×

Warning message

  • Cisco Support Forums is in Read Only mode while the site is being migrated.
  • Cisco Support Forums is in Read Only mode while the site is being migrated.

Hairpin VPN on OUTSIDE interface

Answered Question
Jul 30th, 2012
User Badges:

Hairping VPN on OUTSIDE interface


What I currently have is SSL Anyconnect VPN connections to the ASA which is working fine.


I want to tunnel all networks back through the ASA.

Any web connections will go to the ASA and haripin back out the OUTSIDE interface to get web access.


I have a static route on the ASA for creating the VPN

route OUTSIDE 0.0.0.0 0.0.0.0 <PUBLIC_IP>

NAT exemption is in place for creating the VPN

nat (INSIDE,OUTSIDE) source static any any destination static VPN_POOL_OG VPN_POOL_OG

What I need is the configuration to create the VPN hairpin for internet traffic.

Any help is greatly appeciated.

VPNHairpin.jpg                  

Correct Answer by Javier Portuguez about 5 years 2 weeks ago

Hi Thomas,


You need the following:


1)

same-security-traffic permit intra-interface


2)

VPN pool  = 192.168.3.0/24


object network obj-vpnpool

     subnet 192.168.3.0 255.255.255.0

     nat (outside,outside) dynamic interface

!


Please let me know


Rate any post you find helpful.

  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 5 (2 ratings)
Loading.
Correct Answer
Javier Portuguez Mon, 07/30/2012 - 07:30
User Badges:
  • Red, 2250 points or more

Hi Thomas,


You need the following:


1)

same-security-traffic permit intra-interface


2)

VPN pool  = 192.168.3.0/24


object network obj-vpnpool

     subnet 192.168.3.0 255.255.255.0

     nat (outside,outside) dynamic interface

!


Please let me know


Rate any post you find helpful.

Thomas Kelly Mon, 07/30/2012 - 08:03
User Badges:

Javier, you legend.

Thanks very much.

Never had a straight answer so quickly.

Cheers.

Javier Portuguez Mon, 07/30/2012 - 08:08
User Badges:
  • Red, 2250 points or more

I so happy to hear that!!


Thanks for your nice comments (5 stars), they are more valuable than any stars


Do not hesitate to count on us at any time.


Take care!!

Actions

This Discussion