Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Community Member

VPN Help

I need to allow 192.168.6.0 accross the vpn tunnel to the 172.18.1.0 network. The 192.168.5.0 crosses the tunnel fine. I do not want 192.168.7.0 to be allowed accross the tunnel. I have attached my ASA 5505 config. Any help would be deeply appreciated

3 REPLIES

Re: VPN Help

Hi Raymond,

Issue the following exactly.

access-list inside_nat0_outbound extended permit ip 192.168.6.0 255.255.255.0 172.18.1.0 255.255.255.0

access-list 101 deny ip 192.168.7.0 255.255.255.0 172.18.1.0 255.255.0.0

access-list 101 permit ip any any

group-policy L2L internal

group-policy L2L attributes

vpn-filter value 101

tunnel-group xx.xx.xxx.99 ipsec-attribute

default-group-policy L2L

Regards

Community Member

Re: VPN Help

Will not accept these commands:

access-list 101 deny ip 192.168.7.0 255.255.255.0 172.18.1.0 255.255.0.0

access-list 101 permit ip any any

Re: VPN Help

Because the netmask is wrong. Here is the correct one

access-list 101 deny ip 192.168.7.0 255.255.255.0 172.18.1.0 255.255.255.0

access-list 101 permit ip any any

105
Views
0
Helpful
3
Replies
CreatePlease to create content