lexx
Junior Member | Редактировать | Профиль | Сообщение | Цитировать | Сообщить модератору Подскажите в чем может быть причина следущей проблемы: cisco asa 5520 сконфигурирована в режиме прозрачного фаервола, через нее устанавливаются VPN соединения до интернет шлюза, и после 3-4 одновременных соединений, при попытке установки 5го соедининения вываливается "Ошибка 800 подключения к VPN Не удалось установить подключение." в логах Код: 4|Sep 28 2009|11:50:59|106023|192.168.100.253|500|ProxyServer|500|Deny udp src inside:192.168.100.253/500 dst outside:ProxyServer/500 by access-group "inside_access_in" [0x0, 0x0] 4|Sep 28 2009|11:50:50|106023|192.168.100.253|500|ProxyServer|500|Deny udp src inside:192.168.100.253/500 dst outside:ProxyServer/500 by access-group "inside_access_in" [0x0, 0x0] 4|Sep 28 2009|11:50:45|106023|192.168.100.253|500|ProxyServer|500|Deny udp src inside:192.168.100.253/500 dst outside:ProxyServer/500 by access-group "inside_access_in" [0x0, 0x0] 4|Sep 28 2009|11:50:42|106023|192.168.100.253|500|ProxyServer|500|Deny udp src inside:192.168.100.253/500 dst outside:ProxyServer/500 by access-group "inside_access_in" [0x0, 0x0] 4|Sep 28 2009|11:50:41|106023|192.168.100.253|56810|ProxyServer|443|Deny tcp src inside:192.168.100.253/56810 dst outside:ProxyServer/443 by access-group "inside_access_in" [0x0, 0x0] 4|Sep 28 2009|11:50:41|106023|192.168.100.253|56810|ProxyServer|443|Deny tcp src inside:192.168.100.253/56810 dst outside:ProxyServer/443 by access-group "inside_access_in" [0x0, 0x0] 4|Sep 28 2009|11:50:40|106023|192.168.100.253|500|ProxyServer|500|Deny udp src inside:192.168.100.253/500 dst outside:ProxyServer/500 by access-group "inside_access_in" [0x0, 0x0] 4|Sep 28 2009|11:50:40|106023|192.168.100.253|56810|ProxyServer|443|Deny tcp src inside:192.168.100.253/56810 dst outside:ProxyServer/443 by access-group "inside_access_in" [0x0, 0x0] 4|Sep 28 2009|11:50:30|106023|192.168.100.253|1701|ProxyServer|1701|Deny udp src inside:192.168.100.253/1701 dst outside:ProxyServer/1701 by access-group "inside_access_in" [0x0, 0x0] 4|Sep 28 2009|11:50:20|106023|192.168.100.253|1701|ProxyServer|1701|Deny udp src inside:192.168.100.253/1701 dst outside:ProxyServer/1701 by access-group "inside_access_in" [0x0, 0x0] 4|Sep 28 2009|11:50:18|106023|192.168.100.253|137|192.168.101.255|137|Deny udp src inside:192.168.100.253/137 dst outside:192.168.101.255/137 by access-group "inside_access_in" [0x0, 0x0] 4|Sep 28 2009|11:50:18|106023|192.168.100.253|137|192.168.101.255|137|Deny udp src inside:192.168.100.253/137 dst outside:192.168.101.255/137 by access-group "inside_access_in" [0x0, 0x0] 4|Sep 28 2009|11:50:17|106023|192.168.100.253|137|192.168.101.255|137|Deny udp src inside:192.168.100.253/137 dst outside:192.168.101.255/137 by access-group "inside_access_in" [0x0, 0x0] 4|Sep 28 2009|11:50:16|106023|192.168.100.253|137|192.168.101.255|137|Deny udp src inside:192.168.100.253/137 dst outside:192.168.101.255/137 by access-group "inside_access_in" [0x0, 0x0] 4|Sep 28 2009|11:50:15|106023|192.168.100.253|137|192.168.101.255|137|Deny udp src inside:192.168.100.253/137 dst outside:192.168.101.255/137 by access-group "inside_access_in" [0x0, 0x0] 4|Sep 28 2009|11:50:15|106023|192.168.100.253|137|192.168.101.255|137|Deny udp src inside:192.168.100.253/137 dst outside:192.168.101.255/137 by access-group "inside_access_in" [0x0, 0x0] 4|Sep 28 2009|11:50:14|106023|192.168.100.253|59808|224.0.0.252|5355|Deny udp src inside:192.168.100.253/59808 dst outside:224.0.0.252/5355 by access-group "inside_access_in" [0x0, 0x0] 4|Sep 28 2009|11:50:14|106023|192.168.100.253|59808|224.0.0.252|5355|Deny udp src inside:192.168.100.253/59808 dst outside:224.0.0.252/5355 by access-group "inside_access_in" [0x0, 0x0] 4|Sep 28 2009|11:50:12|106023|192.168.100.253|1701|ProxyServer|1701|Deny udp src inside:192.168.100.253/1701 dst outside:ProxyServer/1701 by access-group "inside_access_in" [0x0, 0x0] 4|Sep 28 2009|11:50:08|106023|192.168.100.253|1701|ProxyServer|1701|Deny udp src inside:192.168.100.253/1701 dst outside:ProxyServer/1701 by access-group "inside_access_in" [0x0, 0x0] 4|Sep 28 2009|11:50:06|106023|192.168.100.253|1701|ProxyServer|1701|Deny udp src inside:192.168.100.253/1701 dst outside:ProxyServer/1701 by access-group "inside_access_in" [0x0, 0x0] 4|Sep 28 2009|11:50:05|106023|192.168.100.253|1701|ProxyServer|1701|Deny udp src inside:192.168.100.253/1701 dst outside:ProxyServer/1701 by access-group "inside_access_in" [0x0, 0x0] 6|Sep 28 2009|11:50:05|302018|192.168.100.253||ProxyServer|2048|Teardown GRE connection 468090 from inside:192.168.100.253 to outside:ProxyServer/2048 duration 0:00:00 bytes 0 6|Sep 28 2009|11:50:05|302018|ProxyServer||192.168.100.253|22621|Teardown GRE connection 468091 from outside:ProxyServer to inside:192.168.100.253/22621 duration 0:00:00 bytes 0 6|Sep 28 2009|11:50:05|302014|ProxyServer|1723|192.168.100.253|56809|Teardown TCP connection 468089 for outside:ProxyServer/1723 to inside:192.168.100.253/56809 duration 0:00:00 bytes 512 TCP FINs 6|Sep 28 2009|11:50:05|302013|ProxyServer|1723|192.168.100.253|56809|Built outbound TCP connection 468089 for outside:ProxyServer/1723 (ProxyServer/1723) to inside:192.168.100.253/56809 (192.168.100.253/56809) | |