Site to Site with Cisco ASA

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance



I am at the remote office (ISa2004) and the ASA is at the main office. I
created a new network called Main Office containing addresses
10.xx.xx.xx/16, 169.xx.xx.xx/22, 192.xx.xx.xx/24. I am utilizing an IPSec
connection with Phase 1 settings as follows:
3DES
SHA1
DH Group 2
Authenticate and generate keyy ever 86400 seconds.

Phase 2
3DES
SHA1
Generate a new key every 4608000kb, 28800seconds
PFS
DH Group 2
And am using a pre shared key for authentication.

The Cisco ASA is configured in the same manner.

The network rule is:
route - main office, internal - main office, internal.

The firewall policy rules are:
main office to remote - allow all outbound traffice from main office to
internal, local host - all users
remote to main office - allow all outbound traffice from internal, local
host to main office - all users

The connection gets created but is not stable. It seems to drop quite
frequently. While monitoring IKE Client and IKE server protocols I catch "A
connection was gracefully closed in an orderly shutdown process with a
three-way FIN-initiated handshake." quite frequently around the same time
that the drop occurs. Does anyone have any ideas?


.



Relevant Pages

  • Re: Using Remote Desktop From an SBS Domain
    ... Right click My Network Places...Properties. ... computer that is on a remote network now. ... Internet connection, bypassing my SBS/ISA network all together. ... the port number you connect to from 80 to a port of your ...
    (microsoft.public.windows.server.sbs)
  • Re: Problem with RWW, can list computers/servers, cannot get logged in
    ... > When I say "outside the network" I mean accessing the network via a ... > one of two errors at the remote desktop, ... > connection might not be enabled or the computer might be too bust to ... Even turned off connection limits in ISA General... ...
    (microsoft.public.windows.server.sbs)
  • Re: Using Remote Desktop From an SBS Domain
    ... Internet connection, bypassing my SBS/ISA network all together. ... machine that I'm trying to connect to is configured to accept Remote Desktop ... the port number you connect to from 80 to a port of your ...
    (microsoft.public.windows.server.sbs)
  • Re: VPN and remote gateway
    ... 317025, we could know that if you use local gateway, your internet connection will not be a problem, but, you could not access your ... remote network since there is no route between you computer and your remote company network. ...
    (microsoft.public.windows.server.sbs)
  • Re: Problem with RWW, can list computers/servers, cannot get logge
    ... I believe I have the certificate address handled correctly, ... >> to which the network in connected. ... The client could not establis a connection to the remote ... >> connection might not be enabled or the computer might be too bust to ...
    (microsoft.public.windows.server.sbs)