<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="https://community.sophos.com/cfs-file/__key/system/syndication/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>IPSec S2S UTM135 &amp;lt;-&amp;gt; Cisco ASA Aufbau nur von ASA möglich</title><link>https://community.sophos.com/utm-firewall/f/german-forum/79704/ipsec-s2s-utm135---cisco-asa-aufbau-nur-von-asa-moglich</link><description>Hallo Alle zusammen, 
 Ich habe einen IPSec Tunnel zu konfigurieren. 
 Aufbau 
 UTM &amp;lt;-&amp;gt; Fritzbox 7390 (static IP) &amp;lt;-&amp;gt; ASA (static IP) &amp;lt;-&amp;gt; interne Netze 
 Ich habe die Konfig anhand der FAQ V7 Cisco gemacht und habe auch nach einigen Anlaufproblemen eine</description><dc:language>en-US</dc:language><generator>Telligent Community 12</generator><item><title>RE: IPSec S2S UTM135 &lt;-&gt; Cisco ASA Aufbau nur von ASA möglich</title><link>https://community.sophos.com/thread/305415?ContentTypeID=1</link><pubDate>Tue, 13 Sep 2016 14:29:24 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:0058bd7a-5479-4300-9b25-7e893b2a429f</guid><dc:creator>BAlfson</dc:creator><description>&lt;p&gt;Auf beiden Seiten - kannst uns bilder von beiden Policies zeigen?&lt;/p&gt;
&lt;p&gt;MfG - Bob&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: IPSec S2S UTM135 &lt;-&gt; Cisco ASA Aufbau nur von ASA möglich</title><link>https://community.sophos.com/thread/304378?ContentTypeID=1</link><pubDate>Sat, 27 Aug 2016 02:53:26 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:f3f37462-7226-47a4-89c8-6e30b101bd71</guid><dc:creator>bpman</dc:creator><description>&lt;p&gt;Guten Morgen? Bob,&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;auf welcher Seite soll ich denn die SA Einstellungen anpassen?&lt;/p&gt;
&lt;p&gt;UTM oder ASA? &lt;/p&gt;
&lt;p&gt;Oder besser gefragt, wie bekomme ich sie passend?&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;Gru&amp;szlig; Bernd&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: IPSec S2S UTM135 &lt;-&gt; Cisco ASA Aufbau nur von ASA möglich</title><link>https://community.sophos.com/thread/304369?ContentTypeID=1</link><pubDate>Fri, 26 Aug 2016 19:46:54 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:5433690f-b8d4-4027-bf38-8f5c6022223a</guid><dc:creator>BAlfson</dc:creator><description>&lt;p&gt;&amp;quot;All IPSec SA proposals found unacceptable.&amp;quot;&lt;/p&gt;
&lt;p&gt;MfG - Bob&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: IPSec S2S UTM135 &lt;-&gt; Cisco ASA Aufbau nur von ASA möglich</title><link>https://community.sophos.com/thread/304331?ContentTypeID=1</link><pubDate>Fri, 26 Aug 2016 06:33:21 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:b51188fa-1129-44f2-b365-1aa7334e97ac</guid><dc:creator>bpman</dc:creator><description>&lt;p&gt;Hier das UTW-Log ohne Debug Optionen&lt;/p&gt;
&lt;p&gt;--------------------------&lt;/p&gt;
&lt;p&gt;2016:08:26-13:15:44 asg12 ipsec_starter[5331]: Starting strongSwan 4.4.1git20100610 IPsec [starter]...&lt;br /&gt;2016:08:26-13:15:44 asg12 pluto[5344]: Starting IKEv1 pluto daemon (strongSwan 4.4.1git20100610) THREADS VENDORID CISCO_QUIRKS&lt;br /&gt;2016:08:26-13:15:44 asg12 pluto[5344]: loaded plugins: curl ldap aes des blowfish serpent twofish sha1 sha2 md5 random x509 pubkey pkcs1 pgp dnskey pem sqlite hmac gmp xauth attr attr-sql resolve&lt;br /&gt;2016:08:26-13:15:44 asg12 pluto[5344]: including NAT-Traversal patch (Version 0.6c)&lt;br /&gt;2016:08:26-13:15:44 asg12 pluto[5344]: Using Linux 2.6 IPsec interface code&lt;br /&gt;2016:08:26-13:15:44 asg12 ipsec_starter[5338]: pluto (5344) started after 20 ms&lt;br /&gt;2016:08:26-13:15:45 asg12 pluto[5344]: loading ca certificates from &amp;#39;/etc/ipsec.d/cacerts&amp;#39;&lt;br /&gt;2016:08:26-13:15:45 asg12 pluto[5344]: loaded ca certificate from &amp;#39;/etc/ipsec.d/cacerts/VPN Signing CA.pem&amp;#39;&lt;br /&gt;2016:08:26-13:15:45 asg12 pluto[5344]: loading aa certificates from &amp;#39;/etc/ipsec.d/aacerts&amp;#39;&lt;br /&gt;2016:08:26-13:15:45 asg12 pluto[5344]: loading ocsp certificates from &amp;#39;/etc/ipsec.d/ocspcerts&amp;#39;&lt;br /&gt;2016:08:26-13:15:45 asg12 pluto[5344]: Changing to directory &amp;#39;/etc/ipsec.d/crls&amp;#39;&lt;br /&gt;2016:08:26-13:15:45 asg12 pluto[5344]: loading attribute certificates from &amp;#39;/etc/ipsec.d/acerts&amp;#39;&lt;br /&gt;2016:08:26-13:15:45 asg12 pluto[5344]: adding interface wlan0/wlan0 172.16.28.1:500&lt;br /&gt;2016:08:26-13:15:45 asg12 pluto[5344]: adding interface wlan0/wlan0 172.16.28.1:4500&lt;br /&gt;2016:08:26-13:15:45 asg12 pluto[5344]: adding interface eth4/eth4 172.16.20.1:500&lt;br /&gt;2016:08:26-13:15:45 asg12 pluto[5344]: adding interface eth4/eth4 172.16.20.1:4500&lt;br /&gt;2016:08:26-13:15:45 asg12 pluto[5344]: adding interface eth1/eth1 192.168.10.66:500&lt;br /&gt;2016:08:26-13:15:45 asg12 pluto[5344]: adding interface eth1/eth1 192.168.10.66:4500&lt;br /&gt;2016:08:26-13:15:45 asg12 pluto[5344]: adding interface eth0/eth0 10.228.187.185:500&lt;br /&gt;2016:08:26-13:15:45 asg12 pluto[5344]: adding interface eth0/eth0 10.228.187.185:4500&lt;br /&gt;2016:08:26-13:15:45 asg12 pluto[5344]: adding interface lo/lo 127.0.0.1:500&lt;br /&gt;2016:08:26-13:15:45 asg12 pluto[5344]: adding interface lo/lo 127.0.0.1:4500&lt;br /&gt;2016:08:26-13:15:45 asg12 pluto[5344]: adding interface lo/lo ::1:500&lt;br /&gt;2016:08:26-13:15:45 asg12 pluto[5344]: loading secrets from &amp;quot;/etc/ipsec.secrets&amp;quot;&lt;br /&gt;2016:08:26-13:15:45 asg12 pluto[5344]: loaded PSK secret for 176.94.108.98 82.193.226.141&lt;br /&gt;2016:08:26-13:15:45 asg12 pluto[5344]: listening for IKE messages&lt;br /&gt;2016:08:26-13:15:45 asg12 pluto[5344]: added connection description &amp;quot;S_LRA&amp;quot;&lt;br /&gt;2016:08:26-13:15:45 asg12 pluto[5344]: &amp;quot;S_LRA&amp;quot; #1: initiating Main Mode&lt;br /&gt;2016:08:26-13:15:45 asg12 pluto[5344]: added connection description &amp;quot;S_LRA&amp;quot;&lt;br /&gt;2016:08:26-13:15:45 asg12 pluto[5344]: added connection description &amp;quot;S_LRA&amp;quot;&lt;br /&gt;2016:08:26-13:15:45 asg12 pluto[5344]: &amp;quot;S_LRA&amp;quot; #1: received Vendor ID payload [RFC 3947]&lt;br /&gt;2016:08:26-13:15:45 asg12 pluto[5344]: &amp;quot;S_LRA&amp;quot; #1: ignoring Vendor ID payload [FRAGMENTATION c0000000]&lt;br /&gt;2016:08:26-13:15:45 asg12 pluto[5344]: &amp;quot;S_LRA&amp;quot; #1: enabling possible NAT-traversal with method 3&lt;br /&gt;2016:08:26-13:15:45 asg12 pluto[5344]: &amp;quot;S_LRA&amp;quot; #1: ignoring Vendor ID payload [Cisco-Unity]&lt;br /&gt;2016:08:26-13:15:45 asg12 pluto[5344]: &amp;quot;S_LRA&amp;quot; #1: received Vendor ID payload [XAUTH]&lt;br /&gt;2016:08:26-13:15:45 asg12 pluto[5344]: &amp;quot;S_LRA&amp;quot; #1: ignoring Vendor ID payload [955941cdcf31fdd599b00805893672ec]&lt;br /&gt;2016:08:26-13:15:45 asg12 pluto[5344]: &amp;quot;S_LRA&amp;quot; #1: ignoring Vendor ID payload [Cisco VPN 3000 Series]&lt;br /&gt;2016:08:26-13:15:45 asg12 pluto[5344]: &amp;quot;S_LRA&amp;quot; #1: NAT-Traversal: Result using RFC 3947: i am NATed&lt;br /&gt;2016:08:26-13:15:45 asg12 pluto[5344]: &amp;quot;S_LRA&amp;quot; #1: received Vendor ID payload [Dead Peer Detection]&lt;br /&gt;2016:08:26-13:15:45 asg12 pluto[5344]: | protocol/port in Phase 1 ID Payload is 17/0. accepted with port_floating NAT-T&lt;br /&gt;2016:08:26-13:15:45 asg12 pluto[5344]: &amp;quot;S_LRA&amp;quot; #1: Peer ID is ID_IPV4_ADDR: &amp;#39;82.193.226.141&amp;#39;&lt;br /&gt;2016:08:26-13:15:45 asg12 pluto[5344]: &amp;quot;S_LRA&amp;quot; #1: Dead Peer Detection (RFC 3706) enabled&lt;br /&gt;2016:08:26-13:15:45 asg12 pluto[5344]: &amp;quot;S_LRA&amp;quot; #1: ISAKMP SA established&lt;br /&gt;2016:08:26-13:15:45 asg12 pluto[5344]: &amp;quot;S_LRA&amp;quot; #2: initiating Quick Mode PSK+ENCRYPT+TUNNEL+PFS+UP {using isakmp#1}&lt;br /&gt;2016:08:26-13:15:45 asg12 pluto[5344]: &amp;quot;S_LRA&amp;quot; #3: initiating Quick Mode PSK+ENCRYPT+TUNNEL+PFS+UP {using isakmp#1}&lt;br /&gt;2016:08:26-13:15:45 asg12 pluto[5344]: &amp;quot;S_LRA&amp;quot; #4: initiating Quick Mode PSK+ENCRYPT+TUNNEL+PFS+UP {using isakmp#1}&lt;br /&gt;2016:08:26-13:15:45 asg12 pluto[5344]: &amp;quot;S_LRA&amp;quot; #1: ignoring informational payload, type NO_PROPOSAL_CHOSEN&lt;br /&gt;2016:08:26-13:15:45 asg12 pluto[5344]: &amp;quot;S_LRA&amp;quot; #1: received Delete SA payload: deleting ISAKMP State #1&lt;/p&gt;
&lt;p&gt;----------------------&lt;/p&gt;
&lt;p&gt;Dazu das passende ASA log. Es muss allerdings von unten gelesen werden.&lt;/p&gt;
&lt;p&gt;----------------------&lt;/p&gt;
