Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
Announcements
Step-by-Step Configuration and Troubleshooting Best Practices for the NGFW, NGIPS and AMP Technologies A Visual Guide to the Cisco Firepower Threat Defense (FTD)
Community Member

Cisco ASA 5510 Ver. 8.0

Hello,

We currently have an ASA 5510 setup for remote VPN purpose only. My question is, is it better to run VPN-POOL on ASA with the same subnet of the INSIDE interface or have the VPN-POOL on a separate subnet. I notice if we have the POOL on the same subnet as the INSIDE interface then VPN client also receives the INSIDE interface include in their gateway address VPN adapter.

Example

Outside IP 192.168.0.1

Inside IP 192.168.100.1

VPN-POOL 192.168.100.50-192.168.100.100

Or

VPN-POOL 192.168.200.50-192.168.200.100

3 REPLIES
Green

Re: Cisco ASA 5510 Ver. 8.0

Always separate. Use the 200 pool.

Community Member

Re: Cisco ASA 5510 Ver. 8.0

If x.200 is the case then will disable split-tunneling still work? We would like to see all user traffic in and out on their pc. Thanks

Community Member

Re: Cisco ASA 5510 Ver. 8.0

it will work, but you cna t access your inside hosts

132
Views
0
Helpful
3
Replies
CreatePlease to create content