05-08-2017 04:14 AM - edited 02-21-2020 09:16 PM
Help required for IPSec Vpn connection - internet not working after VPN connected
VPN connected to Cisco ASA through VPN client 5.0.07. The vpn was established and we can access the network. But same time our internet from the vpn client PC is not working.
any routing / gateway problem. I have searched a lot and found the tunnel configuration but still same issue. please suggest
vpn-tunnel-protocol ikev1
split-tunnel-policy excludespecified
split-tunnel-network-list value Local_Lan_access
default-domain value xxxxxxxxx
group-policy VPNGroup_1 internal
group-policy VPNGroup_1 attributes
dns-server value 192.168.10.10 87.237.197.3
vpn-tunnel-protocol ikev1
split-tunnel-policy excludespecified
split-tunnel-network-list value Local_Lan_access
05-08-2017 05:41 AM
Your split tunnel policy is excludespecified. Which means that all traffic except the one defined in the "Local_Lan_access" ACL is sent through the VPN tunnel. This includes internet traffic also. If you need this traffic to work, you need to configure a Policy NAT rule on the ASA. An example of how to do this is here:
http://www.cisco.com/c/en/us/support/docs/security/asa-5500-x-series-next-generation-firewalls/100918-asa-sslvpn-00.html#anc6
example NAT:
ciscoasa(config)# object network obj-AnyconnectPool
ciscoasa(config-network-object)# subnet 192.168.10.0 255.255.255.0
ciscoasa(config-network-object)# nat (outside,outside) dynamic interface
05-09-2017 06:27 AM
tried this solution still not working c
05-09-2017 06:27 AM
Did you also add the following command to allow traffic flow between the outside interface:
ciscoasa(config)#same-security-traffic permit intra-interface
Check the ASA nat translations to see if VPN traffic is being translated on the ASA.
05-09-2017 10:56 PM
allow traffic flow between the outside interface is also configured. can you please tell how to configure NAT translation through ASDM.
My client network is 192.168.15.0
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide