Cisco ASA 5510 Ver. 8.0

Unanswered Question

Hello,


We currently have an ASA 5510 setup for remote VPN purpose only. My question is, is it better to run VPN-POOL on ASA with the same subnet of the INSIDE interface or have the VPN-POOL on a separate subnet. I notice if we have the POOL on the same subnet as the INSIDE interface then VPN client also receives the INSIDE interface include in their gateway address VPN adapter.


Example


Outside IP 192.168.0.1

Inside IP 192.168.100.1

VPN-POOL 192.168.100.50-192.168.100.100

Or

VPN-POOL 192.168.200.50-192.168.200.100


  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Loading.
acomiskey Mon, 11/24/2008 - 16:41
User Badges:
  • Green, 3000 points or more

Always separate. Use the 200 pool.

mkkeyan Mon, 11/24/2008 - 23:05
User Badges:

it will work, but you cna t access your inside hosts

Actions

This Discussion