strange asa problem

Unanswered Question
Jan 22nd, 2008
User Badges:


I have the situation in the attachment.

I've set up a remote access vpn for client 2 to access some networks behind R1 and R2. There is no NAT involved. The network uses OSPF. The routes are injected into OSPF using RRI. I've activated the same-security-traffic permit intra-interface to allow traffic to R2 also.

All is fine, all routers learn the new route but the trouble is that I can only access hosts behind R1. A traceroute from behind R2 dies in ASA. A traceroute from the vpn client doesn't even leave ASA.

To make a test I made another vpn connection profile for the inside interface and tested it with the client 1. This client is able to access all hosts, both behind R1 and R2.

What am I missing?



Gabriel Gearip

  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
acomiskey Tue, 01/22/2008 - 08:42
User Badges:
  • Green, 3000 points or more

Could you post a config?

Does it work if you add...

global (outside) 1 interface

nat (outside) 1

gabriel.gearip Tue, 01/22/2008 - 10:39
User Badges:

Yes, it works but I don't want to nat the vpn clients; also only the clients will be able to communicate with the outside world.

I will post a config on Monday when I'll get to work.



Gabriel Gearip


This Discussion