Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
CheckPointerXL
Advisor
Advisor

VPN with ASA - Smaller subnets are negotiated on Phase 2 - No working traffic

Hi all,

i tried to bring up a ikev1 tunnel with a ASA but no luck.

Essentially, the encryption domain is:

Local: 172.16.0.0/12   Remote: 192.168.151.0/24

but after the tunnel is established there is no traffic and this is likely the main reason:

 

 

asa2.JPG

basically it seems the opposite problem about the famous supernetting

 

any suggestion?

R81.10 take110

thanks

0 Kudos
6 Replies
Bob_Zimmerman
Authority
Authority

What does an IKE debug say? That's the final word in which side is doing the wrong thing.

0 Kudos
CheckPointerXL
Advisor
Advisor

it says that CP is going to propose the smaller subnet....

i already saw this behavoir in other deployment with asa

 

sorry forgot to mention R81.10 take110

 
0 Kudos
the_rock
Legend
Legend

set below values to FALSE in guidbedit, push policy -> test

Andy

 

ike_enable_supernet

ike_p2_enable_supernet_from_R80.20

ike_use_largest_possible_subnets

 

 

0 Kudos
CaseyB
Advisor

0 Kudos
the_rock
Legend
Legend

I seen that sk before...its good reference, for sure, though I never had that sort of problem with any customer.

Andy

0 Kudos
CheckPointerXL
Advisor
Advisor

sounds good... i will investigate, already seen that sk but not considered until now....ty

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events