cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
538
Views
5
Helpful
3
Replies

EZVPN and ASA, with NEM

cuthbert-cisco
Level 1
Level 1

We have setup a site to connect to the ASA with ezvpn and nem, which works fine, but we also want internet based traffic to be in the tunnel then go out through the asa. This means that it arrives encrypted on the same interface as we want to send it out to the net. This works fine with the cisco pc client but not these sites?

My only possible thought is the tunneled default route option and send the packet to an internal router before it gets bounced back into the ASA - not sure if this would work. Any other ideas?

Thanks

Jon

3 Replies 3

ggilbert
Cisco Employee
Cisco Employee

Jon,

Can you give me the output of the following commands

sh run | in route

sh run | in local pool

sh run | in nat

And the network address of the remote EzVPN client.

After the EzVPN client is connected, can you run the following command and send it to me.

sh vpn-sessionsdb remote

Thanks

Gilbert

Thank you for the responses, but I've sorted it. The network range was missing from being dynamically natted for the internet.

Thanks

rkazmierczak
Level 1
Level 1

hi,

if the ASA is also the default gateway on your network (connected to the internet), the only thing you probably need to do is to make sure that the you do nat on the remote subnet so that the remote subnet can reach the internet.

This can be a bit tricky because you still have to do nat on these subnets when the destination is the HQ network.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: