Azure site-to-site VPN to Cisco ASA 5512-X issue

Hello everyone,

I configured site-to-site VPN in Azure to our Cisco ASA 5512-X. The Azure Vnet dashboard says it is connected, and shows Data Out, not in (image attached). When I attempt telnet or ping from the Azure VNet to the onprem network, there is no response. When I run Packet tracer on the ASA, it works (image attached). What might I be doing wrong here?

UPDATE: Added sanitized config
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

LA_AdminAuthor Commented:
I fixed this. For whoever needs help in the future, the issue was that the VPN script Azure generates is for the 8.3 OS. My OS is 9.1, and the nat rule generated in the script was:

nat (inside,outside) source static onprem-networks onprem-networks destination static azure-networks azure-networks

Open in new window

What was needed is at the end:

nat (inside,outside) source static onprem-networks onprem-networks destination static azure-networks azure-networks no-proxy-arp route-lookup

Open in new window

Once the correct rule was entered, ping and telnet worked.

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today

From novice to tech pro — start learning today.