I am having trouble inspecting network traffic on an ASA that is being used as a VPN Concentrator. Based on some documentation I have recently come upon it eludes that this may not even be possible based on the fact the logical inspection point in the ASA is sandwiched between the firewall policy and VPN policy.
I guess my question is whether the ASA with AIP SSM is even capable of doing what I would like to do and if it is could you point towards any specific documentation that covers this configuration.
Thanks in advance for the responses.