cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
555
Views
0
Helpful
2
Replies

Using Tunnel Default Gateway for VPN's via ASA 5520

whiteford
Level 1
Level 1

Hi,

We monitor internal users http traffic using a product called Surfcontrol Web Filter - SCWF. This SCWF server sits on a VLAN (Cisco 3750) which also has the inside interface of the ASA and we mirror the traffic seen on the inside port to the SCWF port. It all works well.

Now the problem I have. I have just set up the remote VPN feature on the ASA and everything works along with the Internet. However the internet for the VPN users don't come inside and via this SCFW server to be monitored, instead the traffic goes back out to the outside interface.

So I though I could use the tunnel default gateway "0.0.0.0 0.0.0.0 <ip gateway> tunneled"

Am I on the right lines using this because I have tried point it to several devices inside and they no longer get internet access.

I'm just trying to treat the VPN internet access like the internal users so they get monitored.

Thanks in advance for your help.

2 Replies 2

brettmilborrow
Level 1
Level 1

This command will not fix your problem.

The traffic from the VPN users towards the internet does not cross the 3750, neither can you force it to.

You may need to install some sort of proxy service and configure your SurfControl to monitor at the proxy level. This option is potentially a better solution than using SurfControl in promiscuous mode as there is a potential some some packets to get through to the 'banned sites' before SurfControl is able to intercept the connection (busy network or slow SurfControl server.

kaachary
Cisco Employee
Cisco Employee

You can point the tunnel default gateway to SCWF ip address, if its on the same VLAN as the inside interface.

Alternatively, you can change the proxy settings on the remote user browser to point it to SCWF ip.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card