ASA 5510 Routing Question.

Answered Question
Mar 25th, 2008
User Badges:

Forgive me if this get confusing.


I have a new ASA 5510, I have set it up for VPN use. I can vpn via IPSEC and connect to 2 of my subnets .0 and .64 (we have 4 subnets in our range) I can ping, http(s), connect to shares, SSH etc. I am using the ACL from our outgoing VPN box so I nothing there should be wrong. The problem I am having is getting to our lab network which is on the .128 subnet. I can't ping, connect, http anything.


Is there some special routing I need to do in order for people who VPN in to see that subnet? (For testing purposes the ASA is behind the firewall and connected directly to .0 subnet so I know it's not the firewall and everything else on that subnet can see our lab.)


Thanks for helping out the new guy.

Shawn

Correct Answer by Collin Clark about 9 years 2 months ago

Shawn-


Your .0 & .64 subnets are considered 'interesting traffic' (by an ACL) and they are not NAT'd and sent across the VPN tunnel. You need to add the .128 subnet to both the ACL that says no NAT and that specifies interesting traffic. If you run into any snags, post a sanitized config and we'll be able to give a more detailed answer.


HTH

  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 5 (1 ratings)
Loading.
Correct Answer
Collin Clark Wed, 03/26/2008 - 06:37
User Badges:
  • Purple, 4500 points or more

Shawn-


Your .0 & .64 subnets are considered 'interesting traffic' (by an ACL) and they are not NAT'd and sent across the VPN tunnel. You need to add the .128 subnet to both the ACL that says no NAT and that specifies interesting traffic. If you run into any snags, post a sanitized config and we'll be able to give a more detailed answer.


HTH

shawnreis Wed, 03/26/2008 - 11:06
User Badges:

I currently only have 1 ACL in place. Should I have another one?

Collin Clark Wed, 03/26/2008 - 11:41
User Badges:
  • Purple, 4500 points or more

Cisco suggests using two, but it's common to only see one. Don't worry about creating another ACL.

Actions

This Discussion