 




<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: 3G &#8211; Creating a S2S VPN when the 3G card uses DHCP and not static?</title>
	<atom:link href="http://itknowledgeexchange.techtarget.com/itanswers/3g-creating-a-s2s-vpn-when-the-3g-card-uses-dhcp-and-not-static/feed/" rel="self" type="application/rss+xml" />
	<link>http://itknowledgeexchange.techtarget.com/itanswers/3g-creating-a-s2s-vpn-when-the-3g-card-uses-dhcp-and-not-static/</link>
	<description></description>
	<lastBuildDate>Fri, 24 May 2013 07:13:09 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	
	<item>
		<title>By: pkpatel1151</title>
		<link>http://itknowledgeexchange.techtarget.com/itanswers/3g-creating-a-s2s-vpn-when-the-3g-card-uses-dhcp-and-not-static/#comment-83981</link>
		<dc:creator>pkpatel1151</dc:creator>
		<pubDate>Wed, 17 Nov 2010 17:02:18 +0000</pubDate>
		<guid isPermaLink="false">#comment-83981</guid>
		<description><![CDATA[Coledej,

Send me your config&#039;s - minus password - for router and ASA to pkpatel@icon-networks.com.]]></description>
		<content:encoded><![CDATA[<p>Coledej,</p>
<p>Send me your config&#8217;s &#8211; minus password &#8211; for router and ASA to <a href="mailto:pkpatel@icon-networks.com">pkpatel@icon-networks.com</a>.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: coledej</title>
		<link>http://itknowledgeexchange.techtarget.com/itanswers/3g-creating-a-s2s-vpn-when-the-3g-card-uses-dhcp-and-not-static/#comment-83965</link>
		<dc:creator>coledej</dc:creator>
		<pubDate>Wed, 17 Nov 2010 09:43:04 +0000</pubDate>
		<guid isPermaLink="false">#comment-83965</guid>
		<description><![CDATA[Hi PKpatel,
Can you put me through how you are able to achieve this please I have set my 1941 router to use aggressive mode to establishe the vpn and has a dynamic crypto map on my ASA with the pre-shared key on the default group.But I still get error with the phase 1 failing just as someone(orange newbie) complained earlier.
Error from ASA

STV-5520-01(config)# Nov 13 12:54:39 [IKEv1]: IP = 212.183.140.25, Received ISAKMP Aggressive Mode message 1 with unknown tunnel group name &#039;212.183.140.25&#039;.
Nov 13 12:54:39 [IKEv1]: Group = DefaultRAGroup, IP = 212.183.140.25, Removing peer from peer table failed, no match!

Error from Router
*Nov 13 12:57:12.259: ISAKMP:(0): retransmitting phase 1 AG_INIT_EXCH
*Nov 13 12:57:12.259: ISAKMP:(0): sending packet to 195.89.37.162 my_port 500 peer_port 500 (I) AG_INIT_EXCH
*Nov 13 12:57:12.259: ISAKMP:(0):Sending an IKE IPv4 Packet.
*Nov 13 12:57:13.695: ISAKMP (0): received packet from 195.89.37.162 dport 500 sport 500 Global (I) AG_INIT_EXCH
*Nov 13 12:57:13.695: ISAKMP:(0):Notify has no hash. Rejected.
*Nov 13 12:57:13.695: ISAKMP (0): Unknown Input IKE_MESG_FROM_PEER, IKE_INFO_NOTIFY:  state = IKE_I_AM1
*Nov 13 12:57:13.695: ISAKMP:(0):Input = IKE_MESG_FROM_PEER, IKE_INFO_NOTIFY
*Nov 13 12:57:13.695: ISAKMP:(0):Old State = IKE_I_AM1  New State = IKE_I_AM1


