?
Solved

Remote end of ipsec tunnel not responding

Posted on 2014-10-29
6
Medium Priority
?
490 Views
Last Modified: 2014-10-30
Hi

I have just setup an ipsec tunnel between and Mikrotik RB951G and a Cisco ASA 5505
using SHA hash algo and 3DES encryption

I followed the following presentation: http://wiki.mikrotik.com/wiki/MikroTik_router_to_CISCO_PIX_Firewall_IPSEC

The tunnel seems to be up, I have SAs for both directions, though only one has current bytes (RB => Cisco) and the info appearing in the ipsec log seems pretty positive

I have pinged a host that is present on the remote LAN, but get I no response, it just times'out

What I can't figure out is how do my packets know how to get to the remote LAN ?
I haven't created a explicit route; only the ipsec policy knows of the association between our two LANs
I don't know how I would create such a route because I don't have an 'ipsec' interface to point to

any ideas
thanks
yann
0
Comment
Question by:Yann Shukor
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 2
6 Comments
 
LVL 18

Expert Comment

by:Akinsd
ID: 40412592
I think you just answered your own question.

Check your routes, NAT and ACL settings.
Usually, traffic destined for VPN need to be excluded from NAT
A traceroute or packet-trace on the ASA will show you the path the traffic is taking
0
 

Author Comment

by:Yann Shukor
ID: 40412594
I indeed have a rule which excludes traffic between the two LANs from being NATed
Traceroute from my end (Mikrotik) doesn't get any further than the router
0
 
LVL 18

Assisted Solution

by:Akinsd
Akinsd earned 750 total points
ID: 40412607
Traceroute from my end (Mikrotik) doesn't get any further than the router
A set of  asterixs (***********) would mean the traffic is blocked (ACL issue)
A destination unreachable would indicate the router doesn't know where to send the traffic (Route issue)
ICMP Traffic (especially a traceroute - type 8) through VPN would not display past the VPN entry point (meaning your setup is correct, but the ASA is not responding).

If Mikrltiks have packet-trace feature, then try that or have the engineer on the other end run a detailed packet-trace from the ASA
0
Optimum High-Definition Video Viewing and Control

The ATEN VM0404HA 4x4 4K HDMI Matrix Switch supports 4K resolutions of UHD (3840 x 2160) and DCI (4096 x 2160) with refresh rates of 30 Hz (4:4:4) and 60 Hz (4:2:0). It is ideal for applications where the routing of 4K digital signals is required.

 

Author Comment

by:Yann Shukor
ID: 40412635
I'll have to wait till my customer is present to check whether his LAN knows how to reach my LAN

The question remains though: how do I create a route to my client's LAN ?
I can't point it at an IPSEC interface, because there isn't one
I tried to point it at my router's WAN IP address but that didn't work: unreachable, then at my routers WAN interface : but the pings still don't get any responses
0
 
LVL 57

Accepted Solution

by:
Pete Long earned 750 total points
ID: 40412727
As pointed out sounds more like a phase 2 problem, if you have esablished SA, and can see bytes moving, then usually one of the sections (bytes encaps or decaps) will be at Zero. this points you to the physical location of the problem, see Troubleshooting Phase 2 Cisco Site to Site (L2L) VPN Tunnels

P
0
 

Author Closing Comment

by:Yann Shukor
ID: 40412868
In fact it was my Orange Livebox which was preventing the VPN
from functionning correctly (even with rule allowing port 500
and 4500)  
I used my other WAN uplink (which uses another router) and
the VPN hooked up straight away allowing my pings through
0

Featured Post

WatchGuard's M Series Appliances - Miecom Approved

WatchGuard's newest M series appliances were put to the test by Miercom.  We had great results and outperformed all of our competitors in both stateless and stateful traffic throghput scenarios! Ready to see how your UTM appliance stacked up? Download the Miercom Report!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Shadow IT is coming out of the shadows as more businesses are choosing cloud-based applications. It is now a multi-cloud world for most organizations. Simultaneously, most businesses have yet to consolidate with one cloud provider or define an offic…
This article explains the fundamentals of industrial networking which ultimately is the backbone network which is providing communications for process devices like robots and other not so interesting stuff.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
As a trusted technology advisor to your customers you are likely getting the daily question of, ‘should I put this in the cloud?’ As customer demands for cloud services increases, companies will see a shift from traditional buying patterns to new…
Suggested Courses

764 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question