Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements
Webcast-Catalyst9k
New Member

ASA 5510 Address Assignment

Hello,

I've got an ASA5510 which should assign an address from a local pool to the client, address-pool is e.g. 192.168.239.5-192.168.239.250, mask 255.255.255.255. the pool is assigned via Group-Policy. The Client is AnyConnect 3.0.4235

If the client connects, he gets an address 192.168.239.9(preferred) but in the Windows Network-Config the Default-Gateway is 192.168.239.11 (most time one higher than the Client-Address!!!???

shouldn't the Gateway address be the same than the Client-Address?

anyway the Client can't find a Route to the Inside Networks.

I tried to assign the address via Connection Profile (Tunnel-Group) but with the same Result

The inside Networks are complete other Address-Space, so the Addresses from the Pool are virtual Addresses.

Any Hints?

Thanks

Karl

1 ACCEPTED SOLUTION

Accepted Solutions
Cisco Employee

ASA 5510 Address Assignment

Default gateway assigned should be fine as it will just send traffic destined towards the VPN tunnel towards the tunnel.

Do you have split tunnel configured? If not, please configure split tunnel policy and split tunnel ACL.

If you do not want to configure split tunnel, then just configure the split tunnel policy.

Pls share your configuration if you don't know how to configure it.

4 REPLIES
Cisco Employee

ASA 5510 Address Assignment

Default gateway assigned should be fine as it will just send traffic destined towards the VPN tunnel towards the tunnel.

Do you have split tunnel configured? If not, please configure split tunnel policy and split tunnel ACL.

If you do not want to configure split tunnel, then just configure the split tunnel policy.

Pls share your configuration if you don't know how to configure it.

New Member

ASA 5510 Address Assignment

Hello Jennifer,

thank you for your advice, but I've now tried to configure split-tunnel (ACE with my internal networks) and I think I've tried all possibilitys: no success.

I think there is any other (simple) problem, that I don't see.

I'm sure I've already managed it, but now there is some testing with a Radius-Config, which works, but not the Tunnel.

Cisco Employee

ASA 5510 Address Assignment

can you please share your config so we can have a look at what might be the issue. thx

New Member

ASA 5510 Address Assignment

Sorry, i've found the real Problem:

an Access-List blocking udp, shame on me.

but anyway I learned a lot about "Split-Tunneling". Now everything is fine.

(I knew, it is a very simple Problem)

773
Views
0
Helpful
4
Replies
CreatePlease to create content