Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

Anyconnect with ASA5520 issues

Hi,

I set up Remote access VPN, I get connected but no traffic.

From packet tracer seems to be OK.

Any ideeas?

Thanks!

10 REPLIES
Super Bronze

Anyconnect with ASA5520 issues

You would need to configure NAT exemption as follows:

object network obj-172.16.5.0

   subnet 172.16.5.0 255.255.255.0

object network obj-172.16.0.0

   subnet 172.16.0.0 255.255.255.224

object network obj-172.16.2.0

   subnet 172.16.2.0 255.255.254.0

object network vpn-pool

   subnet 172.16.200.0 255.255.255.0

nat (LAN-Servers,External) source static obj-172.16.5.0 obj-172.16.5.0 destination static vpn-pool vpn-pool

nat (LAN-IT,External) source static obj-172.16.0.0 obj-172.16.0.0 destination static vpn-pool vpn-pool

nat (LAN-GenPop,External) source static obj-172.16.2.0 obj-172.16.2.0 destination static vpn-pool vpn-pool

New Member

Re: Anyconnect with ASA5520 issues

Thank you.

I'm afraid it's not working, same thing like before

Now I have this:

Super Bronze

Anyconnect with ASA5520 issues

How are you trying to test? Did you use ping?

If you do, please also add the following:

policy-map global_policy
class inspection_default

   inspect icmp

And are you able to ping 172.16.0.29 after connected through AnyConnect?

New Member

Anyconnect with ASA5520 issues

I tried with ping, nothing.

I added those, still nothing.

i can't ping anything, not even 172.16.0.29.

But now, in packet tracer I have this:

Thank you!

Anyconnect with ASA5520 issues

You need to declarate the network routes for the inside network. Can you put the show output of the command "debug crypto ipsec sa"???

Saludos,
Jose Luis B.
No te olvides de calificar si te sirvio la ayuda.
Please do rate if the given information helps.

Saludos, Jose Luis B. No te olvides de calificar si te sirvio la ayuda. Please do rate if the given information helps.
New Member

Anyconnect with ASA5520 issues

No output on "debug crypto ipsec". (with sa it gives me an error)

Super Bronze

Anyconnect with ASA5520 issues

well, this is AnyConnect, so the "debug cry ipsec" is incorrect debug to use.

Can you please connect via AnyConnect, and share the output of statistics and also the route from the AnyConnect client.

Also, pls share the latest config after the changes.

New Member

Re: Anyconnect with ASA5520 issues

This is what I have:

1.png

2.png

Super Bronze

Anyconnect with ASA5520 issues

On the ASA, can you please share the details of the following once you connected through the AnyConnect and ping something:

show vpn-sessiondb detail anyconnect

New Member

Re: Anyconnect with ASA5520 issues

Yes sir!

Here you have:

389
Views
0
Helpful
10
Replies