<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Anyconnect unable to connect network -  inside bvi interface in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/anyconnect-unable-to-connect-network-inside-bvi-interface/m-p/4097537#M1070749</link>
    <description>&lt;P&gt;share the &lt;STRONG&gt;show run nat&lt;/STRONG&gt; and &lt;STRONG&gt;show nat detail&lt;/STRONG&gt; output please.&lt;/P&gt;</description>
    <pubDate>Thu, 04 Jun 2020 12:35:12 GMT</pubDate>
    <dc:creator>Sheraz.Salim</dc:creator>
    <dc:date>2020-06-04T12:35:12Z</dc:date>
    <item>
      <title>Anyconnect unable to connect network -  inside bvi interface</title>
      <link>https://community.cisco.com/t5/network-security/anyconnect-unable-to-connect-network-inside-bvi-interface/m-p/4097419#M1070731</link>
      <description>&lt;P&gt;&lt;BR /&gt;Hello, i have to following problem.&lt;BR /&gt;Connected via anyconnect (vpn ip address 10.10.10.239) , i am not able to connect to 10.10.11.10 which is on interface bvi2&lt;/P&gt;&lt;P&gt;ASA# sh version&lt;/P&gt;&lt;P&gt;Cisco Adaptive Security Appliance Software Version 9.8(1)&lt;BR /&gt;Firepower Extensible Operating System Version 2.2(1.47)&lt;BR /&gt;Device Manager Version 7.8(1)&lt;/P&gt;&lt;P&gt;ASA# sh run&lt;/P&gt;&lt;P&gt;ASA Version 9.8(1)&lt;BR /&gt;!&lt;BR /&gt;hostname ASA&lt;BR /&gt;domain-name rornet.ro&lt;/P&gt;&lt;P&gt;ip local pool Euro 10.10.10.239-10.10.10.254 mask 255.255.255.0&lt;/P&gt;&lt;P&gt;!&lt;BR /&gt;interface GigabitEthernet1/1&lt;BR /&gt;nameif outside&lt;BR /&gt;security-level 0&lt;BR /&gt;ip address 89.238.216.40 255.255.255.240&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet1/2&lt;BR /&gt;XXXXXXXX&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet1/3&lt;BR /&gt;bridge-group 1&lt;BR /&gt;nameif OsloEth0+modem1+management-oslo_1&lt;BR /&gt;security-level 100&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet1/4&lt;BR /&gt;XXXXXXXX&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet1/5&lt;BR /&gt;bridge-group 2&lt;BR /&gt;nameif osloEth1+modem2_1&lt;BR /&gt;security-level 100&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet1/6&lt;BR /&gt;bridge-group 2&lt;BR /&gt;nameif osloEth1+modem2_2&lt;BR /&gt;security-level 100&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet1/7&lt;BR /&gt;XXXXXXXXXxx&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet1/8&lt;BR /&gt;bridge-group 1&lt;BR /&gt;nameif OsloEth0+modem1+management-oslo_2&lt;BR /&gt;security-level 100&lt;BR /&gt;!&lt;BR /&gt;interface Management1/1&lt;BR /&gt;management-only&lt;BR /&gt;no nameif&lt;BR /&gt;no security-level&lt;BR /&gt;no ip address&lt;BR /&gt;!&lt;BR /&gt;interface BVI1&lt;BR /&gt;nameif OsloEth0+modem1+management-oslo&lt;BR /&gt;security-level 100&lt;BR /&gt;ip address 10.10.10.1 255.255.255.0&lt;BR /&gt;!&lt;BR /&gt;interface BVI2&lt;BR /&gt;description osloEth1+modem2&lt;BR /&gt;nameif OsloEth1+modem2&lt;BR /&gt;security-level 100&lt;BR /&gt;ip address 10.10.11.1 255.255.255.0&lt;BR /&gt;!&lt;BR /&gt;same-security-traffic permit inter-interface&lt;BR /&gt;same-security-traffic permit intra-interface&lt;BR /&gt;object network obj_any1&lt;BR /&gt;subnet 0.0.0.0 0.0.0.0&lt;BR /&gt;object network obj_any2&lt;BR /&gt;subnet 0.0.0.0 0.0.0.0&lt;BR /&gt;object network obj_any3&lt;BR /&gt;subnet 0.0.0.0 0.0.0.0&lt;BR /&gt;object network obj_any4&lt;BR /&gt;subnet 0.0.0.0 0.0.0.0&lt;BR /&gt;object network obj_any5&lt;BR /&gt;subnet 0.0.0.0 0.0.0.0&lt;BR /&gt;object network obj_any6&lt;BR /&gt;subnet 0.0.0.0 0.0.0.0&lt;BR /&gt;object network obj_any7&lt;BR /&gt;subnet 0.0.0.0 0.0.0.0&lt;BR /&gt;object network Local-Codecs&lt;BR /&gt;subnet 192.168.6.0 255.255.255.0&lt;BR /&gt;object network EuroRadio_CGT&lt;BR /&gt;subnet 192.168.101.0 255.255.255.0&lt;BR /&gt;object network NETWORK_OBJ_10.10.10.96_28&lt;BR /&gt;subnet 10.10.10.96 255.255.255.240&lt;BR /&gt;object network NETWORK_OBJ_192.168.6.0_24&lt;BR /&gt;subnet 192.168.6.0 255.255.255.0&lt;BR /&gt;object network 6.6-VNC&lt;BR /&gt;host 192.168.6.6&lt;BR /&gt;object network 6.2-VNC&lt;BR /&gt;host 192.168.6.2&lt;BR /&gt;object network SRR_PUBLIC&lt;BR /&gt;host 89.238.216.40&lt;BR /&gt;object service OBJ-TCP-VNC&lt;BR /&gt;service tcp source eq 6000&lt;BR /&gt;object network VPN_POOL&lt;BR /&gt;subnet 10.10.10.0 255.255.255.0&lt;BR /&gt;description VPN_POOL&lt;BR /&gt;object-group network PoolLocalCodecs&lt;BR /&gt;network-object host 192.168.6.250&lt;BR /&gt;network-object host 192.168.6.251&lt;BR /&gt;network-object host 192.168.6.252&lt;BR /&gt;network-object host 192.168.6.253&lt;BR /&gt;network-object host 192.168.6.254&lt;BR /&gt;object-group network NO_NAT_VPN_DESTINATION1&lt;BR /&gt;network-object 10.10.11.0 255.255.255.0&lt;BR /&gt;object-group network NO_NAT_VPN_DESTINATION2&lt;BR /&gt;network-object host 10.10.10.10&lt;BR /&gt;network-object 10.10.10.0 255.255.255.0&lt;BR /&gt;access-list srr_splitTunnelAcl standard permit 10.10.10.0 255.255.255.0&lt;BR /&gt;access-list srr_splitTunnelAcl standard permit 10.10.11.0 255.255.255.0&lt;BR /&gt;access-list srr_splitTunnelAcl standard permit 192.168.100.0 255.255.255.0&lt;BR /&gt;access-list srr_splitTunnelAcl standard permit 192.168.101.0 255.255.255.0&lt;BR /&gt;access-list srr_splitTunnelAcl standard permit 192.168.6.0 255.255.255.0&lt;BR /&gt;access-list OsloEth0+modem1+management-oslo_access_in extended permit ip any any&lt;BR /&gt;access-list OsloEth1+modem2_access_in extended permit ip any any&lt;BR /&gt;access-list Local-Codecs_nat0_outbound extended permit ip 192.168.6.0 255.255.255.0 object-group PoolLocalCodecs&lt;BR /&gt;access-list srrcodecs_splitTunnel standard permit 192.168.6.0 255.255.255.0&lt;BR /&gt;access-list srrcodecs_splitTunnel standard permit 193.231.72.0 255.255.255.0&lt;BR /&gt;access-list srrcodecs_splitTunnel standard permit 89.238.216.32 255.255.255.240&lt;BR /&gt;access-list srrcodecs_splitTunnel standard permit 10.10.10.0 255.255.255.0&lt;BR /&gt;access-list srrcodecs_splitTunnel standard permit 10.10.11.0 255.255.255.0&lt;BR /&gt;access-list SRR-LAN_in extended deny ip any any log&lt;BR /&gt;access-list VPN1_splitTunnelAcl standard permit 192.168.6.0 255.255.255.0&lt;BR /&gt;access-list AnyConnect_Client_Local_Print extended deny ip any4 any4&lt;BR /&gt;access-list AnyConnect_Client_Local_Print extended permit tcp any4 any4 eq lpd&lt;BR /&gt;access-list AnyConnect_Client_Local_Print remark IPP: Internet Printing Protocol&lt;BR /&gt;access-list AnyConnect_Client_Local_Print extended permit tcp any4 any4 eq 631&lt;BR /&gt;access-list AnyConnect_Client_Local_Print remark Windows' printing port&lt;BR /&gt;access-list AnyConnect_Client_Local_Print extended permit tcp any4 any4 eq 9100&lt;BR /&gt;access-list AnyConnect_Client_Local_Print remark mDNS: multicast DNS protocol&lt;BR /&gt;access-list AnyConnect_Client_Local_Print extended permit udp any4 host 224.0.0.251 eq 5353&lt;BR /&gt;access-list AnyConnect_Client_Local_Print remark LLMNR: Link Local Multicast Name Resolution protocol&lt;BR /&gt;access-list AnyConnect_Client_Local_Print extended permit udp any4 host 224.0.0.252 eq 5355&lt;BR /&gt;access-list AnyConnect_Client_Local_Print remark TCP/NetBIOS protocol&lt;BR /&gt;access-list AnyConnect_Client_Local_Print extended permit tcp any4 any4 eq 137&lt;BR /&gt;access-list AnyConnect_Client_Local_Print extended permit udp any4 any4 eq netbios-ns&lt;BR /&gt;access-list outside_in extended permit tcp any object 6.6-VNC eq 5900&lt;BR /&gt;access-list outside_in extended permit tcp any object 6.2-VNC eq 5901&lt;BR /&gt;access-list outside_in extended permit ip 10.10.10.0 255.255.255.0 10.10.11.0 255.255.255.0&lt;BR /&gt;access-list outside_in extended permit ip 172.18.1.0 255.255.255.0 10.10.11.0 255.255.255.0&lt;BR /&gt;access-list outside_in extended permit ip 10.10.11.0 255.255.255.0 10.10.10.0 255.255.255.0&lt;BR /&gt;access-list outside_in extended permit ip 10.10.11.0 255.255.255.0 172.18.1.0 255.255.255.0&lt;BR /&gt;pager lines 24&lt;BR /&gt;logging enable&lt;BR /&gt;logging timestamp&lt;BR /&gt;logging trap notifications&lt;BR /&gt;logging history emergencies&lt;BR /&gt;logging asdm errors&lt;BR /&gt;logging host outside 10.1.0.100&lt;BR /&gt;logging host outside 10.106.0.50&lt;BR /&gt;mtu outside 1500&lt;BR /&gt;mtu SRR-LAN 1500&lt;BR /&gt;mtu OsloEth0+modem1+management-oslo_1 1500&lt;BR /&gt;mtu Local-Codecs 1500&lt;BR /&gt;mtu osloEth1+modem2_1 1500&lt;BR /&gt;mtu osloEth1+modem2_2 1500&lt;BR /&gt;mtu EuroRadio_CGT 1500&lt;BR /&gt;mtu OsloEth0+modem1+management-oslo_2 1500&lt;BR /&gt;icmp unreachable rate-limit 1 burst-size 1&lt;BR /&gt;icmp permit any SRR-LAN&lt;BR /&gt;icmp permit any Local-Codecs&lt;BR /&gt;icmp permit any EuroRadio_CGT&lt;BR /&gt;icmp permit any OsloEth0+modem1+management-oslo&lt;BR /&gt;icmp permit any OsloEth1+modem2&lt;BR /&gt;no asdm history enable&lt;BR /&gt;arp timeout 14400&lt;BR /&gt;no arp permit-nonconnected&lt;BR /&gt;arp rate-limit 16384&lt;BR /&gt;nat (EuroRadio_CGT,outside) source static NETWORK_OBJ_192.168.6.0_24 NETWORK_OBJ_192.168.6.0_24 destination static NETWORK_OBJ_10.10.10.96_28 NETWORK_OBJ_10.10.10.96_28 no-proxy-arp route-lookup&lt;BR /&gt;nat (Local-Codecs,outside) source static NETWORK_OBJ_192.168.6.0_24 NETWORK_OBJ_192.168.6.0_24 destination static NETWORK_OBJ_10.10.10.96_28 NETWORK_OBJ_10.10.10.96_28 no-proxy-arp route-lookup&lt;BR /&gt;!&lt;BR /&gt;object network Local-Codecs&lt;BR /&gt;nat (Local-Codecs,outside) dynamic interface&lt;BR /&gt;object network EuroRadio_CGT&lt;BR /&gt;nat (EuroRadio_CGT,outside) dynamic interface&lt;BR /&gt;object network 6.6-VNC&lt;BR /&gt;nat (Local-Codecs,outside) static interface service tcp 5900 5900&lt;BR /&gt;object network 6.2-VNC&lt;BR /&gt;nat (Local-Codecs,outside) static interface service tcp 5901 5901&lt;BR /&gt;access-group outside_in in interface outside&lt;BR /&gt;access-group SRR-LAN_in in interface SRR-LAN&lt;BR /&gt;access-group OsloEth0+modem1+management-oslo_access_in in interface OsloEth0+modem1+management-oslo&lt;BR /&gt;access-group OsloEth1+modem2_access_in in interface OsloEth1+modem2&lt;BR /&gt;route outside 0.0.0.0 0.0.0.0 89.238.216.33 1&lt;BR /&gt;route SRR-LAN 10.0.0.0 255.0.0.0 10.1.0.1 1&lt;BR /&gt;timeout xlate 3:00:00&lt;BR /&gt;timeout pat-xlate 0:00:30&lt;BR /&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 sctp 0:02:00 icmp 0:00:02&lt;BR /&gt;timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00&lt;BR /&gt;timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00&lt;BR /&gt;timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute&lt;BR /&gt;timeout tcp-proxy-reassembly 0:01:00&lt;BR /&gt;timeout floating-conn 0:00:00&lt;BR /&gt;timeout conn-holddown 0:00:15&lt;BR /&gt;timeout igp stale-route 0:01:10&lt;BR /&gt;user-identity default-domain LOCAL&lt;BR /&gt;aaa authentication ssh console LOCAL&lt;BR /&gt;aaa authorization command LOCAL&lt;BR /&gt;aaa authorization exec LOCAL&lt;BR /&gt;aaa authentication login-history&lt;BR /&gt;http server enable 50000&lt;BR /&gt;http 193.231.72.0 255.255.255.0 outside&lt;BR /&gt;http 86.120.118.125 255.255.255.255 outside&lt;BR /&gt;http 89.238.213.250 255.255.255.255 outside&lt;BR /&gt;http 10.1.20.0 255.255.255.0 outside&lt;BR /&gt;http 195.82.148.30 255.255.255.255 outside&lt;BR /&gt;http 192.168.6.250 255.255.255.255 outside&lt;BR /&gt;http 192.168.6.251 255.255.255.255 outside&lt;BR /&gt;http 192.168.6.252 255.255.255.255 outside&lt;BR /&gt;http 192.168.6.253 255.255.255.255 outside&lt;BR /&gt;http 192.168.6.254 255.255.255.255 outside&lt;BR /&gt;http 10.1.0.0 255.255.0.0 SRR-LAN&lt;BR /&gt;http 79.246.82.240 255.255.255.255 outside&lt;BR /&gt;http 5.154.236.2 255.255.255.255 outside&lt;BR /&gt;snmp-server host outside 10.1.0.100 community ***** version 2c&lt;BR /&gt;snmp-server host outside 10.106.0.161 poll community *****&lt;BR /&gt;no snmp-server location&lt;BR /&gt;no snmp-server contact&lt;BR /&gt;snmp-server community *****&lt;BR /&gt;sysopt noproxyarp outside&lt;BR /&gt;service sw-reset-button&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-3DES-SHA esp-3des esp-sha-hmac&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-256-MD5 esp-aes-256 esp-md5-hmac&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-DES-SHA esp-des esp-sha-hmac&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-DES-MD5 esp-des esp-md5-hmac&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-192-MD5 esp-aes-192 esp-md5-hmac&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-3DES-MD5 esp-3des esp-md5-hmac&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-256-SHA esp-aes-256 esp-sha-hmac&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-128-SHA esp-aes esp-sha-hmac&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-192-SHA esp-aes-192 esp-sha-hmac&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-128-MD5 esp-aes esp-md5-hmac&lt;BR /&gt;crypto ipsec security-association pmtu-aging infinite&lt;BR /&gt;crypto dynamic-map SYSTEM_DEFAULT_CRYPTO_MAP 65535 set pfs group1&lt;BR /&gt;crypto dynamic-map SYSTEM_DEFAULT_CRYPTO_MAP 65535 set ikev1 transform-set ESP-AES-128-SHA ESP-AES-128-MD5 ESP-AES-192-SHA ESP-AES-192-MD5 ESP-AES-256-SHA ESP-AES-256-MD5 ESP-3DES-SHA ESP-3DES-MD5 ESP-DES-SHA ESP-DES-MD5&lt;BR /&gt;crypto map outside_map 65535 ipsec-isakmp dynamic SYSTEM_DEFAULT_CRYPTO_MAP&lt;BR /&gt;crypto map outside_map interface outside&lt;BR /&gt;crypto ca trustpool policy&lt;BR /&gt;crypto ikev1 enable outside&lt;BR /&gt;crypto ikev1 policy 10&lt;BR /&gt;authentication pre-share&lt;BR /&gt;encryption aes-256&lt;BR /&gt;hash sha&lt;BR /&gt;group 2&lt;BR /&gt;lifetime 86400&lt;BR /&gt;crypto ikev1 policy 20&lt;BR /&gt;authentication rsa-sig&lt;BR /&gt;encryption aes-256&lt;BR /&gt;hash sha&lt;BR /&gt;group 2&lt;BR /&gt;lifetime 86400&lt;BR /&gt;crypto ikev1 policy 40&lt;BR /&gt;authentication pre-share&lt;BR /&gt;encryption aes-192&lt;BR /&gt;hash sha&lt;BR /&gt;group 2&lt;BR /&gt;lifetime 86400&lt;BR /&gt;crypto ikev1 policy 50&lt;BR /&gt;authentication rsa-sig&lt;BR /&gt;encryption aes-192&lt;BR /&gt;hash sha&lt;BR /&gt;group 2&lt;BR /&gt;lifetime 86400&lt;BR /&gt;crypto ikev1 policy 70&lt;BR /&gt;authentication pre-share&lt;BR /&gt;encryption aes&lt;BR /&gt;hash sha&lt;BR /&gt;group 2&lt;BR /&gt;lifetime 86400&lt;BR /&gt;crypto ikev1 policy 80&lt;BR /&gt;authentication rsa-sig&lt;BR /&gt;encryption aes&lt;BR /&gt;hash sha&lt;BR /&gt;group 2&lt;BR /&gt;lifetime 86400&lt;BR /&gt;crypto ikev1 policy 100&lt;BR /&gt;authentication pre-share&lt;BR /&gt;encryption 3des&lt;BR /&gt;hash sha&lt;BR /&gt;group 2&lt;BR /&gt;lifetime 86400&lt;BR /&gt;crypto ikev1 policy 110&lt;BR /&gt;authentication rsa-sig&lt;BR /&gt;encryption 3des&lt;BR /&gt;hash sha&lt;BR /&gt;group 2&lt;BR /&gt;lifetime 86400&lt;BR /&gt;crypto ikev1 policy 130&lt;BR /&gt;authentication pre-share&lt;BR /&gt;encryption des&lt;BR /&gt;hash sha&lt;BR /&gt;group 2&lt;BR /&gt;lifetime 86400&lt;BR /&gt;crypto ikev1 policy 140&lt;BR /&gt;authentication rsa-sig&lt;BR /&gt;encryption des&lt;BR /&gt;hash sha&lt;BR /&gt;group 2&lt;BR /&gt;lifetime 86400&lt;BR /&gt;telnet timeout 5&lt;BR /&gt;ssh stricthostkeycheck&lt;BR /&gt;ssh 0.0.0.0 0.0.0.0 outside&lt;BR /&gt;ssh 10.1.0.0 255.255.0.0 SRR-LAN&lt;BR /&gt;ssh 10.0.0.0 255.0.0.0 SRR-LAN&lt;BR /&gt;ssh timeout 60&lt;BR /&gt;ssh version 2&lt;BR /&gt;ssh key-exchange group dh-group1-sha1&lt;BR /&gt;console timeout 0&lt;/P&gt;&lt;P&gt;dhcpd auto_config outside&lt;BR /&gt;!&lt;BR /&gt;threat-detection basic-threat&lt;BR /&gt;threat-detection statistics access-list&lt;BR /&gt;no threat-detection statistics tcp-intercept&lt;BR /&gt;ntp server 10.1.50.1&lt;BR /&gt;webvpn&lt;BR /&gt;enable outside&lt;BR /&gt;anyconnect image disk0:/anyconnect-win-4.5.03040-webdeploy-k9.pkg 2&lt;BR /&gt;anyconnect image disk0:/anyconnect-macos-4.5.03040-webdeploy-k9.pkg 3&lt;BR /&gt;anyconnect enable&lt;BR /&gt;tunnel-group-list enable&lt;BR /&gt;cache&lt;BR /&gt;disable&lt;BR /&gt;error-recovery disable&lt;BR /&gt;group-policy DfltGrpPolicy attributes&lt;BR /&gt;vpn-idle-timeout 2&lt;BR /&gt;group-policy GroupPolicy_SSL internal&lt;BR /&gt;group-policy GroupPolicy_SSL attributes&lt;BR /&gt;wins-server none&lt;BR /&gt;dns-server value 193.231.236.25&lt;BR /&gt;vpn-tunnel-protocol ssl-client&lt;BR /&gt;split-tunnel-policy tunnelspecified&lt;BR /&gt;split-tunnel-network-list value srrcodecs_splitTunnel&lt;BR /&gt;default-domain value rornet.ro&lt;BR /&gt;tunnel-group SSL type remote-access&lt;BR /&gt;tunnel-group SSL general-attributes&lt;BR /&gt;address-pool Euro&lt;BR /&gt;default-group-policy GroupPolicy_SSL&lt;BR /&gt;tunnel-group SSL webvpn-attributes&lt;BR /&gt;group-alias SSL enable&lt;BR /&gt;!&lt;BR /&gt;class-map inspection_default&lt;BR /&gt;match default-inspection-traffic&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;policy-map type inspect dns preset_dns_map&lt;BR /&gt;parameters&lt;BR /&gt;message-length maximum client auto&lt;BR /&gt;message-length maximum 512&lt;BR /&gt;no tcp-inspection&lt;BR /&gt;policy-map global_policy&lt;BR /&gt;class inspection_default&lt;BR /&gt;inspect dns preset_dns_map&lt;BR /&gt;inspect ftp&lt;BR /&gt;inspect h323 h225&lt;BR /&gt;inspect h323 ras&lt;BR /&gt;inspect rsh&lt;BR /&gt;inspect rtsp&lt;BR /&gt;inspect esmtp&lt;BR /&gt;inspect sqlnet&lt;BR /&gt;inspect skinny&lt;BR /&gt;inspect sunrpc&lt;BR /&gt;inspect xdmcp&lt;BR /&gt;inspect sip&lt;BR /&gt;inspect netbios&lt;BR /&gt;inspect tftp&lt;BR /&gt;inspect ip-options&lt;BR /&gt;inspect icmp&lt;BR /&gt;!&lt;BR /&gt;service-policy global_policy global&lt;BR /&gt;prompt hostname context&lt;BR /&gt;no call-home reporting anonymous&lt;BR /&gt;Cryptochecksum:b735bbefc44e5cb8ac0c5c0e2c5fe051&lt;BR /&gt;: end&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;ASA# packet-tracer input outside icmp 10.10.10.239 8 1 10.10.11.10&lt;/P&gt;&lt;P&gt;Phase: 1&lt;BR /&gt;Type: ROUTE-LOOKUP&lt;BR /&gt;Subtype: Resolve Egress Interface&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;found next-hop 10.10.11.10 using egress ifc OsloEth1+modem2&lt;/P&gt;&lt;P&gt;Phase: 2&lt;BR /&gt;Type: ACCESS-LIST&lt;BR /&gt;Subtype: log&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;access-group outside_in in interface outside&lt;BR /&gt;access-list outside_in extended permit ip 10.10.10.0 255.255.255.0 10.10.11.0 255.255.255.0&lt;BR /&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Phase: 3&lt;BR /&gt;Type: NAT&lt;BR /&gt;Subtype: per-session&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Phase: 4&lt;BR /&gt;Type: IP-OPTIONS&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Phase: 5&lt;BR /&gt;Type: ACCESS-LIST&lt;BR /&gt;Subtype: log&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;access-group outside_in in interface outside&lt;BR /&gt;access-list outside_in extended permit ip 10.10.10.0 255.255.255.0 10.10.11.0 255.255.255.0&lt;BR /&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Phase: 6&lt;BR /&gt;Type: NAT&lt;BR /&gt;Subtype: per-session&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Phase: 7&lt;BR /&gt;Type: IP-OPTIONS&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Phase: 8&lt;BR /&gt;Type: CP-PUNT&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Phase: 9&lt;BR /&gt;Type: WEBVPN-SVC&lt;BR /&gt;Subtype: in&lt;BR /&gt;Result: DROP&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Result:&lt;BR /&gt;input-interface: outside&lt;BR /&gt;input-status: up&lt;BR /&gt;input-line-status: up&lt;BR /&gt;output-interface: OsloEth1+modem2&lt;BR /&gt;output-status: up&lt;BR /&gt;output-line-status: up&lt;BR /&gt;Action: drop&lt;BR /&gt;Drop-reason: (acl-drop) Flow is denied by configured rule&lt;/P&gt;&lt;P&gt;ASA# packet-tracer input outside tcp 10.10.10.239 80 10.10.11.10 80 detailed&lt;/P&gt;&lt;P&gt;Phase: 1&lt;BR /&gt;Type: ROUTE-LOOKUP&lt;BR /&gt;Subtype: Resolve Egress Interface&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;found next-hop 10.10.11.10 using egress ifc OsloEth1+modem2&lt;/P&gt;&lt;P&gt;Phase: 2&lt;BR /&gt;Type: ACCESS-LIST&lt;BR /&gt;Subtype: log&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;access-group outside_in in interface outside&lt;BR /&gt;access-list outside_in extended permit ip 10.10.10.0 255.255.255.0 10.10.11.0 255.255.255.0&lt;BR /&gt;Additional Information:&lt;BR /&gt;Forward Flow based lookup yields rule:&lt;BR /&gt;in id=0x7f29ec2258f0, priority=13, domain=permit, deny=false&lt;BR /&gt;hits=4, user_data=0x7f29e2aab2c0, cs_id=0x0, use_real_addr, flags=0x0, protocol=0&lt;BR /&gt;src ip/id=10.10.10.0, mask=255.255.255.0, port=0, tag=any&lt;BR /&gt;dst ip/id=10.10.11.0, mask=255.255.255.0, port=0, tag=any, dscp=0x0&lt;BR /&gt;input_ifc=outside, output_ifc=any&lt;/P&gt;&lt;P&gt;Phase: 3&lt;BR /&gt;Type: NAT&lt;BR /&gt;Subtype: per-session&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;Forward Flow based lookup yields rule:&lt;BR /&gt;in id=0x7f29e94341f0, priority=0, domain=nat-per-session, deny=false&lt;BR /&gt;hits=3922254, user_data=0x0, cs_id=0x0, reverse, use_real_addr, flags=0x0, protocol=6&lt;BR /&gt;src ip/id=0.0.0.0, mask=0.0.0.0, port=0, tag=any&lt;BR /&gt;dst ip/id=0.0.0.0, mask=0.0.0.0, port=0, tag=any, dscp=0x0&lt;BR /&gt;input_ifc=any, output_ifc=any&lt;/P&gt;&lt;P&gt;Phase: 4&lt;BR /&gt;Type: IP-OPTIONS&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;Forward Flow based lookup yields rule:&lt;BR /&gt;in id=0x7f29ea07c810, priority=0, domain=inspect-ip-options, deny=true&lt;BR /&gt;hits=2491683, user_data=0x0, cs_id=0x0, reverse, flags=0x0, protocol=0&lt;BR /&gt;src ip/id=0.0.0.0, mask=0.0.0.0, port=0, tag=any&lt;BR /&gt;dst ip/id=0.0.0.0, mask=0.0.0.0, port=0, tag=any, dscp=0x0&lt;BR /&gt;input_ifc=outside, output_ifc=any&lt;/P&gt;&lt;P&gt;Phase: 5&lt;BR /&gt;Type: ACCESS-LIST&lt;BR /&gt;Subtype: log&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;access-group outside_in in interface outside&lt;BR /&gt;access-list outside_in extended permit ip 10.10.10.0 255.255.255.0 10.10.11.0 255.255.255.0&lt;BR /&gt;Additional Information:&lt;BR /&gt;Forward Flow based lookup yields rule:&lt;BR /&gt;in id=0x7f29ec2258f0, priority=13, domain=permit, deny=false&lt;BR /&gt;hits=5, user_data=0x7f29e2aab2c0, cs_id=0x0, use_real_addr, flags=0x0, protocol=0&lt;BR /&gt;src ip/id=10.10.10.0, mask=255.255.255.0, port=0, tag=any&lt;BR /&gt;dst ip/id=10.10.11.0, mask=255.255.255.0, port=0, tag=any, dscp=0x0&lt;BR /&gt;input_ifc=outside, output_ifc=any&lt;/P&gt;&lt;P&gt;Phase: 6&lt;BR /&gt;Type: NAT&lt;BR /&gt;Subtype: per-session&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;Forward Flow based lookup yields rule:&lt;BR /&gt;in id=0x7f29e94341f0, priority=0, domain=nat-per-session, deny=false&lt;BR /&gt;hits=3922255, user_data=0x0, cs_id=0x0, reverse, use_real_addr, flags=0x0, protocol=6&lt;BR /&gt;src ip/id=0.0.0.0, mask=0.0.0.0, port=0, tag=any&lt;BR /&gt;dst ip/id=0.0.0.0, mask=0.0.0.0, port=0, tag=any, dscp=0x0&lt;BR /&gt;input_ifc=any, output_ifc=any&lt;/P&gt;&lt;P&gt;Phase: 7&lt;BR /&gt;Type: IP-OPTIONS&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;Forward Flow based lookup yields rule:&lt;BR /&gt;in id=0x7f29ea07c810, priority=0, domain=inspect-ip-options, deny=true&lt;BR /&gt;hits=2491684, user_data=0x0, cs_id=0x0, reverse, flags=0x0, protocol=0&lt;BR /&gt;src ip/id=0.0.0.0, mask=0.0.0.0, port=0, tag=any&lt;BR /&gt;dst ip/id=0.0.0.0, mask=0.0.0.0, port=0, tag=any, dscp=0x0&lt;BR /&gt;input_ifc=outside, output_ifc=any&lt;/P&gt;&lt;P&gt;Phase: 8&lt;BR /&gt;Type: CP-PUNT&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;Forward Flow based lookup yields rule:&lt;BR /&gt;in id=0x7f29eae7f800, priority=79, domain=punt, deny=true&lt;BR /&gt;hits=84, user_data=0x7f29e90323e0, cs_id=0x0, flags=0x0, protocol=0&lt;BR /&gt;src ip/id=10.10.10.239, mask=255.255.255.255, port=0, tag=any&lt;BR /&gt;dst ip/id=0.0.0.0, mask=0.0.0.0, port=0, tag=any, dscp=0x0&lt;BR /&gt;input_ifc=outside, output_ifc=any&lt;/P&gt;&lt;P&gt;Phase: 9&lt;BR /&gt;Type: WEBVPN-SVC&lt;BR /&gt;Subtype: in&lt;BR /&gt;Result: DROP&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;Forward Flow based lookup yields rule:&lt;BR /&gt;in id=0x7f29edc19760, priority=71, domain=svc-ib-tunnel-flow, deny=false&lt;BR /&gt;hits=84, user_data=0xe28000, cs_id=0x0, reverse, flags=0x0, protocol=0&lt;BR /&gt;src ip/id=10.10.10.239, mask=255.255.255.255, port=0, tag=any&lt;BR /&gt;dst ip/id=0.0.0.0, mask=0.0.0.0, port=0, tag=any, dscp=0x0&lt;BR /&gt;input_ifc=outside, output_ifc=any&lt;/P&gt;&lt;P&gt;Result:&lt;BR /&gt;input-interface: outside&lt;BR /&gt;input-status: up&lt;BR /&gt;input-line-status: up&lt;BR /&gt;output-interface: OsloEth1+modem2&lt;BR /&gt;output-status: up&lt;BR /&gt;output-line-status: up&lt;BR /&gt;Action: drop&lt;BR /&gt;Drop-reason: (acl-drop) Flow is denied by configured rule&lt;/P&gt;&lt;P&gt;What i think is that traffic from 10.10.11.10 needs to be extempt, going out through internet, it should go through the vpn tunnel:&lt;/P&gt;&lt;P&gt;I have tried:&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;object-group network NO_NAT_VPN_DESTINATION1&lt;BR /&gt;network-object 10.10.11.0 255.255.255.0&lt;/P&gt;&lt;P&gt;object-group network NO_NAT_VPN_DESTINATION2&lt;BR /&gt;network-object 10.10.10.0 255.255.255.0&lt;/P&gt;&lt;P&gt;!not working because it is a bvi interface&lt;BR /&gt;nat (OsloEth1+modem2,outside) source static NO_NAT_VPN_DESTINATION1 NO_NAT_VPN_DESTINATION1 destination static VPN_POOL VPN_POOL no-proxy-arp&lt;/P&gt;&lt;P&gt;! i have tried this , but it didn`t worked&lt;BR /&gt;nat (osloEth1+modem2_1,outside) source static NO_NAT_VPN_DESTINATION1 NO_NAT_VPN_DESTINATION1 destination static NO_NAT_VPN_DESTINATION2 NO_NAT_VPN_DESTINATION2 no-proxy-arp&lt;BR /&gt;nat (osloEth1+modem2_2,outside) source static NO_NAT_VPN_DESTINATION1 NO_NAT_VPN_DESTINATION1 destination static NO_NAT_VPN_DESTINATION2 NO_NAT_VPN_DESTINATION2 no-proxy-arp&lt;/P&gt;&lt;P&gt;Connected with anyconnect, i am able to ping 10.10.10.0..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 04 Jun 2020 08:09:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/anyconnect-unable-to-connect-network-inside-bvi-interface/m-p/4097419#M1070731</guid>
      <dc:creator>Calin Cristea</dc:creator>
      <dc:date>2020-06-04T08:09:54Z</dc:date>
    </item>
    <item>
      <title>Re: Anyconnect unable to connect network -  inside bvi interface</title>
      <link>https://community.cisco.com/t5/network-security/anyconnect-unable-to-connect-network-inside-bvi-interface/m-p/4097515#M1070745</link>
      <description>&lt;P&gt;here apply these config and test it.&lt;/P&gt;
&lt;PRE&gt;object network ANYCONNECT-POOL
 range 10.10.10.239 10.10.10.254
!
object network ANYCONNECT-POOL
 range 10.10.10.239 10.10.10.254
 nat (outside,outside) dynamic interface
!
