>[оверквотинг удален]
>> address-pool vpn-pool
>> default-group-policy DefaultRAGroup
>> tunnel-group DefaultRAGroup ipsec-attributes
>> pre-shared-key *****
>> tunnel-group DefaultRAGroup ppp-attributes
>> no authentication chap
>> authentication ms-chap-v2
> Считаю, Вам нужно посмотреть в сторону NAT-T - он и сделан для
> того, чтобы работать за NAT.Использует порт UDP 4500. Поэтому и не
> работает у вас, когда включаете. Так не нестроен проброс этого порта Проброс настроил, винду пропатчил. Теперь затыкается на 2 фазе. Ошибка 789 (моментально). По ваершарку с компа затыкается все на запросах от компа: "ISAKMP Quick Mode", ответов по ваершарку от cisco ASA нет.
Дебаг выдает:
Jul 08 00:51:37 [IKEv1]: Group = DefaultRAGroup, IP = 87.245.143.138, PHASE 1 CO
MPLETED
Jul 08 00:51:37 [IKEv1]: IP = 87.245.143.138, Keep-alive type for this connectio
n: None
Jul 08 00:51:37 [IKEv1]: IP = 87.245.143.138, Keep-alives configured on but peer
does not support keep-alives (type = None)
Jul 08 00:51:37 [IKEv1 DEBUG]: Group = DefaultRAGroup, IP = 87.245.143.138, Star
ting P1 rekey timer: 21600 seconds.
Jul 08 00:51:37 [IKEv1]: IP = 87.245.143.138, IKE_DECODE RECEIVED Message (msgid
=4bab0f43) with payloads : HDR + HASH (8) + SA (1) + NONCE (10) + ID (5) + ID (5
) + NONE (0) total length : 291
Jul 08 00:51:37 [IKEv1 DEBUG]: Group = DefaultRAGroup, IP = 87.245.143.138, proc
essing hash payload
Jul 08 00:51:37 [IKEv1 DEBUG]: Group = DefaultRAGroup, IP = 87.245.143.138, proc
essing SA payload
Jul 08 00:51:37 [IKEv1 DEBUG]: Group = DefaultRAGroup, IP = 87.245.143.138, proc
essing nonce payload
Jul 08 00:51:37 [IKEv1 DEBUG]: Group = DefaultRAGroup, IP = 87.245.143.138, proc
essing ID payload
Jul 08 00:51:37 [IKEv1]: Group = DefaultRAGroup, IP = 87.245.143.138, Received r
emote Proxy Host FQDN in ID Payload: Host Name: verge-12318352f Address 0.0.0.
0, Protocol 17, Port 1701
Jul 08 00:51:37 [IKEv1 DEBUG]: Group = DefaultRAGroup, IP = 87.245.143.138, proc
essing ID payload
Jul 08 00:51:37 [IKEv1]: Group = DefaultRAGroup, IP = 87.245.143.138, Received l
ocal Proxy Host data in ID Payload: Address 87.245.143.140, Protocol 17, Port 1
701
Jul 08 00:51:37 [IKEv1]: Group = DefaultRAGroup, IP = 87.245.143.138, Error proc
essing payload: Payload ID: 5
Jul 08 00:51:37 [IKEv1]: Group = DefaultRAGroup, IP = 87.245.143.138, QM FSM err
or (P2 struct &0x2829b5c8, mess id 0x4bab0f43)!
Jul 08 00:51:37 [IKEv1 DEBUG]: Group = DefaultRAGroup, IP = 87.245.143.138, IKE
QM Responder FSM error history (struct &0x2829b5c8) <state>, <event>: QM_DONE,
EV_ERROR-->QM_BLD_MSG2, EV_PROC_MSG-->QM_BLD_MSG2, EV_HASH_OK-->QM_BLD_MSG2, Nu
llEvent-->QM_BLD_MSG2, EV_COMP_HASH-->QM_BLD_MSG2, EV_VALIDATE_MSG-->QM_BLD_MSG2
, EV_DECRYPT_OK-->QM_BLD_MSG2, NullEvent
Jul 08 00:51:37 [IKEv1 DEBUG]: Group = DefaultRAGroup, IP = 87.245.143.138, send
ing delete/delete with reason message
Jul 08 00:51:37 [IKEv1]: Group = DefaultRAGroup, IP = 87.245.143.138, Removing p
eer from correlator table failed, no match!
