cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2126
Views
0
Helpful
6
Replies

How to block internet IP for vpn client

hugochengym
Level 1
Level 1

Hi all

I would like to block internet IP address from VPN client. I tried setup a rule by using ADSM, the rule was hitted but no blocked. Can you teach me how to do it?

Our ASA Platform:

ASA Verison: 8.0(4)

ADSM Verison: 6.4(7)

Hugo

6 Replies 6

Jennifer Halim
Cisco Employee
Cisco Employee

What do you mean by block internet IP from VPN Client? Do you mean that you do not wnat the VPN Client to access the Internet? Do you have split tunnel configured? If you do, then you will need to disable split tunnel, and configure VPN Filter to only allow specific access.

rizwanr74
Level 7
Level 7

Hi Hugo,

You have to find out dynamic-map associated with your remote-vpn client configuration on your ASA and apply "set reverse-route" and I have highlighted one below example for you.

crypto dynamic-map outside_dyn_map 20 set reverse-route

thanks

Rizwan Rafeek

Rizwan,

not quite sure why you ask Hugo to "set reverse-route" as he wants to block Internet from VPN Client.

In the VPN ACL you need to have the specific rules alone and deny the rest.... Also you need to deny split tunneling if any......

Always we use to restrict by specifying the limited rules in VPN ACL. If you have split tunnel u need to disable it.... if they have split tunnel then the internet traffic will get routed locally for them....

Hello Jennifer,

When firewall inject the default route on the VPN client computer and this newly added default-route have lower metric value and VPN-client’s pervious default-route will be set with higher metric value, as a result all traffic will fall into vpn tunnel interface on client computer and this method will cutoff illegitimate traffic, when vpn is established to a corporate network.

Those no-nat traffic will traverse inside corporate network and internet bound traffic can be dynamic-nat on the outside interface, if firewall administrator chooses to.

Hope that answers your question

Thanks

Rizwan Rafeek

Yeah, but "set reverse-route" has nothing to do with what you have just explained.

"set reverse-route" will inject the VPN Client pool back into the internal dynamic routing protocol as a static route, and won't do anything on the vpn client side.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card