Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations SkipVought on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Cisco ASA IPSec Spoof Detected

Status
Not open for further replies.

tbierl

IS-IT--Management
Jan 28, 2013
1
0
0
US
I have a situation were we have a remote site connected with a ASA 5505 to our ASA 5525-x, then forwording out another tunnel via a 1870 series router. The problem is when it passes through the 5525 in the middle, it blocks the connection as IPSec Spoof Detected. What should I check to resolve this problem. FYI-I am holding off on posting configs because I want to learn where the problem lies, not just fix it.
 
ANti-spoofing basically defines some networks as "internal" and all the rest as "external", and then any "internal" IP address that appears on the external interface is therefore obviously spoofed and must be dropped.
 
Could be a NAT issue, as in VPN pool addresses not being excluded from being NATted back out...

10 ? "TIMMAY!!!"
20 goto 10
run
TIMMAY!!!...
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top