08-03-2017 05:05 PM
I'm trying to set this up using only the Outside interface (nothing attached to inside at all) I've got the VPN setup and I can connect to it from the outside, but I go
For the setup I currently have, the 5508's outside interface is connected to a switch that connects to my router/
08-03-2017 06:28 PM
well there will only be one route as everything is going thru the outside interface
route outside 0.0.0.0 0.0.0.0 192.168.1.100
what is the Ip address of the outside interface of the 5508
I was just thinking about the NAT and how you subnet your 192.168.1.0
object network inside
subnet 192.168.1.0 255.255.255.128
lets make the vpn client 192.168.1.192/28
object CISCO-VPN-CLIENT
subnet 192.168.1.192 255.255.255.240
nat (outside,outside) source static CISCO-VPN-CLIENT CISCO-VPN-CLIENT destination static inside inside no-proxy-arp route-lookup
08-04-2017 05:30 AM
I apologize Richard, I incorrectly said I could ping the inside interface of the ASA, I should have said outside. The outside interface is 192.168.1.100. So would the above still be good?
Also I don't have anything setting on the inside interface. Currently no interface is configured as inside. Should I set one up?
08-04-2017 05:42 AM
Oh ok...sorry I see what your saying now. I'm creating the "inside" with that first command. Sorry it's too early and the caffeine hasn't kicked in yet. :) I'll give this a try.
08-04-2017 06:03 AM
Just to clarify
your network looks like this
PC> Internet----< outside interface Firewall /Router inside interface>--192.168.1.0/24----< outside interface 5508 VPN termination>
so what are the IP addresses of inside interface of firewall/router and outside interface of 5508?
08-04-2017 07:14 AM
Yes correct that is how the network is setup.
Instead of the route statement you have I already had one in place pointing to my gateway on lan (192.168.1.1, this is the IP of the router/firewall) The outside interface of the 5508 is that 192.168.1.100.
Also see above, I ended up changing the vpn pool to a totally different subnet when I retried everything.
08-04-2017 07:15 AM
Okay so I gave this a try, but it didn't seem to work. I also tried just putting the vpn pool into a totally separate subnet. Below is what I did.
I did the first command as you suggested.
object network inside
subnet 192.168.1.0 255.255.255.0 (I just went ahead and made it the whole subnet because I changed the VPN-POOL to be on a different one)
object VPN-POOL
subnet 192.168.50.0 255.255.255.0
nat (outside,outside) source static VPN-POOL VPN-POOL destination static inside inside no-proxy-arp route-lookup
I still was unable to get to anything on 192.168.1.0 network..
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide