Only One user can use the VPN at a time...

Unanswered Question
Sep 26th, 2008
User Badges:


We've built a Remote Access VPN on our ASA5520 here and have run into something odd. I think so anyway.

Only one user can VPN in and actually access our network at a time. Any other users can log in but are essentially isolated. They can't access any equipment on our network.

I'm using a IP pool for VPN users of the only pingable address on that network is the first user who logged in. No one else is pingable from each other, or from any device on our network.

Has anyone seen this before?


  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
andrew-susag Fri, 09/26/2008 - 04:50
User Badges:

To add to this.

I do see the VPN connection establish on the ASDM Log window, but I do not see any log messages when I attempt to ping or access a device from the faulty connection.

From the 1 working connection, I do.

It's almost like the info is being routed elsewhere...

singhsaju Fri, 09/26/2008 - 05:43
User Badges:
  • Silver, 250 points or more

There is no config here . Can you paste it?

To solve an issue early the reason why "No one else is pingable from each other" is you are not allowin intra-interface communication:-

Add the following:-

same-security-traffic permit intra-interface

This will allow multiple VPN client connections to communicate with each other.

Post your config for a review of only 1 user at a time issue.


singhsaju Fri, 09/26/2008 - 07:29
User Badges:
  • Silver, 250 points or more

I am not sure if this issue is happening because of following observation.

The config is using ip in the VPN pool , we cannot use this ip address as this is broadcast ip in the VPN pool subnet. Do the following and then check connecting vpn clients and post results.

no ip local pool ifn_noc_ips mask

ip local pool ifn_noc_ips mask



Pls rate helpful posts


This Discussion