I need to make users connected with vpn client to central office's lan, going to internet using the central office's internet connection. I mean wihout having split-tunnel and without using an internal proxy. I would like to know if it is possible with PIX or ASA. I think it's like to tell to have traffic going in and out the firewall using the same outside interface. Thank you very much in advance for your appreciated support.
As far as routing is concern, if you connect to the ASA inside interface, it would be different to when you are connecting to the outside interface.
When connecting to the outside, the VPN Pool would be routed to the outside interface, and when connecting to the inside interface, now the VPN Pool would be routed to the inside interface, hence the NAT statement will also change to the inside interface instead of outside.
It will not be a true test of when VPN is connected via the outside interface.
We have configured the outside and inside Interface with official ipv6 adresses, set a default route on outside Interface to our router, we also have definied a rule , which also gets hits, to permit tcp from inside Interface to any6.
In Syslog I also se...