Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Community Member

EZVPN and ASA, with NEM

We have setup a site to connect to the ASA with ezvpn and nem, which works fine, but we also want internet based traffic to be in the tunnel then go out through the asa. This means that it arrives encrypted on the same interface as we want to send it out to the net. This works fine with the cisco pc client but not these sites?

My only possible thought is the tunneled default route option and send the packet to an internal router before it gets bounced back into the ASA - not sure if this would work. Any other ideas?

Thanks

Jon

3 REPLIES
Cisco Employee

Re: EZVPN and ASA, with NEM

Jon,

Can you give me the output of the following commands

sh run | in route

sh run | in local pool

sh run | in nat

And the network address of the remote EzVPN client.

After the EzVPN client is connected, can you run the following command and send it to me.

sh vpn-sessionsdb remote

Thanks

Gilbert

Community Member

Re: EZVPN and ASA, with NEM

Thank you for the responses, but I've sorted it. The network range was missing from being dynamically natted for the internet.

Thanks

Community Member

Re: EZVPN and ASA, with NEM

hi,

if the ASA is also the default gateway on your network (connected to the internet), the only thing you probably need to do is to make sure that the you do nat on the remote subnet so that the remote subnet can reach the internet.

This can be a bit tricky because you still have to do nat on these subnets when the destination is the HQ network.

283
Views
5
Helpful
3
Replies
CreatePlease to create content