cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
426
Views
0
Helpful
1
Replies

ASA Hairpinning

Ericunicast
Level 1
Level 1

Does anyone know how I can setup a client vpn group to be able to terminate at an ASA and still have Internet and the ability to traverse other VPN connected sites (Hardware VPN)?

Thanks

1 Reply 1

timkaye
Level 1
Level 1

Hello.

to allow traffic to enter and exit the same interface, use the same-security-traffic command in global configuration mode.

same-security-traffic permit intra-interface.

As long as you configure the ASA and the other VPN site routers to permit traffic for the client VPN address range this will work.

Tim

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card