cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
249
Views
4
Helpful
2
Replies

routing for an asa5510

rhltechie
Level 1
Level 1

Hi all,

A quick question about routing on a asa5510. If i have users coming into an interface for vpn, and that interface also being the interface that connects to the internet, how is it that i allow my vpn users to use the internet( that i provide, no split tunnel)as the asa doesn't support a packet in/out a single interface? I understand that the pix works this way as well? forgive me as i am new to pix/asa.

Thanks,

R

1 Accepted Solution

Accepted Solutions

jackko
Level 7
Level 7

with asa or pix v7.x, it is feasible to redirect internet traffic without configuring split tunneling.

for instance, all traffic originated from a vpn client software host is encrypted and sent to the asa. asa receives, determines the packet is destined for internet. asa will then forward the packet back to the internet.

have a look at this cisco doc, it provides a detail configuration example for redirecting internet traffic for software client:

http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a00805734ae.shtml#diag

View solution in original post

2 Replies 2

pkhatri
Level 11
Level 11

I'm not an expert on the ASA either but one suggestion would be to get the users to access the Internet through a proxy server sitting on your inside network. That will mean that a completely new packet will be generated by the proxy and you won't have the problem of a packet going out the interface it came in on.

Paresh

jackko
Level 7
Level 7

with asa or pix v7.x, it is feasible to redirect internet traffic without configuring split tunneling.

for instance, all traffic originated from a vpn client software host is encrypted and sent to the asa. asa receives, determines the packet is destined for internet. asa will then forward the packet back to the internet.

have a look at this cisco doc, it provides a detail configuration example for redirecting internet traffic for software client:

http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a00805734ae.shtml#diag

Review Cisco Networking products for a $25 gift card