I'm having a problem trying to have a anyconnect client hairpin to the Internet on a Cisco2821 with 12.4(22)T.
I believe my nat is correct. I'm using a route-map for NAT and it includes the VPN pool. I also include the vpn-pool in no-nat.
The vpn-pool is not directly conected, so I created a loopback interface with the same network as the vpn-pool.
I suspect the problem is the sslvpn virtual interface SSLVPN-VIF0. When I use "ip debug packet detail". I see the packets directed toward my default gatway, but nothing appears in the nat tables. Since the sslvpn is using a virtual interface, is there a way to define it as "ip nat inside"?
has anyone had any luck with sslvpn to hairpin?