ho una VPN Site-to-Site che funziona in un solo senso, remote verso centro, cioé la VPN va su, e VNC funziona.
Nell'altra direzione non funziona, ed il ping non va in nessuna delle due direzioni.
IMHO, ci dev'essere qualcosa che non va nell'asa di centro stella, perché se pingo dalla lan remota un host della lan centrale o viceversa ottengo:
Codice: Seleziona tutto
No translation group found for icmp src inside:IP_ON_CENTRAL_LAN dst inside:IP_ON_REMOTE_LAN (type 8, code 0)
Codice: Seleziona tutto
access-list inside_nat0_outbound extended permit ip LocalLAN 255.255.255.0 RemoteLAN 255.255.255.0
access-list inside_nat0_outbound extended permit icmp LocalLAN 255.255.255.0 RemoteLAN 255.255.255.0
access-list outside_1_cryptomap extended permit ip LocalLAN 255.255.255.0 RemoteLAN 255.255.255.0
access-list outside_1_cryptomap extended permit icmp LocalLAN 255.255.255.0 RemoteLAN 255.255.255.0
nat (inside) 0 access-list inside_nat0_outbound
nat (inside) 0 access-list inside_nat0_outbound outside
crypto map outside_map 1 match address outside_1_cryptomap
crypto map outside_map 1 set peer IP_PUBBLICO_REMOTO
Codice: Seleziona tutto
access-list inside_outbound_nat0_acl permit ip LanRemote 255.255.255.0 LanCentral 255.255.255.0
access-list inside_outbound_nat0_acl permit icmp LanRemote 255.255.255.0 LanCentral 255.255.255.0
access-list outside_cryptomap_20 permit ip LanRemote 255.255.255.0 LanCentral 255.255.255.0
access-list outside_cryptomap_20 permit icmp LanRemote 255.255.255.0 LanCentral 255.255.255.0
nat (inside) 0 access-list inside_outbound_nat0_acl
crypto map outside_map 20 ipsec-isakmp
crypto map outside_map 20 match address outside_cryptomap_20
crypto map outside_map 20 set peer IP_PUBBLICO_CENTRO
crypto map outside_map 20 set transform-set ESP-3DES-MD5
crypto map outside_map interface outside
Grazie e ciao