&lt;p&gt;7|Aug 26 2016|13:17:46|609002|x.x.x.x(fritz)||||Teardown local-host outside:x.x.x.x(fritz) duration 0:02:01&lt;br /&gt;6|Aug 26 2016|13:17:46|302016|x.x.x.x(fritz)|4500|x.x.x.x(asa)|4500|Teardown UDP connection 388810 for outside:x.x.x.x(fritz)/4500 to identity:x.x.x.x(asa)/4500 duration 0:02:01 bytes 1376&lt;br /&gt;6|Aug 26 2016|13:17:46|302016|x.x.x.x(fritz)|500|x.x.x.x(asa)|500|Teardown UDP connection 388809 for outside:x.x.x.x(fritz)/500 to identity:x.x.x.x(asa)/500 duration 0:02:01 bytes 1044&lt;br /&gt;5|Aug 26 2016|13:15:45|713904|||||IP = x.x.x.x(fritz), Received encrypted packet with no matching SA, dropping&lt;br /&gt;5|Aug 26 2016|13:15:45|713904|||||IP = x.x.x.x(fritz), Received encrypted packet with no matching SA, dropping&lt;br /&gt;5|Aug 26 2016|13:15:45|713904|||||IP = x.x.x.x(fritz), Received encrypted packet with no matching SA, dropping&lt;br /&gt;4|Aug 26 2016|13:15:45|113019|||||Group = x.x.x.x(fritz), Username = x.x.x.x(fritz), IP = x.x.x.x(fritz), Session disconnected. Session Type: LAN-to-LAN, Duration: 0h:00m:00s, Bytes xmt: 0, Bytes rcv: 0, Reason: Phase 2 Mismatch&lt;br /&gt;5|Aug 26 2016|13:15:45|713259|||||Group = x.x.x.x(fritz), IP = x.x.x.x(fritz), Session is being torn down. Reason: Phase 2 Mismatch&lt;br /&gt;7|Aug 26 2016|13:15:45|713236|||||IP = x.x.x.x(fritz), IKE_DECODE SENDING Message (msgid=c42ca052) with payloads : HDR + HASH (8) + DELETE (12) + NONE (0) total length : 80&lt;br /&gt;7|Aug 26 2016|13:15:45|715046|||||Group = x.x.x.x(fritz), IP = x.x.x.x(fritz), constructing qm hash payload&lt;br /&gt;7|Aug 26 2016|13:15:45|715046|||||Group = x.x.x.x(fritz), IP = x.x.x.x(fritz), constructing IKE delete payload&lt;br /&gt;7|Aug 26 2016|13:15:45|715046|||||Group = x.x.x.x(fritz), IP = x.x.x.x(fritz), constructing blank hash payload&lt;br /&gt;7|Aug 26 2016|13:15:45|713906|||||Group = x.x.x.x(fritz), IP = x.x.x.x(fritz), sending delete/delete with reason message&lt;br /&gt;7|Aug 26 2016|13:15:45|713906|||||Group = x.x.x.x(fritz), IP = x.x.x.x(fritz), IKE SA MM:d0e69e60 terminating:&amp;nbsp; flags 0x0100c002, refcnt 0, tuncnt 0&lt;br /&gt;7|Aug 26 2016|13:15:45|713906|||||Group = x.x.x.x(fritz), IP = x.x.x.x(fritz), IKE SA MM:d0e69e60 rcv&amp;#39;d Terminate: state MM_ACTIVE&amp;nbsp; flags 0x0000c042, refcnt 1, tuncnt 0&lt;br /&gt;6|Aug 26 2016|13:15:45|713213|||||Group = x.x.x.x(fritz), IP = x.x.x.x(fritz), Deleting static route for L2L peer that came in on a dynamic map. address: 10.228.187.184, mask: 255.255.255.248&lt;br /&gt;3|Aug 26 2016|13:15:45|713902|||||Group = x.x.x.x(fritz), IP = x.x.x.x(fritz), Removing peer from correlator table failed, no match!&lt;br /&gt;7|Aug 26 2016|13:15:45|713906|||||Group = x.x.x.x(fritz), IP = x.x.x.x(fritz), sending delete/delete with reason message&lt;br /&gt;7|Aug 26 2016|13:15:45|715065|||||Group = x.x.x.x(fritz), IP = x.x.x.x(fritz), IKE QM Responder FSM error history (struct &amp;amp;0xae5de2c8)&amp;nbsp; &amp;lt;state&amp;gt;, &amp;lt;event&amp;gt;:&amp;nbsp; QM_DONE, EV_ERROR--&amp;gt;QM_BLD_MSG2, EV_NEGO_SA--&amp;gt;QM_BLD_MSG2, EV_IS_REKEY--&amp;gt;QM_BLD_MSG2, EV_CONFIRM_SA--&amp;gt;QM_BLD_MSG2, EV_PROC_MSG--&amp;gt;QM_BLD_MSG2, EV_HASH_OK--&amp;gt;QM_BLD_MSG2, NullEvent--&amp;gt;QM_BLD_MSG2, EV_COMP_HASH&lt;br /&gt;3|Aug 26 2016|13:15:45|713902|||||Group = x.x.x.x(fritz), IP = x.x.x.x(fritz), QM FSM error (P2 struct &amp;amp;0xae5de2c8, mess id 0x6b7e66e9)!&lt;br /&gt;7|Aug 26 2016|13:15:45|713236|||||IP = x.x.x.x(fritz), IKE_DECODE SENDING Message (msgid=6f3f6fac) with payloads : HDR + HASH (8) + NOTIFY (11) + NONE (0) total length : 84&lt;br /&gt;7|Aug 26 2016|13:15:45|715046|||||Group = x.x.x.x(fritz), IP = x.x.x.x(fritz), constructing qm hash payload&lt;br /&gt;7|Aug 26 2016|13:15:45|713906|||||Group = x.x.x.x(fritz), IP = x.x.x.x(fritz), constructing ipsec notify payload for msg id 6b7e66e9&lt;br /&gt;7|Aug 26 2016|13:15:45|715046|||||Group = x.x.x.x(fritz), IP = x.x.x.x(fritz), constructing blank hash payload&lt;br /&gt;7|Aug 26 2016|13:15:45|713906|||||Group = x.x.x.x(fritz), IP = x.x.x.x(fritz), sending notify message&lt;br /&gt;5|Aug 26 2016|13:15:45|713904|||||Group = x.x.x.x(fritz), IP = x.x.x.x(fritz), All IPSec SA proposals found unacceptable!&lt;br /&gt;7|Aug 26 2016|13:15:45|715047|||||Group = x.x.x.x(fritz), IP = x.x.x.x(fritz), processing IPSec SA payload&lt;br /&gt;7|Aug 26 2016|13:15:45|713066|||||Group = x.x.x.x(fritz), IP = x.x.x.x(fritz), IKE Remote Peer configured for crypto map: SYSTEM_DEFAULT_CRYPTO_MAP&lt;br /&gt;7|Aug 26 2016|13:15:45|715059|||||Group = x.x.x.x(fritz), IP = x.x.x.x(fritz), Selecting only UDP-Encapsulated-Tunnel and&amp;nbsp; UDP-Encapsulated-Transport modes defined by NAT-Traversal&lt;br /&gt;7|Aug 26 2016|13:15:45|715059|||||Group = x.x.x.x(fritz), IP = x.x.x.x(fritz), Selecting only UDP-Encapsulated-Tunnel and&amp;nbsp; UDP-Encapsulated-Transport modes defined by NAT-Traversal&lt;br /&gt;7|Aug 26 2016|13:15:45|715059|||||Group = x.x.x.x(fritz), IP = x.x.x.x(fritz), Selecting only UDP-Encapsulated-Tunnel and&amp;nbsp; UDP-Encapsulated-Transport modes defined by NAT-Traversal&lt;br /&gt;7|Aug 26 2016|13:15:45|715059|||||Group = x.x.x.x(fritz), IP = x.x.x.x(fritz), Selecting only UDP-Encapsulated-Tunnel and&amp;nbsp; UDP-Encapsulated-Transport modes defined by NAT-Traversal&lt;br /&gt;7|Aug 26 2016|13:15:45|715059|||||Group = x.x.x.x(fritz), IP = x.x.x.x(fritz), Selecting only UDP-Encapsulated-Tunnel and&amp;nbsp; UDP-Encapsulated-Transport modes defined by NAT-Traversal&lt;br /&gt;7|Aug 26 2016|13:15:45|715059|||||Group = x.x.x.x(fritz), IP = x.x.x.x(fritz), Selecting only UDP-Encapsulated-Tunnel and&amp;nbsp; UDP-Encapsulated-Transport modes defined by NAT-Traversal&lt;br /&gt;7|Aug 26 2016|13:15:45|715059|||||Group = x.x.x.x(fritz), IP = x.x.x.x(fritz), Selecting only UDP-Encapsulated-Tunnel and&amp;nbsp; UDP-Encapsulated-Transport modes defined by NAT-Traversal&lt;br /&gt;7|Aug 26 2016|13:15:45|715059|||||Group = x.x.x.x(fritz), IP = x.x.x.x(fritz), Selecting only UDP-Encapsulated-Tunnel and&amp;nbsp; UDP-Encapsulated-Transport modes defined by NAT-Traversal&lt;br /&gt;7|Aug 26 2016|13:15:45|715059|||||Group = x.x.x.x(fritz), IP = x.x.x.x(fritz), Selecting only UDP-Encapsulated-Tunnel and&amp;nbsp; UDP-Encapsulated-Transport modes defined by NAT-Traversal&lt;br /&gt;7|Aug 26 2016|13:15:45|715059|||||Group = x.x.x.x(fritz), IP = x.x.x.x(fritz), Selecting only UDP-Encapsulated-Tunnel and&amp;nbsp; UDP-Encapsulated-Transport modes defined by NAT-Traversal&lt;br /&gt;7|Aug 26 2016|13:15:45|713225|||||Group = x.x.x.x(fritz), IP = x.x.x.x(fritz), Static Crypto Map check, map SYSTEM_DEFAULT_CRYPTO_MAP, seq = 65535 is a successful match&lt;br /&gt;7|Aug 26 2016|13:15:45|713222|||||Group = x.x.x.x(fritz), IP = x.x.x.x(fritz), Static Crypto Map check, map = outside_map, seq = 21, ACL does not match proxy IDs src:10.228.187.184 dst:10.228.103.0&lt;br /&gt;7|Aug 26 2016|13:15:45|713221|||||Group = x.x.x.x(fritz), IP = x.x.x.x(fritz), Static Crypto Map check, checking map = outside_map, seq = 21...&lt;br /&gt;7|Aug 26 2016|13:15:45|713223|||||Group = x.x.x.x(fritz), IP = x.x.x.x(fritz), Static Crypto Map check, map = outside_map, seq = 10, no ACL configured&lt;br /&gt;7|Aug 26 2016|13:15:45|713221|||||Group = x.x.x.x(fritz), IP = x.x.x.x(fritz), Static Crypto Map check, checking map = outside_map, seq = 10...&lt;br /&gt;7|Aug 26 2016|13:15:45|713223|||||Group = x.x.x.x(fritz), IP = x.x.x.x(fritz), Static Crypto Map check, map = outside_map, seq = 2, no ACL configured&lt;br /&gt;7|Aug 26 2016|13:15:45|713221|||||Group = x.x.x.x(fritz), IP = x.x.x.x(fritz), Static Crypto Map check, checking map = outside_map, seq = 2...&lt;br /&gt;7|Aug 26 2016|13:15:45|713222|||||Group = x.x.x.x(fritz), IP = x.x.x.x(fritz), Static Crypto Map check, map = outside_map, seq = 1, ACL does not match proxy IDs src:10.228.187.184 dst:10.228.103.0&lt;br /&gt;7|Aug 26 2016|13:15:45|713221|||||Group = x.x.x.x(fritz), IP = x.x.x.x(fritz), Static Crypto Map check, checking map = outside_map, seq = 1...&lt;br /&gt;7|Aug 26 2016|13:15:45|713906|||||Group = x.x.x.x(fritz), IP = x.x.x.x(fritz), QM IsRekeyed old sa not found by addr&lt;br /&gt;7|Aug 26 2016|13:15:45|713034|||||Group = x.x.x.x(fritz), IP = x.x.x.x(fritz), Received local IP Proxy Subnet data in ID Payload:&amp;nbsp;&amp;nbsp; Address 10.228.103.0, Mask 255.255.255.0, Protocol 0, Port 0&lt;br /&gt;7|Aug 26 2016|13:15:45|714011|||||Group = x.x.x.x(fritz), IP = x.x.x.x(fritz), ID_IPV4_ADDR_SUBNET ID received--10.228.103.0--255.255.255.0&lt;br /&gt;7|Aug 26 2016|13:15:45|715047|||||Group = x.x.x.x(fritz), IP = x.x.x.x(fritz), processing ID payload&lt;br /&gt;7|Aug 26 2016|13:15:45|713035|||||Group = x.x.x.x(fritz), IP = x.x.x.x(fritz), Received remote IP Proxy Subnet data in ID Payload:&amp;nbsp;&amp;nbsp; Address 10.228.187.184, Mask 255.255.255.248, Protocol 0, Port 0&lt;br /&gt;7|Aug 26 2016|13:15:45|714011|||||Group = x.x.x.x(fritz), IP = x.x.x.x(fritz), ID_IPV4_ADDR_SUBNET ID received--10.228.187.184--255.255.255.248&lt;br /&gt;7|Aug 26 2016|13:15:45|715047|||||Group = x.x.x.x(fritz), IP = x.x.x.x(fritz), processing ID payload&lt;br /&gt;7|Aug 26 2016|13:15:45|713906|||||Group = x.x.x.x(fritz), IP = x.x.x.x(fritz), processing ISA_KE for PFS in phase 2&lt;br /&gt;7|Aug 26 2016|13:15:45|715047|||||Group = x.x.x.x(fritz), IP = x.x.x.x(fritz), processing ke payload&lt;br /&gt;7|Aug 26 2016|13:15:45|715047|||||Group = x.x.x.x(fritz), IP = x.x.x.x(fritz), processing nonce payload&lt;br /&gt;7|Aug 26 2016|13:15:45|715047|||||Group = x.x.x.x(fritz), IP = x.x.x.x(fritz), processing SA payload&lt;br /&gt;7|Aug 26 2016|13:15:45|715047|||||Group = x.x.x.x(fritz), IP = x.x.x.x(fritz), processing hash payload&lt;br /&gt;7|Aug 26 2016|13:15:45|713236|||||IP = x.x.x.x(fritz), IKE_DECODE RECEIVED Message (msgid=6b7e66e9) with payloads : HDR + HASH (8) + SA (1) + NONCE (10) + KE (4) + ID (5) + ID (5) + NONE (0) total length : 292&lt;br /&gt;7|Aug 26 2016|13:15:45|714003|||||IP = x.x.x.x(fritz), IKE Responder starting QM: msg id = 6b7e66e9&lt;br /&gt;7|Aug 26 2016|13:15:45|715080|||||Group = x.x.x.x(fritz), IP = x.x.x.x(fritz), Starting P1 rekey timer: 27360 seconds.&lt;br /&gt;7|Aug 26 2016|13:15:45|713121|||||IP = x.x.x.x(fritz), Keep-alive type for this connection: DPD&lt;br /&gt;5|Aug 26 2016|13:15:45|713119|||||Group = x.x.x.x(fritz), IP = x.x.x.x(fritz), PHASE 1 COMPLETED&lt;br /&gt;6|Aug 26 2016|13:15:45|113009|||||AAA retrieved default group policy (GroupPolicy_x.x.x.x(fritz)) for user = x.x.x.x(fritz)&lt;br /&gt;7|Aug 26 2016|13:15:45|713236|||||IP = x.x.x.x(fritz), IKE_DECODE SENDING Message (msgid=0) with payloads : HDR + ID (5) + HASH (8) + VENDOR (13) + NONE (0) total length : 84&lt;br /&gt;7|Aug 26 2016|13:15:45|715046|||||Group = x.x.x.x(fritz), IP = x.x.x.x(fritz), constructing dpd vid payload&lt;br /&gt;7|Aug 26 2016|13:15:45|715076|||||Group = x.x.x.x(fritz), IP = x.x.x.x(fritz), Computing hash for ISAKMP&lt;br /&gt;7|Aug 26 2016|13:15:45|715046|||||Group = x.x.x.x(fritz), IP = x.x.x.x(fritz), constructing hash payload&lt;br /&gt;7|Aug 26 2016|13:15:45|715046|||||Group = x.x.x.x(fritz), IP = x.x.x.x(fritz), constructing ID payload&lt;br /&gt;7|Aug 26 2016|13:15:45|713906|||||IP = x.x.x.x(fritz), Connection landed on tunnel_group x.x.x.x(fritz)&lt;br /&gt;6|Aug 26 2016|13:15:45|713905|||||Group = x.x.x.x(fritz), IP = x.x.x.x(fritz), Floating NAT-T from x.x.x.x(fritz) port 500 to x.x.x.x(fritz) port 4500&lt;br /&gt;6|Aug 26 2016|13:15:45|713172|||||Group = x.x.x.x(fritz), IP = x.x.x.x(fritz), Automatic NAT Detection Status:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Remote end&amp;nbsp;&amp;nbsp; IS&amp;nbsp;&amp;nbsp; behind a NAT device&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; This&amp;nbsp;&amp;nbsp; end is NOT behind a NAT device&lt;br /&gt;7|Aug 26 2016|13:15:45|715076|||||Group = x.x.x.x(fritz), IP = x.x.x.x(fritz), Computing hash for ISAKMP&lt;br /&gt;7|Aug 26 2016|13:15:45|715047|||||Group = x.x.x.x(fritz), IP = x.x.x.x(fritz), processing hash payload&lt;br /&gt;7|Aug 26 2016|13:15:45|714011|||||Group = x.x.x.x(fritz), IP = x.x.x.x(fritz), ID_IPV4_ADDR ID received&lt;br /&gt;7|Aug 26 2016|13:15:45|715047|||||Group = x.x.x.x(fritz), IP = x.x.x.x(fritz), processing ID payload&lt;br /&gt;7|Aug 26 2016|13:15:45|713236|||||IP = x.x.x.x(fritz), IKE_DECODE RECEIVED Message (msgid=0) with payloads : HDR + ID (5) + HASH (8) + NONE (0) total length : 64&lt;br /&gt;6|Aug 26 2016|13:15:45|302015|x.x.x.x(fritz)|4500|x.x.x.x(asa)|4500|Built inbound UDP connection 388810 for outside:x.x.x.x(fritz)/4500 (x.x.x.x(fritz)/4500) to identity:x.x.x.x(asa)/4500 (x.x.x.x(asa)/4500)&lt;br /&gt;7|Aug 26 2016|13:15:45|713236|||||IP = x.x.x.x(fritz), IKE_DECODE SENDING Message (msgid=0) with payloads : HDR + KE (4) + NONCE (10) + VENDOR (13) + VENDOR (13) + VENDOR (13) + VENDOR (13) + NAT-D (20) + NAT-D (20) + NONE (0) total length : 368&lt;br /&gt;7|Aug 26 2016|13:15:45|713906|||||Group = x.x.x.x(fritz), IP = x.x.x.x(fritz), Generating keys for Responder...