I want to force internet traffic through Lan2lan tunnel for filtering

Unanswered Question
Nov 5th, 2007

I currently have an asa5520 configured to allow clients w/ a remote access vpn client to connect. once connected, they can surf the internet and the web pages are filtered through our internal filter. This is the desired effect.

My problem is that I need to build a Lan2lan vpn connection with an asa5505. The vpn connection is made and I have full network access - files / email / etc. The problem is when I surf the web on the PC that is connected to the 5505 goes straight out to the internet and not through the tunnel to our web filtering device. I'm assuming the problem is on the 5505 device. Please point me in the direction on how to force all traffic (once the VPN connection is established) on the 5505 to go through the tunnel to the 5520 device for web filtering.

I have this problem too.
0 votes
  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 5 (1 ratings)
acomiskey Tue, 11/06/2007 - 06:07

You must define all traffic as interesting on the l2l tunnel. So you crypto acl on the headend 5520 would be like this (if is remote network inside 5505)....

access-list crytpo extended permit ip any

and the 5505 would be...

access-list crypto extended permit ip any

This will force all traffic from inside the 5505 over the tunnel.

bkootstra Tue, 11/06/2007 - 08:32

Thanks. It was a Duh moment. I had those statements in the ASA's except that the 2nd statement had my internal network rather than "ANY" for the 5505. Didn't even dawn on me. Thanks again.

shaw.chris Tue, 10/07/2008 - 23:59


Would the 'NONAT' statement need to be altered to match this as well?


This Discussion