Solved

Need help opening ports over Cisco site-to-site VPN

Posted on 2013-01-10
7
555 Views
Last Modified: 2013-01-10
I've got a site-to-site VPN running on a pair of Cisco 5510 firewalls.  One end is with me at my primary site and the other several miles away at a datacenter.  I'd like to find out which ports are open across the VPN and which are not prior to attempting some installs at the datacenter.  Is there an easy way to tell using the ASDM interface?  I would also need to know how to open specific ports if I find that they are closed.  Thanks in advance for any help!
0
Comment
Question by:First Last
  • 3
  • 3
7 Comments
 
LVL 21

Expert Comment

by:mcsween
Comment Utility
Log into the CLI on your firewall and post the result from the show run command issued from enable mode.  Remember to remove any sensitive information before posting.
0
 
LVL 18

Expert Comment

by:fgasimzade
Comment Utility
Ports open depend on the access-lists with interesting traffic configured. Usually all tcp/ip ports are open from local subnet to remote subnet
0
 
LVL 1

Author Comment

by:First Last
Comment Utility
Ok, that took some serious time to clean out the sensitive info but here we go, its attached here.  Thank you for helping me out!
ASA.txt
0
How to run any project with ease

Manage projects of all sizes how you want. Great for personal to-do lists, project milestones, team priorities and launch plans.
- Combine task lists, docs, spreadsheets, and chat in one
- View and edit from mobile/offline
- Cut down on emails

 
LVL 18

Accepted Solution

by:
fgasimzade earned 500 total points
Comment Utility
Do  sh run all, see if you have sysopt connectipn permit-vpn enabled. if yes then all ports are open for ipsec traffic. if no then take a look at your fios access in access lists, everything that is permitted there is permittedfor vpn
0
 
LVL 1

Author Comment

by:First Last
Comment Utility
Ok, I ran that and did find this entry:  sysopt connection permit-vpn

So I'm assuming that all the ports are open for ipsec.  Last question to bug you with...the install is for another Exchange 2010 server for redundancy.  Do you happen to know if exchange would use any ports or protocols that could be blocked even though I'm seeing that line in the config?  I ask because at one point I had some major problems with the two server communicating and wound up having to shut down the instance at the datacenter.
0
 
LVL 18

Assisted Solution

by:fgasimzade
fgasimzade earned 500 total points
Comment Utility
I remember I had problems with inspect smtp, make sure you disable it with no inspect smtp under global policy (in the end of the config)
0
 
LVL 1

Author Comment

by:First Last
Comment Utility
Thanks fgasimzade, I will give that a shot now.
0

Featured Post

How to run any project with ease

Manage projects of all sizes how you want. Great for personal to-do lists, project milestones, team priorities and launch plans.
- Combine task lists, docs, spreadsheets, and chat in one
- View and edit from mobile/offline
- Cut down on emails

Join & Write a Comment

Suggested Solutions

I recently attended Cisco Live! in Las Vegas, a conference that boasted over 28,000 techies in attendance, and a week of hands-on learning hosted by a solid partner with which Concerto goes to market.  Every year, Cisco displays cutting-edge technol…
This process describes the steps required to Import and Export data from and to .pst files using Exchange 2010. We can use these steps to export data from a user to a .pst file, import data back to the same or a different user, or even import data t…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

744 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

16 Experts available now in Live!

Get 1:1 Help Now