&lt;br /&gt;7|Aug 26 2016|13:15:45|713906|||||IP = x.x.x.x(fritz), Connection landed on tunnel_group x.x.x.x(fritz)&lt;br /&gt;7|Aug 26 2016|13:15:45|713906|||||IP = x.x.x.x(fritz), computing NAT Discovery hash&lt;br /&gt;7|Aug 26 2016|13:15:45|715046|||||IP = x.x.x.x(fritz), constructing NAT-Discovery payload&lt;br /&gt;7|Aug 26 2016|13:15:45|713906|||||IP = x.x.x.x(fritz), computing NAT Discovery hash&lt;br /&gt;7|Aug 26 2016|13:15:45|715046|||||IP = x.x.x.x(fritz), constructing NAT-Discovery payload&lt;br /&gt;7|Aug 26 2016|13:15:45|715048|||||IP = x.x.x.x(fritz), Send Altiga/Cisco VPN3000/Cisco ASA GW VID&lt;br /&gt;7|Aug 26 2016|13:15:45|715046|||||IP = x.x.x.x(fritz), constructing VID payload&lt;br /&gt;7|Aug 26 2016|13:15:45|715038|||||IP = x.x.x.x(fritz), Constructing ASA spoofing IOS Vendor ID payload (version: 1.0.0, capabilities: 20000001)&lt;br /&gt;7|Aug 26 2016|13:15:45|715048|||||IP = x.x.x.x(fritz), Send IOS VID&lt;br /&gt;7|Aug 26 2016|13:15:45|715046|||||IP = x.x.x.x(fritz), constructing xauth V6 VID payload&lt;br /&gt;7|Aug 26 2016|13:15:45|715046|||||IP = x.x.x.x(fritz), constructing Cisco Unity VID payload&lt;br /&gt;7|Aug 26 2016|13:15:45|715046|||||IP = x.x.x.x(fritz), constructing nonce payload&lt;br /&gt;7|Aug 26 2016|13:15:45|715046|||||IP = x.x.x.x(fritz), constructing ke payload&lt;br /&gt;7|Aug 26 2016|13:15:45|713906|||||IP = x.x.x.x(fritz), computing NAT Discovery hash&lt;br /&gt;7|Aug 26 2016|13:15:45|715047|||||IP = x.x.x.x(fritz), processing NAT-Discovery payload&lt;br /&gt;7|Aug 26 2016|13:15:45|713906|||||IP = x.x.x.x(fritz), computing NAT Discovery hash&lt;br /&gt;7|Aug 26 2016|13:15:45|715047|||||IP = x.x.x.x(fritz), processing NAT-Discovery payload&lt;br /&gt;7|Aug 26 2016|13:15:45|715047|||||IP = x.x.x.x(fritz), processing nonce payload&lt;br /&gt;7|Aug 26 2016|13:15:45|715047|||||IP = x.x.x.x(fritz), processing ISA_KE payload&lt;br /&gt;7|Aug 26 2016|13:15:45|715047|||||IP = x.x.x.x(fritz), processing ke payload&lt;br /&gt;7|Aug 26 2016|13:15:45|713236|||||IP = x.x.x.x(fritz), IKE_DECODE RECEIVED Message (msgid=0) with payloads : HDR + KE (4) + NONCE (10) + NAT-D (20) + NAT-D (20) + NONE (0) total length : 292&lt;br /&gt;7|Aug 26 2016|13:15:45|713236|||||IP = x.x.x.x(fritz), IKE_DECODE SENDING Message (msgid=0) with payloads : HDR + SA (1) + VENDOR (13) + VENDOR (13) + NONE (0) total length : 128&lt;br /&gt;7|Aug 26 2016|13:15:45|715046|||||IP = x.x.x.x(fritz), constructing Fragmentation VID + extended capabilities payload&lt;br /&gt;7|Aug 26 2016|13:15:45|715046|||||IP = x.x.x.x(fritz), constructing NAT-Traversal VID ver RFC payload&lt;br /&gt;7|Aug 26 2016|13:15:45|715046|||||IP = x.x.x.x(fritz), constructing ISAKMP SA payload&lt;br /&gt;7|Aug 26 2016|13:15:45|715028|||||IP = x.x.x.x(fritz), IKE SA Proposal # 1, Transform # 0 acceptable&amp;nbsp; Matches global IKE entry # 1&lt;br /&gt;7|Aug 26 2016|13:15:45|715047|||||IP = x.x.x.x(fritz), processing IKE SA payload&lt;br /&gt;7|Aug 26 2016|13:15:45|715047|||||IP = x.x.x.x(fritz), processing VID payload&lt;br /&gt;7|Aug 26 2016|13:15:45|715049|||||IP = x.x.x.x(fritz), Received NAT-Traversal ver 02 VID&lt;br /&gt;7|Aug 26 2016|13:15:45|715047|||||IP = x.x.x.x(fritz), processing VID payload&lt;br /&gt;7|Aug 26 2016|13:15:45|715047|||||IP = x.x.x.x(fritz), processing VID payload&lt;br /&gt;7|Aug 26 2016|13:15:45|715049|||||IP = x.x.x.x(fritz), Received NAT-Traversal ver 03 VID&lt;br /&gt;7|Aug 26 2016|13:15:45|715047|||||IP = x.x.x.x(fritz), processing VID payload&lt;br /&gt;7|Aug 26 2016|13:15:45|715049|||||IP = x.x.x.x(fritz), Received NAT-Traversal RFC VID&lt;br /&gt;7|Aug 26 2016|13:15:45|715047|||||IP = x.x.x.x(fritz), processing VID payload&lt;br /&gt;7|Aug 26 2016|13:15:45|715049|||||IP = x.x.x.x(fritz), Received DPD VID&lt;br /&gt;7|Aug 26 2016|13:15:45|715047|||||IP = x.x.x.x(fritz), processing VID payload&lt;br /&gt;7|Aug 26 2016|13:15:45|715049|||||IP = x.x.x.x(fritz), Received xauth V6 VID&lt;br /&gt;7|Aug 26 2016|13:15:45|715047|||||IP = x.x.x.x(fritz), processing VID payload&lt;br /&gt;7|Aug 26 2016|13:15:45|715049|||||IP = x.x.x.x(fritz), Received Cisco Unity client VID&lt;br /&gt;7|Aug 26 2016|13:15:45|715047|||||IP = x.x.x.x(fritz), processing