
interface Ethernet0/2
!
interface Ethernet0/3
!
interface Ethernet0/4
!
interface Ethernet0/5
!
interface Ethernet0/6
!
interface Ethernet0/7
!
boot system disk0:/asa821-k8.bin
ftp mode passive
clock timezone EEST 2
clock summer-time EEDT recurring last Sun Mar 3:00 last Sun Oct 4:00
dns domain-lookup inside
dns domain-lookup outside
dns server-group DefaultDNS
name-server 62.241.198.245
name-server 62.241.195.246
domain-name palvelin.dyndns.info
access-list inside_nat0_outbound extended permit ip 192.168.1.0 255.255.255.0 192.168.1.32 255.255.255.224
access-list DefaultRAGroup_splitTunnelAcl standard permit 192.168.1.0 255.255.255.0
pager lines 24
logging enable
logging console errors
logging monitor errors
logging buffered errors
logging asdm errors
mtu inside 1500
mtu outside 1500
ip local pool VPN 192.168.1.50-192.168.1.99 mask 255.255.255.0
icmp unreachable rate-limit 1 burst-size 1
asdm image disk0:/asdm-621.bin
no asdm history enable
arp timeout 14400
global (outside) 1 interface
nat (inside) 0 access-list inside_nat0_outbound
nat (inside) 1 0.0.0.0 0.0.0.0
route outside 0.0.0.0 0.0.0.0 192.168.1.1 tunneled
timeout xlate 3:00:00
timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02
timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00
timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00
timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute
timeout tcp-proxy-reassembly 0:01:00
dynamic-access-policy-record DfltAccessPolicy
http server enable
http 192.168.1.0 255.255.255.0 inside
no snmp-server location
no snmp-server contact
snmp-server enable traps snmp authentication linkup linkdown coldstart
crypto ipsec transform-set ESP-AES-256-MD5 esp-aes-256 esp-md5-hmac
crypto ipsec transform-set ESP-DES-SHA esp-des esp-sha-hmac
crypto ipsec transform-set ESP-3DES-SHA esp-3des esp-sha-hmac
crypto ipsec transform-set ESP-DES-MD5 esp-des esp-md5-hmac
crypto ipsec transform-set ESP-AES-192-MD5 esp-aes-192 esp-md5-hmac
crypto ipsec transform-set ESP-3DES-MD5 esp-3des esp-md5-hmac
crypto ipsec transform-set ESP-AES-256-SHA esp-aes-256 esp-sha-hmac
crypto ipsec transform-set ESP-AES-128-SHA esp-aes esp-sha-hmac
crypto ipsec transform-set ESP-AES-192-SHA esp-aes-192 esp-sha-hmac
crypto ipsec transform-set ESP-AES-128-MD5 esp-aes esp-md5-hmac
crypto ipsec transform-set TRANS_ESP_AES-128-SHA esp-aes esp-sha-hmac
crypto ipsec transform-set TRANS_ESP_AES-128-SHA mode transport
crypto ipsec transform-set TRANS_ESP_AES-192-SHA esp-aes-192 esp-sha-hmac
crypto ipsec transform-set TRANS_ESP_AES-192-SHA mode transport
crypto ipsec transform-set TRANS_ESP_AES-256-SHA esp-aes-256 esp-sha-hmac
crypto ipsec transform-set TRANS_ESP_AES-256-SHA mode transport
crypto ipsec transform-set TRANS_ESP_3DES_SHA esp-3des esp-sha-hmac
crypto ipsec transform-set TRANS_ESP_3DES_SHA mode transport
crypto ipsec security-association lifetime seconds 28800
crypto ipsec security-association lifetime kilobytes 4608000
crypto dynamic-map SYSTEM_DEFAULT_CRYPTO_MAP 65535 set transform-set ESP-AES-256-SHA ESP-AES-192-SHA ESP-AES-128-SHA TRANS_ESP_AES-256-SHA TRANS_ESP_AES-192-SHA TRANS_ESP_AES-128-SHA ESP-3DES-SHA TRANS_ESP_3DES_SHA
crypto map outside_map 65535 ipsec-isakmp dynamic SYSTEM_DEFAULT_CRYPTO_MAP
crypto map outside_map interface outside
crypto map inside_map 65535 ipsec-isakmp dynamic SYSTEM_DEFAULT_CRYPTO_MAP
crypto map inside_map interface inside
crypto ca trustpoint ASDM_TrustPoint0
enrollment self
subject-name CN=palvelin,C=fi
proxy-ldc-issuer
crl configure
crypto ca certificate chain ASDM_TrustPoint0
crypto isakmp enable inside
crypto isakmp enable outside
crypto isakmp policy 10
authentication pre-share
encryption aes-256
hash sha
group 5
lifetime 86400
crypto isakmp policy 20
authentication pre-share
encryption aes-192
hash sha
group 5
lifetime 86400
crypto isakmp policy 30
authentication pre-share
encryption aes
hash sha
group 5
lifetime 86400
crypto isakmp policy 40
authentication pre-share
encryption 3des
hash sha
group 2
lifetime 86400
vpn-addr-assign local reuse-delay 5
telnet timeout 5
ssh timeout 5
console timeout 0
vpdn group PSOAS request dialout pppoe
vpdn group PSOAS localname exxx
vpdn group PSOAS ppp authentication pap
vpdn username exxx password ********* store-local
dhcpd address A-192.168.1.2-192.168.1.10 inside
dhcpd auto_config outside interface inside
dhcpd enable inside
!
threat-detection basic-threat
threat-detection statistics port
threat-detection statistics protocol
threat-detection statistics access-list
threat-detection statistics tcp-intercept rate-interval 30 burst-rate 400 average-rate 200
ssl encryption 3des-sha1 aes128-sha1 aes256-sha1
webvpn
enable outside
csd image disk0:/securedesktop-asa-3.2.1.126-k9.pkg
group-policy DefaultRAGroup internal
group-policy DefaultRAGroup attributes
dns-server value 62.241.198.245 62.241.195.246
vpn-idle-timeout 86400
vpn-tunnel-protocol l2tp-ipsec svc webvpn
split-tunnel-policy tunnelspecified
split-tunnel-network-list value DefaultRAGroup_splitTunnelAcl
username jani password xxx
username jani attributes
vpn-framed-ip-address 192.168.1.90 255.255.255.0
service-type remote-access
tunnel-group DefaultRAGroup general-attributes
address-pool VPN
default-group-policy DefaultRAGroup
tunnel-group DefaultRAGroup ipsec-attributes
pre-shared-key *
tunnel-group DefaultRAGroup ppp-attributes
no authentication chap
no authentication ms-chap-v1
authentication ms-chap-v2
!
class-map inspection_default
match default-inspection-traffic
!
!
policy-map type inspect dns preset_dns_map
parameters
message-length maximum 512
policy-map global_policy
class inspection_default
inspect dns preset_dns_map
inspect ftp
inspect h323 h225
inspect h323 ras
inspect rsh
inspect rtsp
inspect esmtp
inspect sqlnet
inspect skinny
inspect sunrpc
inspect xdmcp
inspect sip
inspect netbios
inspect tftp
!
service-policy global_policy global
prompt hostname context
Cryptochecksum:fdb9d4b57bf455147afe6bd2544525c2
: end
asdm image disk0:/asdm-621.bin
asdm location A-192.168.1.2 255.255.255.255 inside
no asdm history enable
1:
2:
3:
4:
5:
6:
7:
8:
9:
10:
11:
12:
13:
14:
15:
16:
17:
18:
19:
20:
21:
22:
23:
24:
25:
26:
27:
28:
29:
30:
31:
32:
33:
34:
35:
36:
37:
38:
39:
40:
41:
42:
43:
44:
45:
46:
47:
48:
49:
50:
51:
52:
53:
54:
55:
56:
57:
58:
59:
60:
61:
62:
63:
64:
65:
66:
67:
68:
69:
70:
71:
72:
73:
74:
75:
76:
77:
78:
79:
80:
81:
82:
83:
84:
85:
86:
87:
88:
89:
90:
91:
92:
93:
94:
95:
96:
97:
98:
99:
100:
101:
102:
103:
104:
105:
106:
107:
108:
109:
110:
111:
112:
113:
114:
115:
116:
117:
118:
119:
120:
121:
122:
123:
124:
125:
126:
127:
128:
129:
130:
131:
132:
133:
134:
135:
136:
137:
138:
139:
140:
141:
142:
143:
144:
145:
146:
147:
148:
149:
150:
151:
152:
153:
154:
155:
156:
157:
158:
159:
160:
161:
162:
163:
164:
165:
166:
167:
168:
169:
170:
171:
172:
173:
174:
175:
176:
177:
178:
179:
180:
181:
182:
183:
184:
185:
186:
187:
188:
189:
190:
191:
192:
193:
194:
195:
196:
197:
198:
199:
200:
201:
202:
203:
204:
205:
206:
Select allOpen in new window
by: ccie22921Posted on 2009-08-19 at 13:54:43ID: 25137237
Your NAT 0 statement is incorrect in that the ACL in use is incorrect. CHange it to the following:
/products/ ps6120/ pro ducts_conf iguration_ example091 86a0080702 992.shtml
access-list inside_nat0_outbound extended permit ip 192.168.1.0 255.255.255.0 192.168.1.90 255.255.255.240
What is happening is that your remote end is being NAT'd using the NAT configuration
Also, ensure that you expose your inside network to your VPN during your VPN setup under the ASDM.
http://www.cisco.com/en/US