ASA-SSM IPS locking out VPN Clients

Unanswered Question
Aug 22nd, 2007

Has anyone had issues with S297 / 5.1.6E1 blocking VPN IP's out? Out of the blue my users will checking Email via the VPN and the the IPS will deny the IP address, and lock them out. I have been watching my IPS Event Viewer but am at a lose. I ideas would be a great help.


Thanks,D

  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Loading.
Rodrigo Gurriti Fri, 08/24/2007 - 20:13

I don't have the same version but I'd check the events for overwrite events or check if you don't allow incoming rfc 1918 you may have some traffic coming from the vpn and being translated in as a rfc 1918 addresses.



The only thing I can think would be searching on the events log file and doing some tests after hours or off peak


Try emulate the situation while the traffic is low and would be a lot easier to read the logs.



Actions

This Discussion