cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
852
Views
5
Helpful
2
Replies

ASA Hairpinning

Ericunicast
Level 1
Level 1

I would like to configure ASA 5510 to allow VPN clients access to the network behind the firewall, IPsec vpn tunnels, and internet access.

Is that hairpinning? How do I configure to allow internet access?

It is already setup to allow access to the network, just not the internet.

Thanks.

2 Replies 2

JORGE RODRIGUEZ
Level 10
Level 10

Eric, from what I have read hairpining would be if you were using what is refer as public internet on a stick to allow vpn clients to asa outside internet without using split tunneling in asa. You could either use with split tunneling or outside nat enabling hairpining with same-security-traffic permit intra-interface

Configuring split tunneling

http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a0080702999.shtml

Or public internet on a stick.

same-security-traffic permit intra-interface allows the traffic to exit out on the interface it was received on

global (outside) 1 interface

nat (outside) 1

rate any helpful post if it helps

HTH

Jorge

Jorge Rodriguez

Your configuration issue is split tunnel, than say Jorge.

Hairpining is other concept.

Review Cisco Networking products for a $25 gift card