Jul 08 00:51:37 [IKEv1 DEBUG]: Group = DefaultRAGroup, IP = 87.245.143.138, IKE
SA MM:d26a842d rcv'd Terminate: state MM_ACTIVE flags 0x00000042, refcnt 1, tun
cnt 0
Jul 08 00:51:37 [IKEv1 DEBUG]: Group = DefaultRAGroup, IP = 87.245.143.138, IKE
SA MM:d26a842d terminating: flags 0x01000002, refcnt 0, tuncnt 0
Jul 08 00:51:37 [IKEv1 DEBUG]: Group = DefaultRAGroup, IP = 87.245.143.138, send
ing delete/delete with reason message
Jul 08 00:51:37 [IKEv1 DEBUG]: Group = DefaultRAGroup, IP = 87.245.143.138, cons
tructing blank hash payload
Jul 08 00:51:37 [IKEv1 DEBUG]: Group = DefaultRAGroup, IP = 87.245.143.138, cons
tructing IKE delete payload
Jul 08 00:51:37 [IKEv1 DEBUG]: Group = DefaultRAGroup, IP = 87.245.143.138, cons
tructing qm hash payload
Jul 08 00:51:37 [IKEv1]: IP = 87.245.143.138, IKE_DECODE SENDING Message (msgid=
9d64c90c) with payloads : HDR + HASH (8) + DELETE (12) + NONE (0) total length :
76
Jul 08 00:51:37 [IKEv1]: Group = DefaultRAGroup, IP = 87.245.143.138, Session is
being torn down. Reason: Unknown
Jul 08 00:51:37 [IKEv1]: Ignoring msg to mark SA with dsID 4096 dead because SA
deleted
Jul 08 00:51:37 [IKEv1]: IP = 87.245.143.138, Received encrypted packet with no
matching SA, dropping
Jul 08 00:51:39 [IKEv1]: IP = 87.245.143.138, Received encrypted packet with no
matching SA, dropping
Jul 08 00:51:42 [IKEv1]: IP = 87.245.143.138, Received encrypted packet with no
matching SA, dropping
Конфиг
crypto ipsec transform-set vpn-tran esp-des esp-md5-hmac
crypto ipsec transform-set vpn-tran mode transport
crypto ipsec security-association lifetime seconds 28800
crypto ipsec security-association lifetime kilobytes 4608000
crypto dynamic-map o-d-m 10 set transform-set vpn-tran
crypto map o-map 65000 ipsec-isakmp dynamic o-d-m
crypto map o-map interface local-to-inet
crypto isakmp identity address
crypto isakmp enable local-to-inet
crypto isakmp policy 10
authentication pre-share
encryption des
hash md5
group 1
lifetime 86400
crypto isakmp policy 65535
authentication pre-share
encryption des
hash sha
group 1
lifetime 86400
crypto isakmp nat-traversal 10
group-policy DefaultRAGroup internal
group-policy DefaultRAGroup attributes
vpn-tunnel-protocol IPSec l2tp-ipsec
username root password Mu2HvbX9xenLqIVHN2gY1A== nt-encrypted
username root attributes
service-type admin
tunnel-group DefaultRAGroup general-attributes
address-pool vpn-pool
default-group-policy DefaultRAGroup
tunnel-group DefaultRAGroup ipsec-attributes
pre-shared-key *****
tunnel-group DefaultRAGroup ppp-attributes
no authentication chap
authentication ms-chap-v2
Нашел информацию, что возможна причина в ACL, но добавление строк:
access-list vpn extended permit ip any any log
crypto dynamic-map o-d-m 10 match address vpn
ситуацию не изменило. Дебаг выдает все тоже самое