|
|
Re: [cisco-ttl] ASA vpn client problem
From: Serhat Uslay <serhat.uslay_at_....>
Date: Tue Oct 17 2006 - 08:48:47 EEST
Bu tam cikti degil herhalde, bir suru sey eksik gibi gozuluyor. Iki tane
local pool var 192.168.1.0 ve 192.168.70.0 Ama sadece pool "gezi "
tanimlanmis. Ama bu "gezi" tunnel-group icinde tanimlanmamis onun yerine
"POOLVPN" diye bir sey var.
Soyle bir ornek yapman gerekiyor ;
Birde access-list 15 hic bir yere uygulanmamis. Tam ciktiyi yollarsan tekrar bakabilirim. Serhat
TOLGA SAHAN CELTIK <t_celtik@yahoo.com>
Sent by: cisco-ttl@yahoogroups.com
To
Subject
Merhaba,
Bizim taraf-----internet---------Checpoint-----ASA-----Lokal VPN clientla baglandigim zaman hicbir paketin encrypt edilmedigini ayrica secured network un 0.0.0.0 0.0.0.0 seklinde oldugunu goruyorum.Confıg te hıc bır problem gormezken...neden oluyor, yardimci olursaniz sevinirim.. Config ekte
ASA Version 7.0(2)
ftp mode passive
access-list inside_nat0_outbound extended permit ip any 192.168.1.0
255.255.255.0
group-policy deneme internal
username tolga password 5mhYTi9IjTkulMAX encrypted privilege 0
aaa authentication ssh console LOCAL
no snmp-server location
crypto ipsec transform-set TOLGA esp-3des esp-none
crypto ipsec transform-set ESP-3DES-SHA esp-3des esp-sha-hmac
crypto dynamic-map outside_dyn_map 20 match address
outside_cryptomap_dyn_20
ssh 172.19.0.91 255.255.255.255 outside ssh 172.19.0.71 255.255.255.255 outside ssh 172.19.0.61 255.255.255.255 outside ssh 172.19.0.78 255.255.255.255 outside ssh 172.19.0.212 255.255.255.255 outsidessh 172.19.0.243 255.255.255.255 outside ssh 172.19.60.170 255.255.255.255 outside ssh timeout 5 console time deneme type ipsec-ra tunnel-group deneme general-attributes default-group-policy deneme tunnel-group deneme ipsec-attributes pre-shared-key * tunnel-group deneme1 type ipsec-ra tunnel-group deneme1 general-attributes address-pool POOLVPN default-group-policy deneme1 tunnel-group deneme1 ipsec-attributes pre-shared-key * [Non-text portions of this message have been removed] -- Cisco Teknik Tartisma Listesi (Cisco-ttl) Bu listede onerilen degisikliklerin uygulanmasindaki tum sorumluluk kullaniciya aittir. Liste yoneticileri, oneride bulunan liste uyeleri ya da bu uyelerin calistigi kuruluslar herhangi bir sekilde sorumlu tutulamazlar. Yahoo! Groups Links ---- This email is intended for the named recipient only. It may contain information which is confidential, commercially sensitive, or copyright. If you are not the intended recipient you must not reproduce or distribute any part of the email, disclose its contents, or take any action in reliance. If you have received this email in error, please contact the sender and delete the message. It is your responsibility to scan this email and any attachments for viruses and other defects. To the extent permitted by law, Zurich and its associates will not be liable for any loss or damage arising in any way from this communication including any file attachments. We may monitor email you send to us, either as a reply to this email or any email you send to us, to confirm our systems are protected and for compliance with company policies. Although we take reasonable precautions to protect the confidentiality of our email systems, we do not warrant the confidentiality or security of email or attachments we receive. [Non-text portions of this message have been removed] -- Cisco Teknik Tartisma Listesi (Cisco-ttl) Bu listede onerilen degisikliklerin uygulanmasindaki tum sorumluluk kullaniciya aittir. Liste yoneticileri, oneride bulunan liste uyeleri ya da bu uyelerin calistigi kuruluslar herhangi bir sekilde sorumlu tutulamazlar. Yahoo! Groups LinksReceived on Tue Oct 17 12:54:07 2006 This archive was generated by hypermail 2.1.8 : Tue Oct 17 2006 - 12:54:07 EEST |