VID payload&lt;br /&gt;7|Aug 26 2016|13:15:45|715047|||||IP = x.x.x.x(fritz), processing VID payload&lt;br /&gt;7|Aug 26 2016|13:15:45|713906|||||IP = x.x.x.x(fritz), Oakley proposal is acceptable&lt;br /&gt;7|Aug 26 2016|13:15:45|715047|||||IP = x.x.x.x(fritz), processing SA payload&lt;br /&gt;7|Aug 26 2016|13:15:45|713236|||||IP = x.x.x.x(fritz), IKE_DECODE RECEIVED Message (msgid=0) with payloads : HDR + SA (1) + VENDOR (13) + VENDOR (13) + VENDOR (13) + VENDOR (13) + VENDOR (13) + VENDOR (13) + VENDOR (13) + VENDOR (13) + VENDOR (13) + NONE (0) total length : 256&lt;br /&gt;6|Aug 26 2016|13:15:45|302015|x.x.x.x(fritz)|500|x.x.x.x(asa)|500|Built inbound UDP connection 388809 for outside:x.x.x.x(fritz)/500 (x.x.x.x(fritz)/500) to identity:x.x.x.x(asa)/500 (x.x.x.x(asa)/500)&lt;br /&gt;7|Aug 26 2016|13:15:45|609001|x.x.x.x(fritz)||||Built local-host outside:x.x.x.x(fritz)&lt;/p&gt;
&lt;p&gt;-----------------------&lt;/p&gt;
&lt;p&gt;Vielen Dank&lt;/p&gt;
&lt;p&gt;und ein sch&amp;ouml;nes Wochenende.&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;Gru&amp;szlig; Bernd&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: IPSec S2S UTM135 &lt;-&gt; Cisco ASA Aufbau nur von ASA möglich</title><link>https://community.sophos.com/thread/304291?ContentTypeID=1</link><pubDate>Thu, 25 Aug 2016 16:44:32 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:1eb6c369-6086-4104-af28-832485c56463</guid><dc:creator>BAlfson</dc:creator><description>&lt;p&gt;Bernd, bitte, stelle Debug ab! [;)]&amp;nbsp; Und dann uns etwa 60 Zeilen zeigen.&lt;/p&gt;
&lt;p&gt;MfG - Bob&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: IPSec S2S UTM135 &lt;-&gt; Cisco ASA Aufbau nur von ASA möglich</title><link>https://community.sophos.com/thread/304220?ContentTypeID=1</link><pubDate>Thu, 25 Aug 2016 06:54:33 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:8a343f45-9b00-4c3b-b457-f72b29032b8f</guid><dc:creator>bpman</dc:creator><description>&lt;p&gt;Hier noch ein Auszug aus dem Log mit Debug-Option&lt;/p&gt;
&lt;p&gt;Dabei st&amp;ouml;ren mich die rot markierten Zeilen.&lt;/p&gt;
&lt;p&gt;------------------------------------&lt;/p&gt;
&lt;p&gt;2016:08:25-13:45:49 asg12 pluto[588]: | *received 92 bytes from x.x.x.xASA:4500 on eth1&lt;br /&gt;2016:08:25-13:45:49 asg12 pluto[588]: | **parse ISAKMP Message:&lt;br /&gt;2016:08:25-13:45:49 asg12 pluto[588]: | initiator cookie:&lt;br /&gt;2016:08:25-13:45:49 asg12 pluto[588]: | a6 7b 13 2d 9d 40 a3 b7&lt;br /&gt;2016:08:25-13:45:49 asg12 pluto[588]: | responder cookie:&lt;br /&gt;2016:08:25-13:45:49 asg12 pluto[588]: | b2 e3 90 89 05 84 ee 82&lt;br /&gt;2016:08:25-13:45:49 asg12 pluto[588]: | next payload type: ISAKMP_NEXT_HASH&lt;br /&gt;2016:08:25-13:45:49 asg12 pluto[588]: | ISAKMP version: ISAKMP Version 1.0&lt;br /&gt;2016:08:25-13:45:49 asg12 pluto[588]: | exchange type: ISAKMP_XCHG_INFO&lt;br /&gt;2016:08:25-13:45:49 asg12 pluto[588]: | flags: ISAKMP_FLAG_ENCRYPTION&lt;br /&gt;2016:08:25-13:45:49 asg12 pluto[588]: | message ID: 57 a8 9f bd&lt;br /&gt;2016:08:25-13:45:49 asg12 pluto[588]: | length: 92&lt;br /&gt;2016:08:25-13:45:49 asg12 pluto[588]: | ICOOKIE: a6 7b 13 2d 9d 40 a3 b7&lt;br /&gt;2016:08:25-13:45:49 asg12 pluto[588]: | RCOOKIE: b2 e3 90 89 05 84 ee 82&lt;br /&gt;2016:08:25-13:45:49 asg12 pluto[588]: | peer: 52 c1 e2 8d&lt;br /&gt;2016:08:25-13:45:49 asg12 pluto[588]: | state hash entry 29&lt;br /&gt;2016:08:25-13:45:49 asg12 pluto[588]: | state object #1 found, in STATE_MAIN_I4&lt;br /&gt;2016:08:25-13:45:49 asg12 pluto[588]: | ***parse ISAKMP Hash Payload:&lt;br /&gt;2016:08:25-13:45:49 asg12 pluto[588]: | next payload type: ISAKMP_NEXT_D&lt;br /&gt;2016:08:25-13:45:49 asg12 pluto[588]: | length: 24&lt;br /&gt;2016:08:25-13:45:49 asg12 pluto[588]: | ***parse ISAKMP Delete Payload:&lt;br /&gt;2016:08:25-13:45:49 asg12 pluto[588]: | next payload type: ISAKMP_NEXT_NONE&lt;br /&gt;2016:08:25-13:45:49 asg12 pluto[588]: | length: 28&lt;br /&gt;2016:08:25-13:45:49 asg12 pluto[588]: | DOI: ISAKMP_DOI_IPSEC&lt;br /&gt;2016:08:25-13:45:49 asg12 pluto[588]: | protocol ID: 1&lt;br /&gt;2016:08:25-13:45:49 asg12 pluto[588]: | SPI size: 16&lt;br /&gt;2016:08:25-13:45:49 asg12 pluto[588]: | number of SPIs: 1&lt;br /&gt;2016:08:25-13:45:49 asg12 pluto[588]: | removing 12 bytes of padding&lt;br /&gt;2016:08:25-13:45:49 asg12 pluto[588]: | ICOOKIE: a6 7b 13 2d 9d 40 a3 b7&lt;br /&gt;2016:08:25-13:45:49 asg12 pluto[588]: | RCOOKIE: b2 e3 90 89 05 84 ee 82&lt;br /&gt;2016:08:25-13:45:49 asg12 pluto[588]: | peer: 52 c1 e2 8d&lt;br /&gt;2016:08:25-13:45:49 asg12 pluto[588]: | state hash entry 29&lt;br /&gt;2016:08:25-13:45:49 asg12 pluto[588]: | state object #1 found, in STATE_MAIN_I4&lt;br /&gt;2016:08:25-13:45:49 asg12 pluto[588]: &amp;quot;S_LRA&amp;quot;&lt;strong&gt; #1: &lt;span style="color:#ff0000;"&gt;received Delete SA payload: deleting ISAKMP State #1&lt;/span&gt;&lt;/strong&gt;&lt;br /&gt;2016:08:25-13:45:49 asg12 pluto[588]: |&lt;span style="color:#ff0000;"&gt;&lt;strong&gt; deleting unestablished phase2 state #4&lt;/strong&gt;&lt;/span&gt;&lt;br /&gt;2016:08:25-13:45:49 asg12 pluto[588]: | ICOOKIE: a6 7b 13 2d 9d 40 a3 b7&lt;br /&gt;2016:08:25-13:45:49 asg12 pluto[588]: | RCOOKIE: b2 e3 90 89 05 84 ee 82&lt;br /&gt;2016:08:25-13:45:49 asg12 pluto[588]: | peer: 52 c1 e2 8d&lt;br /&gt;2016:08:25-13:45:49 asg12 pluto[588]: | state hash entry 29&lt;br /&gt;2016:08:25-13:45:49 asg12 pluto[588]: | &lt;span style="color:#ff0000;"&gt;&lt;strong&gt;deleting unestablished phase2 state #3&lt;/strong&gt;&lt;/span&gt;&lt;br /&gt;2016:08:25-13:45:49 asg12 pluto[588]: | ICOOKIE: a6 7b 13 2d 9d 40 a3 b7&lt;br /&gt;2016:08:25-13:45:49 asg12 pluto[588]: | RCOOKIE: b2 e3 90 89 05 84 ee 82&lt;br /&gt;2016:08:25-13:45:49 asg12 pluto[588]: | peer: 52 c1 e2 8d&lt;br /&gt;2016:08:25-13:45:49 asg12 pluto[588]: | state hash entry 29&lt;br /&gt;2016:08:25-13:45:49 asg12 pluto[588]: | &lt;span style="color:#ff0000;"&gt;&lt;strong&gt;deleting unestablished phase2 state #2&lt;/strong&gt;&lt;/span&gt;&lt;br /&gt;2016:08:25-13:45:49 asg12 pluto[588]: | ICOOKIE: a6 7b 13 2d 9d 40 a3 b7&lt;br /&gt;2016:08:25-13:45:49 asg12 pluto[588]: | RCOOKIE: b2 e3 90 89 05 84 ee 82&lt;br /&gt;2016:08:25-13:45:49 asg12 pluto[588]: | peer: 52 c1 e2 8d&lt;br /&gt;2016:08:25-13:45:49 asg12 pluto[588]: | state hash entry 29&lt;br /&gt;2016:08:25-13:45:49 asg12 pluto[588]: | del: a6 7b 13 2d 9d 40 a3 b7 b2 e3 90 89 05 84 ee 82&lt;br /&gt;2016:08:25-13:45:49 asg12 pluto[588]: | next event EVENT_NAT_T_KEEPALIVE in 60 seconds&lt;/p&gt;
&lt;p&gt;------------------------------------&lt;/p&gt;
&lt;p&gt;Gru&amp;szlig; Bernd&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: IPSec S2S UTM135 &lt;-&gt; Cisco ASA Aufbau nur von ASA möglich</title><link>https://community.sophos.com/thread/304170?ContentTypeID=1</link><pubDate>Thu, 25 Aug 2016 01:22:31 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:4cd19dec-ac46-4920-a07d-215b40cf9006</guid><dc:creator>bpman</dc:creator><description>&lt;p&gt;Hallo Bob,&lt;/p&gt;
&lt;p&gt;in den Advanced Options / Preshared Key Settings ist die &amp;ouml;ffentliche Adresse der Fritzbox eingetragen.&lt;/p&gt;
&lt;p&gt;In der Remote Gateway Konfiguration ist bei VPN ID die &amp;ouml;ffentliche Adress der ASA eingetragen.&lt;/p&gt;
&lt;p&gt;Funktioniert auch ohne diesen Eintrag aber sicher ist sicher [:)]&lt;/p&gt;
&lt;p&gt;Kann es sein das die UTM die Reverseaufl&amp;ouml;sung beim Aufbau der Verbindung pr&amp;uuml;ft? Da gibt es noch einen Fehler den ich aber gerade mit dem ISP kl&amp;auml;re.&lt;/p&gt;
&lt;p&gt;Ein Ping hinter der ASA in Richtung UTM baut sofort den Tunnel auf und ich kann auf beiden Seiten arbeiten.&lt;/p&gt;
&lt;p&gt;Versuche ich aber den Tunnel von der UTM aus aufzubauen passiert nichts.&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;Gru&amp;szlig; Bernd&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: IPSec S2S UTM135 &lt;-&gt; Cisco ASA Aufbau nur von ASA möglich</title><link>https://community.sophos.com/thread/304116?ContentTypeID=1</link><pubDate>Wed, 24 Aug 2016 12:01:15 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:7db312cc-e280-4a56-807f-56572816ddfe</guid><dc:creator>BAlfson</dc:creator><description>&lt;p&gt;(Sorry, my German-speaking brain isn&amp;#39;t creating thoughts at the moment. [:(])&lt;/p&gt;
&lt;p&gt;My first guess would be that the &amp;#39;VPN ID&amp;#39; in &amp;#39;Preshared key settings&amp;#39; is not the static public IP on the Fritzbox.&lt;/p&gt;
&lt;p&gt;MfG - Bob (Bitte auf Deutsch weiterhin.)&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item></channel></rss>