Thanks for your help.]]></description>
		<content:encoded><![CDATA[<p>Hi PKpatel,<br />
Can you put me through how you are able to achieve this please I have set my 1941 router to use aggressive mode to establishe the vpn and has a dynamic crypto map on my ASA with the pre-shared key on the default group.But I still get error with the phase 1 failing just as someone(orange newbie) complained earlier.<br />
Error from ASA</p>
<p>STV-5520-01(config)# Nov 13 12:54:39 [IKEv1]: IP = 212.183.140.25, Received ISAKMP Aggressive Mode message 1 with unknown tunnel group name &#8217;212.183.140.25&#8242;.<br />
Nov 13 12:54:39 [IKEv1]: Group = DefaultRAGroup, IP = 212.183.140.25, Removing peer from peer table failed, no match!</p>
<p>Error from Router<br />
*Nov 13 12:57:12.259: ISAKMP:(0): retransmitting phase 1 AG_INIT_EXCH<br />
*Nov 13 12:57:12.259: ISAKMP:(0): sending packet to 195.89.37.162 my_port 500 peer_port 500 (I) AG_INIT_EXCH<br />
*Nov 13 12:57:12.259: ISAKMP:(0):Sending an IKE IPv4 Packet.<br />
*Nov 13 12:57:13.695: ISAKMP (0): received packet from 195.89.37.162 dport 500 sport 500 Global (I) AG_INIT_EXCH<br />
*Nov 13 12:57:13.695: ISAKMP:(0):Notify has no hash. Rejected.<br />
*Nov 13 12:57:13.695: ISAKMP (0): Unknown Input IKE_MESG_FROM_PEER, IKE_INFO_NOTIFY:  state = IKE_I_AM1<br />
*Nov 13 12:57:13.695: ISAKMP:(0):Input = IKE_MESG_FROM_PEER, IKE_INFO_NOTIFY<br />
*Nov 13 12:57:13.695: ISAKMP:(0):Old State = IKE_I_AM1  New State = IKE_I_AM1</p>
<p>Thanks for your help.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pkpatel1151</title>
		<link>http://itknowledgeexchange.techtarget.com/itanswers/3g-creating-a-s2s-vpn-when-the-3g-card-uses-dhcp-and-not-static/#comment-83944</link>
		<dc:creator>pkpatel1151</dc:creator>
		<pubDate>Wed, 17 Nov 2010 01:07:26 +0000</pubDate>
		<guid isPermaLink="false">#comment-83944</guid>
		<description><![CDATA[You can do IPSec VPN between your router with DHCP address and ASA with static  address.   I have about  sites with Cisco 871 on 3G doing VPN with ASA based on pre-shared key.  The only thing to keep in mind is that the VPN can only be initiated by Cisco 871 since this is dynamic VPN.  If it times out, you won;t be able to get to site with Cisco 871 unlesse 871 rebuilds VPN by sending interesting traffic.

We use SLA to keep IPSec VPN active all the time and prevent it from timing out.]]></description>
		<content:encoded><![CDATA[<p>You can do IPSec VPN between your router with DHCP address and ASA with static  address.   I have about  sites with Cisco 871 on 3G doing VPN with ASA based on pre-shared key.  The only thing to keep in mind is that the VPN can only be initiated by Cisco 871 since this is dynamic VPN.  If it times out, you won;t be able to get to site with Cisco 871 unlesse 871 rebuilds VPN by sending interesting traffic.</p>
<p>We use SLA to keep IPSec VPN active all the time and prevent it from timing out.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: coledej</title>
		<link>http://itknowledgeexchange.techtarget.com/itanswers/3g-creating-a-s2s-vpn-when-the-3g-card-uses-dhcp-and-not-static/#comment-83806</link>
		<dc:creator>coledej</dc:creator>
		<pubDate>Mon, 15 Nov 2010 12:10:35 +0000</pubDate>
		<guid isPermaLink="false">#comment-83806</guid>
		<description><![CDATA[Hello,

Just wanted to know if someone eventually had a way around how to establish the vpn from the ASA to the Router with vodafone SIM card ,i am facing the same challenge and i spoke with the Vodafone engineer that says they dont assign static ip address to the SIMs anymore.

Thanks]]></description>
		<content:encoded><![CDATA[<p>Hello,</p>
<p>Just wanted to know if someone eventually had a way around how to establish the vpn from the ASA to the Router with vodafone SIM card ,i am facing the same challenge and i spoke with the Vodafone engineer that says they dont assign static ip address to the SIMs anymore.</p>
<p>Thanks</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: rgunther</title>
		<link>http://itknowledgeexchange.techtarget.com/itanswers/3g-creating-a-s2s-vpn-when-the-3g-card-uses-dhcp-and-not-static/#comment-74811</link>
		<dc:creator>rgunther</dc:creator>
		<pubDate>Fri, 12 Mar 2010 15:26:15 +0000</pubDate>
		<guid isPermaLink="false">#comment-74811</guid>
		<description><![CDATA[When using the ASDM for my ASA5520 and setting up a Site to Site VPN tunnel, there is an option to uncheck Peer IP Address as static.  At that point it looks to be using the Connection Name as the point to authenticate if you should be able to setup a tunnel.  You can still use a PSK or a Indentity Cert at that point to secure your connection as well.

I have never used this feature as everytime I have made a vpn tunnel both sides have the a static IP address.

Hope that helps you.
Ryan Gunther
www.onlinetech.com]]></description>
		<content:encoded><![CDATA[<p>When using the ASDM for my ASA5520 and setting up a Site to Site VPN tunnel, there is an option to uncheck Peer IP Address as static.  At that point it looks to be using the Connection Name as the point to authenticate if you should be able to setup a tunnel.  You can still use a PSK or a Indentity Cert at that point to secure your connection as well.</p>
<p>I have never used this feature as everytime I have made a vpn tunnel both sides have the a static IP address.</p>
<p>Hope that helps you.<br />
Ryan Gunther<br />
<a href="http://www.onlinetech.com" rel="nofollow">http://www.onlinetech.com</a></p>
]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Page Caching using memcached
Database Caching 3/8 queries in 0.042 seconds using memcached
Object Caching 325/326 objects using memcached

Served from: itknowledgeexchange.techtarget.com @ 2013-05-24 08:17:04 -->