ASA 5500 and VPN default gateway

Jan 20, 2007 2 Replies

I'm pulling my hair out trying to figure out why this setup does not work on my ASA 5520



Here is my setup. ASA is setup to accept VPN connections on outside interface, client connects and is assigned an IP from internal network.



Client can access internal resources fine but cannot access Internet while connected to VPN.



All IP's are real as in I'm not using NAT.



External IF: 139.23.126.35 255.255.255.240 Internal IF: 148.36.48.1 255.255.255.224



ASA default route: 139.23.126.36 VPN client address range: 148.36.48.5 to 148.36.48.30



Any suggestions on how I can configure my ASA to route vpn traffic to internal network and external (Internet)



Thanks Scott



Scott,

Hi.

By default PIX versions of FOS 6.X and earlier traffic could not exit an interface with the same security level. This changed in V7. There are a couple of commands used here, I believe the one you need would be:

same-security-traffic permit intra-interface

This allows traffic to enter and exit the same interface.

Of course if you have this already it is likley to be something else. In which case it may be an idea to post your config so that someone else who is more adept at troubleshooting than I am may be able to help.

Regards

Darren

Have you set up split tunnel?

Do you want your clients to connect -directly- to the Internet, or do you want your clients to send all Internet traffic to the ASA which will then forward it on to the Internet?

If you want the clients to send via the ASA, then you are going to have to use NAT, because whichever site receives the request is going to need to see a source IP on the packets which is one of the IPs that is routed to the ASA. Or is it the case that both of your public IP ranges are routed to the ASA already?

Join the Discussion

Have something to add? Share your thoughts — no account required.

Didn't find your answer?

Ask the community — no account required