<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Anyconnect configuration Cisco 1010 in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/anyconnect-configuration-cisco-1010/m-p/4789081#M1098439</link>
    <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/97036"&gt;@Rob Ingram&lt;/a&gt;&amp;nbsp; Hello - I have placed the NAT on the top -- its working fine but now the issue is the second NAT OVPN_DSM stopped working!!&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 08 Mar 2023 07:21:03 GMT</pubDate>
    <dc:creator>saids3</dc:creator>
    <dc:date>2023-03-08T07:21:03Z</dc:date>
    <item>
      <title>Anyconnect configuration Cisco 1010</title>
      <link>https://community.cisco.com/t5/network-security/anyconnect-configuration-cisco-1010/m-p/4788580#M1098424</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;/P&gt;&lt;P&gt;I don't have the option of selecting inside the interface to enable the exempt option for anyconnect!!&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Should I disable it?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do I need any specific NAT or ACL to enable anyconnect?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 07 Mar 2023 11:47:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/anyconnect-configuration-cisco-1010/m-p/4788580#M1098424</guid>
      <dc:creator>saids3</dc:creator>
      <dc:date>2023-03-07T11:47:37Z</dc:date>
    </item>
    <item>
      <title>Re: Anyconnect configuration Cisco 1010</title>
      <link>https://community.cisco.com/t5/network-security/anyconnect-configuration-cisco-1010/m-p/4788597#M1098425</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/386513"&gt;@saids3&lt;/a&gt; yes you will likely need a NAT exemption rule, otherwise traffic would be unintentially translated behind the outside interface.&lt;/P&gt;
&lt;P&gt;What is the configuration of your interfaces?&lt;/P&gt;
&lt;P&gt;Are you actually using a BVI?&lt;/P&gt;
&lt;P&gt;If you have VLANs configured, you specify the VLAN in the NAT rule not the physical interface.&lt;/P&gt;</description>
      <pubDate>Tue, 07 Mar 2023 11:56:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/anyconnect-configuration-cisco-1010/m-p/4788597#M1098425</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2023-03-07T11:56:48Z</dc:date>
    </item>
    <item>
      <title>Re: Anyconnect configuration Cisco 1010</title>
      <link>https://community.cisco.com/t5/network-security/anyconnect-configuration-cisco-1010/m-p/4788601#M1098426</link>
      <description>&lt;P&gt;Yes I'm using BV1&lt;/P&gt;&lt;P&gt;Here is my VPN-NAT ----&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 07 Mar 2023 12:04:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/anyconnect-configuration-cisco-1010/m-p/4788601#M1098426</guid>
      <dc:creator>saids3</dc:creator>
      <dc:date>2023-03-07T12:04:23Z</dc:date>
    </item>
    <item>
      <title>Re: Anyconnect configuration Cisco 1010</title>
      <link>https://community.cisco.com/t5/network-security/anyconnect-configuration-cisco-1010/m-p/4788613#M1098427</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/386513"&gt;@saids3&lt;/a&gt; almost looks ok, just change the source address under both original packet and translated packet to an object representing the network behind inside_2 interface (rather than using any) - then you have a NAT exemption rule between the inside network and the VPN pool. You will need to duplicate the NAT rule for the other BVI interfaces (inside_3, inside_4 etc).&lt;/P&gt;</description>
      <pubDate>Tue, 07 Mar 2023 12:38:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/anyconnect-configuration-cisco-1010/m-p/4788613#M1098427</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2023-03-07T12:38:45Z</dc:date>
    </item>
    <item>
      <title>Re: Anyconnect configuration Cisco 1010</title>
      <link>https://community.cisco.com/t5/network-security/anyconnect-configuration-cisco-1010/m-p/4789081#M1098439</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/97036"&gt;@Rob Ingram&lt;/a&gt;&amp;nbsp; Hello - I have placed the NAT on the top -- its working fine but now the issue is the second NAT OVPN_DSM stopped working!!&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 08 Mar 2023 07:21:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/anyconnect-configuration-cisco-1010/m-p/4789081#M1098439</guid>
      <dc:creator>saids3</dc:creator>
      <dc:date>2023-03-08T07:21:03Z</dc:date>
    </item>
    <item>
      <title>Re: Anyconnect configuration Cisco 1010</title>
      <link>https://community.cisco.com/t5/network-security/anyconnect-configuration-cisco-1010/m-p/4789339#M1098445</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/386513"&gt;@saids3&lt;/a&gt; you need to be more specific in your NAT rules. Don't use "any" for interface or the networks, use the specific interface and a network object - otherwise you will have unintended NAT translations.&lt;/P&gt;</description>
      <pubDate>Wed, 08 Mar 2023 08:01:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/anyconnect-configuration-cisco-1010/m-p/4789339#M1098445</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2023-03-08T08:01:53Z</dc:date>
    </item>
    <item>
      <title>Re: Anyconnect configuration Cisco 1010</title>
      <link>https://community.cisco.com/t5/network-security/anyconnect-configuration-cisco-1010/m-p/4789374#M1098451</link>
      <description>&lt;P&gt;Still same issue - please see the nat setting the first nat is working second not and if I swap the first always works. My network is based on BVI ---&lt;/P&gt;</description>
      <pubDate>Wed, 08 Mar 2023 09:00:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/anyconnect-configuration-cisco-1010/m-p/4789374#M1098451</guid>
      <dc:creator>saids3</dc:creator>
      <dc:date>2023-03-08T09:00:32Z</dc:date>
    </item>
    <item>
      <title>Re: Anyconnect configuration Cisco 1010</title>
      <link>https://community.cisco.com/t5/network-security/anyconnect-configuration-cisco-1010/m-p/4789376#M1098452</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/386513"&gt;@saids3&lt;/a&gt; i thought the objective was to exempt VPN traffic? You need to specify the original and translated source addess as the same network object and the original and translated destination the same network object. This ensures VPN traffic is not unintentially translated.&lt;/P&gt;
&lt;P&gt;Example:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="nat exemption.png" style="width: 701px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/178367i2B0D89CBB4B79D36/image-size/large?v=v2&amp;amp;px=999" role="button" title="nat exemption.png" alt="nat exemption.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 08 Mar 2023 09:07:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/anyconnect-configuration-cisco-1010/m-p/4789376#M1098452</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2023-03-08T09:07:42Z</dc:date>
    </item>
    <item>
      <title>Re: Anyconnect configuration Cisco 1010</title>
      <link>https://community.cisco.com/t5/network-security/anyconnect-configuration-cisco-1010/m-p/4789418#M1098462</link>
      <description>&lt;P&gt;Sorry! but still not working! The good thing is nat number#2 still working!&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 08 Mar 2023 10:18:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/anyconnect-configuration-cisco-1010/m-p/4789418#M1098462</guid>
      <dc:creator>saids3</dc:creator>
      <dc:date>2023-03-08T10:18:38Z</dc:date>
    </item>
    <item>
      <title>Re: Anyconnect configuration Cisco 1010</title>
      <link>https://community.cisco.com/t5/network-security/anyconnect-configuration-cisco-1010/m-p/4789420#M1098463</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/386513"&gt;@saids3&lt;/a&gt; what is the relevance of the anyconnect connection failure in your screenshot? &lt;/P&gt;
&lt;P&gt;Rule#1 would work for traffic from VLAN1 sourced from inside_8 to the VPN-POOL, for any user connected to the VPN. It would have no relevance to establish a VPN if thats what you mean?&lt;/P&gt;</description>
      <pubDate>Wed, 08 Mar 2023 10:24:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/anyconnect-configuration-cisco-1010/m-p/4789420#M1098463</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2023-03-08T10:24:06Z</dc:date>
    </item>
    <item>
      <title>Re: Anyconnect configuration Cisco 1010</title>
      <link>https://community.cisco.com/t5/network-security/anyconnect-configuration-cisco-1010/m-p/4790193#M1098527</link>
      <description>&lt;P&gt;hello&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/97036"&gt;@Rob Ingram&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;any suggestion I need to VPN my network from outside -&amp;nbsp;&lt;/P&gt;&lt;P&gt;I tried this but still failed!!&lt;/P&gt;</description>
      <pubDate>Thu, 09 Mar 2023 10:12:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/anyconnect-configuration-cisco-1010/m-p/4790193#M1098527</guid>
      <dc:creator>saids3</dc:creator>
      <dc:date>2023-03-09T10:12:40Z</dc:date>
    </item>
  </channel>
</rss>

