Forum Discussion
Schrier_58326
Nimbostratus
Jan 28, 2014F5 TMOS 11.3 L2L vpn cisco ASA 8.4<
textWe want to setup a Site-2-Site vpn tunnel from F5 TMOS to a cisco ASA.
We used IKEV1, SHA, 3DES and ESP phase 2.
The VPN tunnel will establish isakmp (phase1)
-- [root@F5:Active:In Sync] con...
Vitaliy_Savrans
Nacreous
Jan 30, 2014By my mind you didn't see trough the tunnel because: From asa nat config I guess that 172.16.1.0/24 is terminated on ASA and 10.10.10.10 terminated of F5 (correct me if I am wrong). But you have access-list for crypto-map:
access-list vpn-test extended permit ip host 10.10.10.10 172.16.1.0 255.255.255.0
there will be no traffic pass through this access-list on ASA and you will not see any hitcounts in ipsec sa. I think you need change vice-vers you access-list and traffic selector.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects