05-17-2007
01:17 PM
- last edited on
02-21-2020
11:46 PM
by
cc_security_adm
I have an 871 router with SSL VPN (full client) configured and it seems to be working swimmingly, with one exception. I do not want to perform split tunneling. On the contrary, I specifically would like all of my Internet-destined traffic to travel to the router down the SSL tunnel and then, after being decrypted, head back out the same interface it came in on out to the Net (hairpin). This doesn't seem to be working for me.
I've removed all access lists to rule those out.
I've double checked my IP address pool and confirmed it is in the same range as a connected interface. This interface also has the NAT Inside command applied to it and I know that when I'm actually physically connected to the 871 that NAT works great.
Is this just not feasible, or am I possibly missing something here? I'm running 12.4(9)T1.
Thanks, in advance, for any help.
05-23-2007 10:19 AM
The ones which you have is done ic correct and feasible.
05-25-2007 06:05 AM
Thanks for the response s.j. Have you actually performed these steps and seen this work? I have spoken to a few folks who have only made this work on the ASA, not using the SSL VPN feature in IOS.
Jim
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide