Site to site VPN not working ASA 5505 8.42

Posted on 2012-08-30
Last Modified: 2012-10-25
Hello all,

I have 2 Cisco ASA 5505's running 8.42. Both have a public IP on the outside port, and a /24 lan on the inside port.

I want a site to site VPN between them, but i cant get it to work. I used the guide at, but still it does not work. I found this question:

I have a rule for nat exemption (make by the site to site wizard), but still the tunnel won't come up.

What am I doing wrong?

ASA# show run object
object network obj_any
object network locallan
object network remotelan

ASA# show run nat
nat (inside,outside) source static Locallan locallan destination static remotelan remotelan no-proxy-arp route-lookup
object network obj_any
 nat (inside,outside) dynamic interface
Question by:eensolution
    LVL 35

    Expert Comment

    by:Ernie Beek
    Anything showing in the logs when you're trying to establish the tunnel?
    LVL 18

    Expert Comment

    Can you show your full sanitized config?
    LVL 57

    Expert Comment

    by:Pete Long
    what's the result of a

    show cry isa command and a show cry ipsec sa command?


    Author Comment

    Apologies, it already works. Problem is that I was pinging the other ASA to initiate the VPN, but the ASA blocked ICMP. When pinging a host on the other side, the tunnel came up fine.

    I have another question though. The situation is that one ASA is at the customers office, and the other one is in a datacenter. The VPN tunnel is between them. That works now.

    Also, I forwarded ports (static nat) 25/80/443/3389 on the outside IP address to one of the servers. But, how do I forward ports from another public IP to another server in the network. How do I make the ASA listen on another public IP address?
    LVL 35

    Expert Comment

    by:Ernie Beek
    The same way as you did with the address on the interface, only now you use another public IP for that. I assume you have multiple publics?
    LVL 35

    Accepted Solution

    So something like:

    object network obj-
    nat (inside,outside) static service tcp www www

    Featured Post

    How your wiki can always stay up-to-date

    Quip doubles as a “living” wiki and a project management tool that evolves with your organization. As you finish projects in Quip, the work remains, easily accessible to all team members, new and old.
    - Increase transparency
    - Onboard new hires faster
    - Access from mobile/offline

    Join & Write a Comment

    If you have an ASA5510 then this sort of thing would be better handled with a CSC Module, however on an ASA5505 thats not an option, and if you want to throw in a quick solution to stop your staff going to facebook during work time, then this is the…
    From Cisco ASA version 8.3, the Network Address Translation (NAT) configuration has been completely redesigned and it may be helpful to have the syntax configuration for both at a glance. You may as well want to read official Cisco published AS…
    Internet Business Fax to Email Made Easy - With eFax Corporate (, you'll receive a dedicated online fax number, which is used the same way as a typical analog fax number. You'll receive secure faxes in your email, fr…
    Access reports are powerful and flexible. Learn how to create a query and then a grouped report using the wizard. Modify the report design after the wizard is done to make it look better. There will be another video to explain how to put the final p…

    733 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    23 Experts available now in Live!

    Get 1:1 Help Now