Solved

Cannot get Dynamic L2L tunnel working with 2 x Cisco ASA 5505

Posted on 2013-01-15
2
627 Views
Last Modified: 2013-01-17
I have a main location with a static IP + ASA 5505, and a second location with a dynamic IP + ASA 5505. I have never done a dynamic tunnel before, so im not sure what i missed. Attached are the scrubbed configs - thx for the help.
Note: There is an IP phone on the Dynamic side that connects to the main office phone system. Now, eventhough the VPN Tunnel is not up, it ONLY works when plugged into the LAN @ the corporate office, OR on the remote network behind the ASA - it will not work from any other internet connection - and im absolutely positive it's connecting via LAN IP and not Public IP, which is strange.
ASA-Corp-office--static-IP-.txt
0
Comment
Question by:mhdcommunications
2 Comments
 
LVL 15

Accepted Solution

by:
max_the_king earned 500 total points
ID: 38786885
Hi,

you need to add the following:

access-list l2l-vpn extended permit ip 192.168.10.0 255.255.255.0 192.168.20.0 255.255.255.0

crypto map dyn-map 10 match address l2l-vpn

on the other side of the tunnel you need to do the "reverse" implementation (assuming your naming convention on vpn config is mirrored, otherwise change accordingly):

access-list l2l-vpn extended permit ip 192.168.20.0 255.255.255.0 192.168.10.0 255.255.255.0

hope this helps
max
crypto map dyn-map 10 match address l2l-vpn
0
 
LVL 1

Author Closing Comment

by:mhdcommunications
ID: 38790456
Also
crypto isakmp enable outside
Thx.
0

Featured Post

Efficient way to get backups off site to Azure

This user guide provides instructions on how to deploy and configure both a StoneFly Scale Out NAS Enterprise Cloud Drive virtual machine and Veeam Cloud Connect in the Microsoft Azure Cloud.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Shoretel QoS Configuration on Cisco Switches 9 43
Move configuration from Cisco 3560 to 3750X 6 43
Static Route 22 48
Cisco ACS 5.4 "management" proc stuck in Restarting 2 40
If you have an ASA5510 then this sort of thing would be better handled with a CSC Module, however on an ASA5505 thats not an option, and if you want to throw in a quick solution to stop your staff going to facebook during work time, then this is the…
Quality of Service (QoS) options are nearly endless when it comes to networks today. This article is merely one example of how it can be handled in a hub-n-spoke design using a 3-tier configuration.
As a trusted technology advisor to your customers you are likely getting the daily question of, ‘should I put this in the cloud?’ As customer demands for cloud services increases, companies will see a shift from traditional buying patterns to new…
Both in life and business – not all partnerships are created equal. Spend 30 short minutes with us to learn:   • Key questions to ask when considering a partnership to accelerate your business into the cloud • Pitfalls and mistakes other partners…

863 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

21 Experts available now in Live!

Get 1:1 Help Now