Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Community Member

Cisco 3020 - same interface

I have 2 interfaces active - public and private IPs. Clients connect to the public IP address.

Does anyone know when you're connected using the VPN client, if you can send traffic immediately back out the public interface to a server on the same subnet as the 3020? I am using a IP pool that gets assigned to the clients on the private interface side as they pass through.

Thank you,

8 REPLIES

Re: Cisco 3020 - same interface

As long as traffic routing and filtering is ok, then you should find no problems.

Community Member

Re: Cisco 3020 - same interface

Routing of all local networks are added . But what do you mean by filtering.

Community Member

Re: Cisco 3020 - same interface

In WebVPN configuration filtering option is'inherit'.

Re: Cisco 3020 - same interface

You are not using webvpn are you? since you wrote VPN client I gather it is the cisco vpn client correct? what I mean is that the concentrator has filters bound to the interfaces, private public and external check those filters and what rules do those filters have to find out whether the traffic from those clients are allowed.

Community Member

Re: Cisco 3020 - same interface

No filters are defined or applied. The VPN client traffic seems to be getting lost in the 3020. Can the 3020 decrypt a packet and then send it back out the same interface on which the encrypted packet arrived?

Re: Cisco 3020 - same interface

I have to say yes, it can since the concentrator can be defined as a hub for vpn traffic, in here I will ask you a question. Do the devices on the "outside" meaning on the public side of the concentrator know how to reach the vpn client? In other words do these devices have a route back to the concetrator to reach the vpn client's pool?

Community Member

Re: Cisco 3020 - same interface

Yes...the server has a route back to the VPN client pool, with the next hop for that network pool being the 3020 public IP.

Re: Cisco 3020 - same interface

You can go ahead and create a filter with IP traffic and debug over that filter to check if packets are sent out and received back, as well you might want to check if there is any chance that a vpn tunnel might be catching this traffic instead.

267
Views
0
Helpful
8
Replies
CreatePlease to create content