zimskiz wrote: » 1. What the object-group obj_any contain? Also i think that the second line is not quit alright ( i will search tomorrow at work) nat (vlan5,internet) source dynamic obj_any interface nat (vlan5,internet) source static Fields-Group Fields-Group destination static Fields-Cardiff Fields-Cardiff no-proxy-arp route-lookup 2. If you try to ping for example "192.168.7.1" did you get any hitcounts in acl internet_cryptomap ? (making this test will exclude any routing issues before ASA 55xx.
websponge wrote: » tried again tonight, the branch office isakmp is: Type : L2L Role : responder Rekey : no State : MM_WAIT_MSG5 head office is waiting for PSK to be checked? (the passkey is 100% correct)
zimskiz wrote: » No matter what is the status of the IPsec tunnel, using ping towards 192.168.7.x will increase the hitcount of that access list. Further more, delete nat (vlan5,internet) source static Fields-Group Fields-Group destination static Fields-Cardiff Fields-Cardiff no-proxy-arp route-lookup. Can we establish a skype session later ? (to troubleshoot in your live environment)
TheNewITGuy wrote: » How are you testing to bring the tunnel up? Also can you paste the output of the debug logs
websponge wrote: » Thanks all, issue is solved at last! Two things causing this, the no nat was after the global pat, so the reason it wouldn't come up some of the time was it was natting before it could no nat! Tunnel traffic was one sided, as there was no route back out from where the destination traffic was, turned out it was a server off a core switch, that had a default route out via a different wan link. I added a static and voila, ! All,good, thank you all.