Remote Access VPN issue

Unanswered Question
Jun 13th, 2007

Hi friends,

There is a ASA 7.2 acting as a VPN gateway for a Remote Access VPN.

There are primarily three networks behind the ASA inside network that are accessed by Remote VPN clients. They are:

There is an access-list on which the ASA is doing No natting and Split tunneling for these three networks.

From the above three networks, and are local network resources. The other network viz. is a remote network to the ASA and is accessible via a MPLS link to the remote network.

All the three networks are reachable from the ASA but for the remote clients, only the local networks behind the ASA are reachable viz. and The remote network on other end of MPLS is not reachable for the remote VPN clients.

Is it possible for these remote VPN users to access network (remote network to ASA)? Just wanted to know if it is technically possible and any directions/ pointers?

I am also enclosing a copy of the config for your kind reference.

Thanks a lot


I have this problem too.
0 votes
  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
acomiskey Wed, 06/13/2007 - 10:34

Without even looking at your config, my guess is that you need a route on the remote network which points to the vpn client pool subnet. Probably...

ip route

srue Thu, 06/14/2007 - 06:56

I dont think I have a solution to your problem, but your inside acl is poorly configured..

access-list inside extended permit ip host any log critical

access-list inside extended permit ip any any

access-list inside extended permit icmp any any

access-list inside extended permit tcp any any eq ftp

access-list inside extended permit tcp any any eq ftp-data

your permit ip any any statement negates anything after it (and really everything before it). You dont even need that ACL on the inside interface, unless you want to specifically deny any traffic, or specifically permit any traffic while denying others. your permit ip any any causes EVERYthing to be allowed through.


This Discussion