nat (any,outside) source static any any dest static ANYCONNECT-POOL ANYCONNECT-POOL no-proxy-arp route-lookup
&lt;/PRE&gt;</description>
      <pubDate>Thu, 04 Jun 2020 11:57:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/anyconnect-unable-to-connect-network-inside-bvi-interface/m-p/4097515#M1070745</guid>
      <dc:creator>Sheraz.Salim</dc:creator>
      <dc:date>2020-06-04T11:57:10Z</dc:date>
    </item>
    <item>
      <title>Re: Anyconnect unable to connect network -  inside bvi interface</title>
      <link>https://community.cisco.com/t5/network-security/anyconnect-unable-to-connect-network-inside-bvi-interface/m-p/4097523#M1070748</link>
      <description>&lt;P&gt;Dear Salim,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Many thanks for you answer. I did apply all of you`re recommandations. Unfortunelly, problem is the same.&lt;/P&gt;&lt;P&gt;I have tried to packed trace with a unused ip now, and the flow seems fine. I am only able to ping/telnet an ip from the same subnet from the vpn class, but not 10.10.11.10&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ASA# sh vpn-sessiondb anyconnect&lt;/P&gt;&lt;P&gt;Session Type: AnyConnect&lt;/P&gt;&lt;P&gt;Username : X Index : 26322&lt;BR /&gt;Assigned IP : 10.10.10.241 Public IP : 193.231.72.7&lt;BR /&gt;Protocol : AnyConnect-Parent SSL-Tunnel DTLS-Tunnel&lt;BR /&gt;License : AnyConnect Premium&lt;BR /&gt;Encryption : AnyConnect-Parent: (1)none SSL-Tunnel: (1)AES-GCM-256 DTLS-Tunnel: (1)AES256&lt;BR /&gt;Hashing : AnyConnect-Parent: (1)none SSL-Tunnel: (1)SHA384 DTLS-Tunnel: (1)SHA1&lt;BR /&gt;Bytes Tx : 255074 Bytes Rx : 78927&lt;BR /&gt;Group Policy : GroupPolicy_SSL Tunnel Group : SSL&lt;BR /&gt;Login Time : 14:49:58 EEDT Thu Jun 4 2020&lt;BR /&gt;Duration : 0h:16m:28s&lt;BR /&gt;Inactivity : 0h:00m:00s&lt;BR /&gt;VLAN Mapping : N/A VLAN : none&lt;BR /&gt;Audt Sess ID : 0a0a0a01066d20005ed8dfe6&lt;BR /&gt;Security Grp : none&lt;BR /&gt;Username : X Index : 52633&lt;BR /&gt;Assigned IP : 10.10.10.242 Public IP : 86.120.253.68&lt;BR /&gt;Protocol : AnyConnect-Parent SSL-Tunnel DTLS-Tunnel&lt;BR /&gt;License : AnyConnect Premium&lt;BR /&gt;Encryption : AnyConnect-Parent: (1)none SSL-Tunnel: (1)AES-GCM-256 DTLS-Tunnel: (1)AES256&lt;BR /&gt;Hashing : AnyConnect-Parent: (1)none SSL-Tunnel: (1)SHA384 DTLS-Tunnel: (1)SHA1&lt;BR /&gt;Bytes Tx : 22016 Bytes Rx : 58851&lt;BR /&gt;Group Policy : GroupPolicy_SSL Tunnel Group : SSL&lt;BR /&gt;Login Time : 15:04:17 EEDT Thu Jun 4 2020&lt;BR /&gt;Duration : 0h:02m:09s&lt;BR /&gt;Inactivity : 0h:00m:00s&lt;BR /&gt;VLAN Mapping : N/A VLAN : none&lt;BR /&gt;Audt Sess ID : 0a0a0a010cd990005ed8e341&lt;BR /&gt;Security Grp : none&lt;/P&gt;&lt;P&gt;ASA-EURORADIO# packet-tracer input outside icmp 10.10.10.243 8 1 10.10.11.10&lt;/P&gt;&lt;P&gt;Phase: 1&lt;BR /&gt;Type: ROUTE-LOOKUP&lt;BR /&gt;Subtype: Resolve Egress Interface&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;found next-hop 10.10.11.10 using egress ifc OsloEth1+modem2&lt;/P&gt;&lt;P&gt;Phase: 2&lt;BR /&gt;Type: UN-NAT&lt;BR /&gt;Subtype: static&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;nat (any,outside) source static any any destination static ANYCONNECT-POOL ANYCONNECT-POOL no-proxy-arp route-lookup&lt;BR /&gt;Additional Information:&lt;BR /&gt;NAT divert to egress interface OsloEth1+modem2&lt;BR /&gt;Untranslate 10.10.11.10/0 to 10.10.11.10/0&lt;/P&gt;&lt;P&gt;Phase: 3&lt;BR /&gt;Type: ACCESS-LIST&lt;BR /&gt;Subtype: log&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;access-group outside_in in interface outside&lt;BR /&gt;access-list outside_in extended permit ip 10.10.10.0 255.255.255.0 10.10.11.0 255.255.255.0&lt;BR /&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Phase: 4&lt;BR /&gt;Type: NAT&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;nat (any,outside) source static any any destination static ANYCONNECT-POOL ANYCONNECT-POOL no-proxy-arp route-lookup&lt;BR /&gt;Additional Information:&lt;BR /&gt;Static translate 10.10.10.243/0 to 10.10.10.243/0&lt;/P&gt;&lt;P&gt;Phase: 5&lt;BR /&gt;Type: NAT&lt;BR /&gt;Subtype: per-session&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Phase: 6&lt;BR /&gt;Type: IP-OPTIONS&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Phase: 7&lt;BR /&gt;Type: ACCESS-LIST&lt;BR /&gt;Subtype: log&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;access-group outside_in in interface outside&lt;BR /&gt;access-list outside_in extended permit ip 10.10.10.0 255.255.255.0 10.10.11.0 255.255.255.0&lt;BR /&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Phase: 8&lt;BR /&gt;Type: NAT&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;nat (any,outside) source static any any destination static ANYCONNECT-POOL ANYCONNECT-POOL no-proxy-arp route-lookup&lt;BR /&gt;Additional Information:&lt;BR /&gt;Static translate 10.10.10.243/0 to 10.10.10.243/0&lt;/P&gt;&lt;P&gt;Phase: 9&lt;BR /&gt;Type: NAT&lt;BR /&gt;Subtype: per-session&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Phase: 10&lt;BR /&gt;Type: IP-OPTIONS&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Phase: 11&lt;BR /&gt;Type: INSPECT&lt;BR /&gt;Subtype: np-inspect&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;class-map inspection_default&lt;BR /&gt;match default-inspection-traffic&lt;BR /&gt;policy-map global_policy&lt;BR /&gt;class inspection_default&lt;BR /&gt;inspect icmp&lt;BR /&gt;service-policy global_policy global&lt;BR /&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Phase: 12&lt;BR /&gt;Type: INSPECT&lt;BR /&gt;Subtype: np-inspect&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Phase: 13&lt;BR /&gt;Type: VPN&lt;BR /&gt;Subtype: ipsec-tunnel-flow&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Phase: 14&lt;BR /&gt;Type: NAT&lt;BR /&gt;Subtype: rpf-check&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;nat (any,outside) source static any any destination static ANYCONNECT-POOL ANYCONNECT-POOL no-proxy-arp route-lookup&lt;BR /&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Phase: 15&lt;BR /&gt;Type: INSPECT&lt;BR /&gt;Subtype: np-inspect&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;class-map inspection_default&lt;BR /&gt;match default-inspection-traffic&lt;BR /&gt;policy-map global_policy&lt;BR /&gt;class inspection_default&lt;BR /&gt;inspect icmp&lt;BR /&gt;service-policy global_policy global&lt;BR /&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Phase: 16&lt;BR /&gt;Type: INSPECT&lt;BR /&gt;Subtype: np-inspect&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Phase: 17&lt;BR /&gt;Type: VPN&lt;BR /&gt;Subtype: ipsec-tunnel-flow&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Phase: 18&lt;BR /&gt;Type: NAT&lt;BR /&gt;Subtype: rpf-check&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;nat (any,outside) source static any any destination static ANYCONNECT-POOL ANYCONNECT-POOL no-proxy-arp route-lookup&lt;BR /&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Phase: 19&lt;BR /&gt;Type: FLOW-CREATION&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;New flow created with id 2695765, packet dispatched to next module&lt;/P&gt;&lt;P&gt;Result:&lt;BR /&gt;input-interface: outside&lt;BR /&gt;input-status: up&lt;BR /&gt;input-line-status: up&lt;BR /&gt;output-interface: OsloEth1+modem2&lt;BR /&gt;output-status: up&lt;BR /&gt;output-line-status: up&lt;BR /&gt;Action: allow&lt;/P&gt;</description>
      <pubDate>Thu, 04 Jun 2020 12:09:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/anyconnect-unable-to-connect-network-inside-bvi-interface/m-p/4097523#M1070748</guid>
      <dc:creator>Calin Cristea</dc:creator>
      <dc:date>2020-06-04T12:09:59Z</dc:date>
    </item>
    <item>
      <title>Re: Anyconnect unable to connect network -  inside bvi interface</title>
      <link>https://community.cisco.com/t5/network-security/anyconnect-unable-to-connect-network-inside-bvi-interface/m-p/4097537#M1070749</link>
      <description>&lt;P&gt;share the &lt;STRONG&gt;show run nat&lt;/STRONG&gt; and &lt;STRONG&gt;show nat detail&lt;/STRONG&gt; output please.&lt;/P&gt;</description>
      <pubDate>Thu, 04 Jun 2020 12:35:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/anyconnect-unable-to-connect-network-inside-bvi-interface/m-p/4097537#M1070749</guid>
      <dc:creator>Sheraz.Salim</dc:creator>
      <dc:date>2020-06-04T12:35:12Z</dc:date>
    </item>
    <item>
      <title>Re: Anyconnect unable to connect network -  inside bvi interface</title>
      <link>https://community.cisco.com/t5/network-security/anyconnect-unable-to-connect-network-inside-bvi-interface/m-p/4097548#M1070750</link>
      <description>&lt;P&gt;ASA-EURORADIO# sh run nat&lt;/P&gt;&lt;P&gt;nat (OsloEth0+modem1+management-oslo_1,outside) source static NO_NAT_VPN_DESTINATION1 NO_NAT_VPN_DESTINATION1 destination static NO_NAT_VPN_CLASS NO_NAT_VPN_CLASS no-proxy-arp route-lookup&lt;BR /&gt;nat (OsloEth0+modem1+management-oslo_2,outside) source static NO_NAT_VPN_DESTINATION1 NO_NAT_VPN_DESTINATION1 destination static NO_NAT_VPN_CLASS NO_NAT_VPN_CLASS no-proxy-arp route-lookup&lt;BR /&gt;nat (OsloEth0+modem1+management-oslo_1,outside) source static NO_NAT_VPN_DESTINATION2 NO_NAT_VPN_DESTINATION2 destination static NO_NAT_VPN_CLASS NO_NAT_VPN_CLASS no-proxy-arp route-lookup&lt;BR /&gt;nat (OsloEth0+modem1+management-oslo_2,outside) source static NO_NAT_VPN_DESTINATION2 NO_NAT_VPN_DESTINATION2 destination static NO_NAT_VPN_CLASS NO_NAT_VPN_CLASS no-proxy-arp route-lookup&lt;BR /&gt;nat (osloEth1+modem2_1,outside) source static NO_NAT_VPN_DESTINATION1 NO_NAT_VPN_DESTINATION1 destination static NO_NAT_VPN_CLASS NO_NAT_VPN_CLASS no-proxy-arp route-lookup&lt;BR /&gt;nat (osloEth1+modem2_2,outside) source static NO_NAT_VPN_DESTINATION1 NO_NAT_VPN_DESTINATION1 destination static NO_NAT_VPN_CLASS NO_NAT_VPN_CLASS no-proxy-arp route-lookup&lt;BR /&gt;nat (osloEth1+modem2_2,outside) source static NO_NAT_VPN_DESTINATION2 NO_NAT_VPN_DESTINATION2 destination static NO_NAT_VPN_CLASS NO_NAT_VPN_CLASS no-proxy-arp route-lookup&lt;BR /&gt;nat (osloEth1+modem2_1,outside) source static NO_NAT_VPN_DESTINATION2 NO_NAT_VPN_DESTINATION2 destination static NO_NAT_VPN_CLASS NO_NAT_VPN_CLASS no-proxy-arp route-lookup&lt;BR /&gt;nat (any,outside) source static ANYCONNECT-POOL ANYCONNECT-POOL destination static NO_NAT_VPN_DESTINATION1 NO_NAT_VPN_DESTINATION1 no-proxy-arp route-lookup&lt;/P&gt;&lt;P&gt;Above are some of my atempts.&lt;/P&gt;&lt;P&gt;nat (any,outside) source static NO_NAT_VPN_DESTINATION1 NO_NAT_VPN_DESTINATION1 destination static ANYCONNECT-POOL ANYCONNECT-POOL no-proxy-arp route-lookup&lt;BR /&gt;!&lt;BR /&gt;object network ANYCONNECT-POOL&lt;BR /&gt;nat (outside,outside) dynamic interface&lt;/P&gt;&lt;P&gt;ASA-EURORADIO# show nat detail&lt;BR /&gt;Manual NAT Policies (Section 1)&lt;BR /&gt;1 (EuroRadio_CGT) to (outside) source static NETWORK_OBJ_192.168.6.0_24 NETWORK_OBJ_192.168.6.0_24 destination static NETWORK_OBJ_10.10.10.96_28 NETWORK_OBJ_10.10.10.96_28 no-proxy-arp route-lookup&lt;BR /&gt;translate_hits = 0, untranslate_hits = 0&lt;BR /&gt;Source - Origin: 192.168.6.0/24, Translated: 192.168.6.0/24&lt;BR /&gt;Destination - Origin: 10.10.10.96/28, Translated: 10.10.10.96/28&lt;BR /&gt;2 (Local-Codecs) to (outside) source static NETWORK_OBJ_192.168.6.0_24 NETWORK_OBJ_192.168.6.0_24 destination static NETWORK_OBJ_10.10.10.96_28 NETWORK_OBJ_10.10.10.96_28 no-proxy-arp route-lookup&lt;BR /&gt;translate_hits = 0, untranslate_hits = 0&lt;BR /&gt;Source - Origin: 192.168.6.0/24, Translated: 192.168.6.0/24&lt;BR /&gt;Destination - Origin: 10.10.10.96/28, Translated: 10.10.10.96/28&lt;BR /&gt;3 (OsloEth0+modem1+management-oslo_1) to (outside) source static NO_NAT_VPN_DESTINATION1 NO_NAT_VPN_DESTINATION1 destination static NO_NAT_VPN_CLASS NO_NAT_VPN_CLASS no-proxy-arp route-lookup&lt;BR /&gt;translate_hits = 0, untranslate_hits = 0&lt;BR /&gt;Source - Origin: 10.10.11.0/24, Translated: 10.10.11.0/24&lt;BR /&gt;Destination - Origin: 172.18.1.0/24, Translated: 172.18.1.0/24&lt;BR /&gt;4 (OsloEth0+modem1+management-oslo_2) to (outside) source static NO_NAT_VPN_DESTINATION1 NO_NAT_VPN_DESTINATION1 destination static NO_NAT_VPN_CLASS NO_NAT_VPN_CLASS no-proxy-arp route-lookup&lt;BR /&gt;translate_hits = 0, untranslate_hits = 0&lt;BR /&gt;Source - Origin: 10.10.11.0/24, Translated: 10.10.11.0/24&lt;BR /&gt;Destination - Origin: 172.18.1.0/24, Translated: 172.18.1.0/24&lt;BR /&gt;5 (OsloEth0+modem1+management-oslo_1) to (outside) source static NO_NAT_VPN_DESTINATION2 NO_NAT_VPN_DESTINATION2 destination static NO_NAT_VPN_CLASS NO_NAT_VPN_CLASS no-proxy-arp route-lookup&lt;BR /&gt;translate_hits = 482, untranslate_hits = 0&lt;BR /&gt;Source - Origin: 10.10.10.0/24, Translated: 10.10.10.0/24&lt;BR /&gt;Destination - Origin: 172.18.1.0/24, Translated: 172.18.1.0/24&lt;BR /&gt;6 (OsloEth0+modem1+management-oslo_2) to (outside) source static NO_NAT_VPN_DESTINATION2 NO_NAT_VPN_DESTINATION2 destination static NO_NAT_VPN_CLASS NO_NAT_VPN_CLASS no-proxy-arp route-lookup&lt;BR /&gt;translate_hits = 5, untranslate_hits = 0&lt;BR /&gt;Source - Origin: 10.10.10.0/24, Translated: 10.10.10.0/24&lt;BR /&gt;Destination - Origin: 172.18.1.0/24, Translated: 172.18.1.0/24&lt;BR /&gt;7 (osloEth1+modem2_1) to (outside) source static NO_NAT_VPN_DESTINATION1 NO_NAT_VPN_DESTINATION1 destination static NO_NAT_VPN_CLASS NO_NAT_VPN_CLASS no-proxy-arp route-lookup&lt;BR /&gt;translate_hits = 0, untranslate_hits = 0&lt;BR /&gt;Source - Origin: 10.10.11.0/24, Translated: 10.10.11.0/24&lt;BR /&gt;Destination - Origin: 172.18.1.0/24, Translated: 172.18.1.0/24&lt;BR /&gt;8 (osloEth1+modem2_2) to (outside) source static NO_NAT_VPN_DESTINATION1 NO_NAT_VPN_DESTINATION1 destination static NO_NAT_VPN_CLASS NO_NAT_VPN_CLASS no-proxy-arp route-lookup&lt;BR /&gt;translate_hits = 427, untranslate_hits = 0&lt;BR /&gt;Source - Origin: 10.10.11.0/24, Translated: 10.10.11.0/24&lt;BR /&gt;Destination - Origin: 172.18.1.0/24, Translated: 172.18.1.0/24&lt;BR /&gt;9 (osloEth1+modem2_2) to (outside) source static NO_NAT_VPN_DESTINATION2 NO_NAT_VPN_DESTINATION2 destination static NO_NAT_VPN_CLASS NO_NAT_VPN_CLASS no-proxy-arp route-lookup&lt;BR /&gt;translate_hits = 0, untranslate_hits = 0&lt;BR /&gt;Source - Origin: 10.10.10.0/24, Translated: 10.10.10.0/24&lt;BR /&gt;Destination - Origin: 172.18.1.0/24, Translated: 172.18.1.0/24&lt;BR /&gt;10 (osloEth1+modem2_1) to (outside) source static NO_NAT_VPN_DESTINATION2 NO_NAT_VPN_DESTINATION2 destination static NO_NAT_VPN_CLASS NO_NAT_VPN_CLASS no-proxy-arp route-lookup&lt;BR /&gt;translate_hits = 0, untranslate_hits = 0&lt;BR /&gt;Source - Origin: 10.10.10.0/24, Translated: 10.10.10.0/24&lt;BR /&gt;Destination - Origin: 172.18.1.0/24, Translated: 172.18.1.0/24&lt;BR /&gt;11 (any) to (outside) source static ANYCONNECT-POOL ANYCONNECT-POOL destination static NO_NAT_VPN_DESTINATION1 NO_NAT_VPN_DESTINATION1 no-proxy-arp route-lookup&lt;BR /&gt;translate_hits = 0, untranslate_hits = 0&lt;BR /&gt;Source - Origin: 10.10.10.239-10.10.10.254, Translated: 10.10.10.239-10.10.10.254&lt;BR /&gt;Destination - Origin: 10.10.11.0/24, Translated: 10.10.11.0/24&lt;BR /&gt;12 (any) to (outside) source static NO_NAT_VPN_DESTINATION1 NO_NAT_VPN_DESTINATION1 destination static ANYCONNECT-POOL ANYCONNECT-POOL no-proxy-arp route-lookup&lt;BR /&gt;translate_hits = 7, untranslate_hits = 0&lt;BR /&gt;Source - Origin: 10.10.11.0/24, Translated: 10.10.11.0/24&lt;BR /&gt;Destination - Origin: 10.10.10.239-10.10.10.254, Translated: 10.10.10.239-10.10.10.254&lt;/P&gt;&lt;P&gt;Auto NAT Policies (Section 2)&lt;BR /&gt;1 (Local-Codecs) to (outside) source static 6.2-VNC interface service tcp 5901 5901&lt;BR /&gt;translate_hits = 0, untranslate_hits = 305903&lt;BR /&gt;Source - Origin: 192.168.6.2/32, Translated: 89.238.216.40/28&lt;BR /&gt;Service - Protocol: tcp Real: 5901 Mapped: 5901&lt;BR /&gt;2 (Local-Codecs) to (outside) source static 6.6-VNC interface service tcp 5900 5900&lt;BR /&gt;translate_hits = 0, untranslate_hits = 1031745&lt;BR /&gt;Source - Origin: 192.168.6.6/32, Translated: 89.238.216.40/28&lt;BR /&gt;Service - Protocol: tcp Real: 5900 Mapped: 5900&lt;BR /&gt;3 (outside) to (outside) source dynamic ANYCONNECT-POOL interface&lt;BR /&gt;translate_hits = 357, untranslate_hits = 0&lt;BR /&gt;Source - Origin: 10.10.10.239-10.10.10.254, Translated: 89.238.216.40/28&lt;BR /&gt;4 (Local-Codecs) to (outside) source dynamic Local-Codecs interface&lt;BR /&gt;translate_hits = 445775, untranslate_hits = 6982&lt;BR /&gt;Source - Origin: 192.168.6.0/24, Translated: 89.238.216.40/28&lt;BR /&gt;5 (EuroRadio_CGT) to (outside) source dynamic EuroRadio_CGT interface&lt;BR /&gt;translate_hits = 661893, untranslate_hits = 57196&lt;BR /&gt;Source - Origin: 192.168.101.0/24, Translated: 89.238.216.40/28&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 04 Jun 2020 12:38:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/anyconnect-unable-to-connect-network-inside-bvi-interface/m-p/4097548#M1070750</guid>
      <dc:creator>Calin Cristea</dc:creator>
      <dc:date>2020-06-04T12:38:49Z</dc:date>
    </item>
    <item>
      <title>Re: Anyconnect unable to connect network -  inside bvi interface</title>
      <link>https://community.cisco.com/t5/network-security/anyconnect-unable-to-connect-network-inside-bvi-interface/m-p/4097564#M1070752</link>
      <description>&lt;P&gt;while you connected to anyconnect could you reach to address 10.10.11.0/24 I know when you did a packet tracer it is showing its taking the right path for natting. instead of doing a packet tracer could you please connect at something on 10.10.11.0/24 range. i mean in term of real live network. your nat rules and tunnel-group and the group-policy looks good.&lt;/P&gt;
&lt;P&gt;could you also double check your split tunnel ip addresses are shown in your anyconnect client.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="any.PNG" style="width: 610px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/76053i0F9E8AE4D862D62E/image-size/large?v=v2&amp;amp;px=999" role="button" title="any.PNG" alt="any.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 04 Jun 2020 12:52:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/anyconnect-unable-to-connect-network-inside-bvi-interface/m-p/4097564#M1070752</guid>
      <dc:creator>Sheraz.Salim</dc:creator>
      <dc:date>2020-06-04T12:52:52Z</dc:date>
    </item>
    <item>
      <title>Re: Anyconnect unable to connect network -  inside bvi interface</title>
      <link>https://community.cisco.com/t5/network-security/anyconnect-unable-to-connect-network-inside-bvi-interface/m-p/4103106#M1071029</link>
      <description>It turns out that the end device did not had a default route backwords (gateway).&lt;BR /&gt;Many thanks Salim for you`re support . 5 stars for you`re professionalism!</description>
      <pubDate>Mon, 15 Jun 2020 06:05:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/anyconnect-unable-to-connect-network-inside-bvi-interface/m-p/4103106#M1071029</guid>
      <dc:creator>Calin Cristea</dc:creator>
      <dc:date>2020-06-15T06:05:01Z</dc:date>
    </item>
  </channel>
</rss>

