Forwarding Cisco ASA VPN traffic to internal URL filter server?
I have currently got my Cisco VPN users and site to site VPNs going through my Cisco Concentrator. They get their web traffic monitored by an internal web filtering server (surfcontrol) as it has to pass through this then through the Cisco ASA firewall.
I have now set up Cisco VPN client connections to the Cisco ASA but the problem is when they access the internet now it instanty goes back out and the traffic is not "seen" by the internal web filter server.
PIX Firewall Software version 6.2 and higher enables you to statically configure multicast routes or use an Internet Group Management Protocol (IGMP) helper address to forward IGMP reports and leave announcements.
This is the multicast support available in this release:
Access list filters can be applied in order to multicast traffic to permit or deny specific protocols and ports.
Network Address Translation (NAT) and Port Address Translation (PAT) can be performed on the multicast packet source addresses only.
Multicast data packets with destination addresses in the 188.8.131.52/24 address range are not forwarded. But, everything else in the 184.108.40.206/8 address range is forwarded.
IGMP packets for address groups within the 220.127.116.11-18.104.22.168 range are not forwarded because these addresses are reserved for protocol use.
NAT is not performed on IGMP packets. When IGMP forwarding is configured, the PIX Firewall forwards the IGMP packets (report and leave) with the IP address of the helper interface as the source IP address.
Table of ContentsIntroductionVersion HistoryPossible Future
UpdatesDocuments PurposeNAT Operation in ASA 8.3+ SectionsRule Types
Network Object NATTwice NAT / Manual NATRule Types used per SectionNAT
Types used with Twice NAT / Manual NAT and Network Obje...
Table of Contents Introduction:This document describes details on how
NAT-T works. Background: ESP encrypts all critical information,
encapsulating the entire inner TCP/UDP datagram within an ESP header.
ESP is an IP protocol in the same sense that TCP an...