Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

How to block internet IP for vpn client

Hi all

I would like to block internet IP address from VPN client. I tried setup a rule by using ADSM, the rule was hitted but no blocked. Can you teach me how to do it?

Our ASA Platform:

ASA Verison: 8.0(4)

ADSM Verison: 6.4(7)

Hugo

6 REPLIES
Cisco Employee

How to block internet IP for vpn client

What do you mean by block internet IP from VPN Client? Do you mean that you do not wnat the VPN Client to access the Internet? Do you have split tunnel configured? If you do, then you will need to disable split tunnel, and configure VPN Filter to only allow specific access.

How to block internet IP for vpn client

Hi Hugo,

You have to find out dynamic-map associated with your remote-vpn client configuration on your ASA and apply "set reverse-route" and I have highlighted one below example for you.

crypto dynamic-map outside_dyn_map 20 set reverse-route

thanks

Rizwan Rafeek

Cisco Employee

How to block internet IP for vpn client

Rizwan,

not quite sure why you ask Hugo to "set reverse-route" as he wants to block Internet from VPN Client.

How to block internet IP for vpn client

In the VPN ACL you need to have the specific rules alone and deny the rest.... Also you need to deny split tunneling if any......

Always we use to restrict by specifying the limited rules in VPN ACL. If you have split tunnel u need to disable it.... if they have split tunnel then the internet traffic will get routed locally for them....

How to block internet IP for vpn client

Hello Jennifer,

When firewall inject the default route on the VPN client computer and this newly added default-route have lower metric value and VPN-client’s pervious default-route will be set with higher metric value, as a result all traffic will fall into vpn tunnel interface on client computer and this method will cutoff illegitimate traffic, when vpn is established to a corporate network.

Those no-nat traffic will traverse inside corporate network and internet bound traffic can be dynamic-nat on the outside interface, if firewall administrator chooses to.

Hope that answers your question

Thanks

Rizwan Rafeek

Cisco Employee

How to block internet IP for vpn client

Yeah, but "set reverse-route" has nothing to do with what you have just explained.

"set reverse-route" will inject the VPN Client pool back into the internal dynamic routing protocol as a static route, and won't do anything on the vpn client side.

1448
Views
0
Helpful
6
Replies
CreatePlease login to create content