×

Warning message

  • Cisco Support Forums is in Read Only mode while the site is being migrated.
  • Cisco Support Forums is in Read Only mode while the site is being migrated.

Can't access machines on different subnets from VPN

Unanswered Question
Jan 13th, 2010
User Badges:

I already know what you're thinking. Split Tunneling. Split Tunneling has been configured correctly.

Our default vlan is 192.168.3.0/24 and I can ping and access any and everything from the VPN to that subnet.

I have added 192.168.50.0/24 to the split tunneling ACL and routing is setup correctly on the ASA because a "show route" will display all the subnets.

when I try to ping 192.168.50.11 I see this error come up in the debugging log


Asymmetric NAT rules matched for forward and 
reverse flows; Connection for icmp src outside:192.168.5.20 dest inside: 192.168.50.11 (type 8, code 0) denied due to NAT reverse path failure.


I researched the cisco system logs on google and found the following:

305013

Error Message    %PIX|ASA-5-305013: Asymmetric NAT rules matched for forward and 
reverse flows; Connection protocol src interface_name:source_address/source_port
dest interface_name:dest_address/dest_port denied due to NAT reverse path failure.

Explanation   An attempt to connect to a mapped host using its actual address was rejected.

Recommended Action   When not on the same interface as the host using NAT, use the mapped address  instead of the actual address to connect to the host. In addition, enable the applicable inspect command if the application embeds the IP address.


I'm not exactly sure what I'm supposed to do to allow the traffic from these other subnets to pass. The default vlan works, but no other vlans allow traffic. Thanks in advance!

  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Loading.
Patrick Cameron Sat, 10/24/2015 - 00:53
User Badges:

I know this is an old thread, but thank you! As you can see from the logs below, I had a similar issue. After reading your second reply, I added an exempt rule to the NAT Rules on the ASA and everything is working perfect..I can communicate with the internal lan now. 

 

"Asymmetric NAT rules matched for forward and reverse flows; Connection for icmp src outside:VPN_Host10 dst inside:CORE-SW1 (type 8, code 0) denied due to NAT reverse path failure" 

Actions

This Discussion