VPN Not Completing Phase 2

Need Assistance troubleshooting Phase 2 of VPN; doesn't look like it's completing the Phase. It does state on the ASA that it completes Phase 1, but reviewing the attached screenshot (minus IPs) Phase 2 is having issues.

Direction:
Pinging Internal Network from external Firewall thru VPN (using internal network IPs)

THANKS
VPN-Log.jpg
Spt_UsAsked:
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

Craig BeckCommented:
Check the ACL which defines the subnets allowed at the local and remote end of the VPN.
0
Spt_UsAuthor Commented:
Thanks; I did that and it seems to have been the issue. i.e. I am allowing icmp, tcp, ip, udp. Question is; this is a site to site; the other side needs to access files, application and domain on this side. I do not see the 'errors; that i was seeing prior;  what's my next step. Do I need to NAT or Forward the address / vpn to a certain 'server' for this.
0
Craig BeckCommented:
If you have a site-to-site there's pure routing, so no NAT required.  If the ACL is permitting IP traffic each way you should be fine.
0
Spt_UsAuthor Commented:
Right now I am routing to .0 for networks; do I need to route to static IPs on servers since they (the site) only needs access to certain things... I appreciate the help; this has been so helpful.
0
Craig BeckCommented:
If the server at site A uses the router at site A as its default gateway, and the clients at site B use the router at site B as their default gateway it should all just work.
0

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Windows Networking

From novice to tech pro — start learning today.

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.