cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
463
Views
0
Helpful
3
Replies

vpn client access to internal server via outside address

acomiskey
Level 10
Level 10

Is is possible for a remote access vpn client to connect to a server on the inside or dmz with it's outside address? ASA 7.2.1

3 Replies 3

acomiskey
Level 10
Level 10

Split tunneling would obviously work, but is there any way without enabling split tunnel?

Is there a way to selectively rewrite dns (dns doctoring) when requests are from certain subnet (vpn client)?

I have what sounds like the same problem. I have a mail server on a DMZ net off of a ASA5510. I have things set up so I can access it from a) the internet and b) the internal lan, BUT users who come in using the VPN cannot connect. They do resolve the address of the mail server to the internal address, but they can never connect.

I have thought about using a split DNS that just gives the VPN users the external IP address of the mail server, and forwards all the other addresses to the internal DNS servers, but that seems like a kludge.

For the record, the company info is incorrect on my account. I am no longer with Cisco. It was fun when I was though.

No, your problem is not the same. You need to add the dmz traffic to your interesting traffic in your crypto acl and also add nat exemption on dmz.

access-list permit ip

access-list dmz_nat0_outbound permit ip host

nat (dmz) 0 access-list dmz_nat0_outbound

I am attempting to use a pair of CSS which resolve to public ip only.

edit: jdehnert, check your other post

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card