07-04-2012 08:43 PM - edited 03-11-2019 04:26 PM
Hi all
I would like to block internet IP address from VPN client. I tried setup a rule by using ADSM, the rule was hitted but no blocked. Can you teach me how to do it?
Our ASA Platform:
ASA Verison: 8.0(4)
ADSM Verison: 6.4(7)
Hugo
07-05-2012 08:01 AM
What do you mean by block internet IP from VPN Client? Do you mean that you do not wnat the VPN Client to access the Internet? Do you have split tunnel configured? If you do, then you will need to disable split tunnel, and configure VPN Filter to only allow specific access.
07-06-2012 12:02 PM
Hi Hugo,
You have to find out dynamic-map associated with your remote-vpn client configuration on your ASA and apply "set reverse-route" and I have highlighted one below example for you.
crypto dynamic-map outside_dyn_map 20 set reverse-route
thanks
Rizwan Rafeek
07-06-2012 08:13 PM
Rizwan,
not quite sure why you ask Hugo to "set reverse-route" as he wants to block Internet from VPN Client.
07-07-2012 10:56 AM
In the VPN ACL you need to have the specific rules alone and deny the rest.... Also you need to deny split tunneling if any......
Always we use to restrict by specifying the limited rules in VPN ACL. If you have split tunnel u need to disable it.... if they have split tunnel then the internet traffic will get routed locally for them....
07-07-2012 06:06 PM
Hello Jennifer,
When firewall inject the default route on the VPN client computer and this newly added default-route have lower metric value and VPN-client’s pervious default-route will be set with higher metric value, as a result all traffic will fall into vpn tunnel interface on client computer and this method will cutoff illegitimate traffic, when vpn is established to a corporate network.
Those no-nat traffic will traverse inside corporate network and internet bound traffic can be dynamic-nat on the outside interface, if firewall administrator chooses to.
Hope that answers your question
Thanks
Rizwan Rafeek
07-07-2012 06:34 PM
Yeah, but "set reverse-route" has nothing to do with what you have just explained.
"set reverse-route" will inject the VPN Client pool back into the internal dynamic routing protocol as a static route, and won't do anything on the vpn client side.
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: