<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic You are welcome. in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/anyconnect-access-to-internal-network/m-p/3001281#M144382</link>
    <description>&lt;P&gt;You are welcome.&lt;/P&gt;
&lt;P&gt;Let us know how you get on with this.&lt;/P&gt;
&lt;P&gt;Please mark your question as answered/resolved if it indeed resolves your question&lt;/P&gt;</description>
    <pubDate>Wed, 07 Dec 2016 07:39:00 GMT</pubDate>
    <dc:creator>mattjones03</dc:creator>
    <dc:date>2016-12-07T07:39:00Z</dc:date>
    <item>
      <title>Anyconnect access to internal network</title>
      <link>https://community.cisco.com/t5/network-security/anyconnect-access-to-internal-network/m-p/3001278#M144377</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I believe I already read all post here about Annyconnect and access to internal network. But I can't found any solucion.&lt;/P&gt;
&lt;P&gt;I need put all traffic in the tunnel, like internet, access to the internal network, and access to other tunnels (site-to-site). In this moment we can connect the AnnyConnect and after I only have internet on the tunnel if I use the IP, because I don't have access to the internal network and I can't use my DNS server. I think I'm missing one NAT but I can't figure out. &amp;nbsp;Some one can take a look and help me, please.&lt;/P&gt;
&lt;P&gt;Internal network 192.168.1.0 255.255.255.0&lt;/P&gt;
&lt;P&gt;VPNPoll 192.168.20.0 255.255.255.0&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Please tell me if you need more information.&amp;nbsp;&lt;/P&gt;
&lt;PRE class="prettyprint"&gt;: Serial Number: *******&lt;BR /&gt;: Hardware: ASA5515,*************&lt;BR /&gt;:&lt;BR /&gt;ASA Version 9.2(2)4 &lt;BR /&gt;!&lt;BR /&gt;hostname CiscoAsaFirewall&lt;BR /&gt;domain-name office.frontiersin.org&lt;BR /&gt;enable password *******************&lt;BR /&gt;names&lt;BR /&gt;ip local pool VPN_DHCP 192.168.20.0-192.168.20.254 mask 255.255.255.0&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/0&lt;BR /&gt; nameif outside&lt;BR /&gt; security-level 0&lt;BR /&gt; ip address 212.243.***.*** 255.255.255.248 &lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/1&lt;BR /&gt; nameif inside&lt;BR /&gt; security-level 100&lt;BR /&gt; ip address 192.168.1.2 255.255.248.0 &lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/2&lt;BR /&gt; shutdown&lt;BR /&gt; no nameif&lt;BR /&gt; no security-level&lt;BR /&gt; no ip address&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/3&lt;BR /&gt; shutdown&lt;BR /&gt; no nameif&lt;BR /&gt; no security-level&lt;BR /&gt; no ip address&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/4&lt;BR /&gt; shutdown&lt;BR /&gt; no nameif&lt;BR /&gt; no security-level&lt;BR /&gt; no ip address&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/5&lt;BR /&gt; shutdown&lt;BR /&gt; no nameif&lt;BR /&gt; no security-level&lt;BR /&gt; no ip address&lt;BR /&gt;!&lt;BR /&gt;interface Management0/0&lt;BR /&gt; management-only&lt;BR /&gt; no nameif&lt;BR /&gt; no security-level&lt;BR /&gt; no ip address&lt;BR /&gt;!&lt;BR /&gt;ftp mode passive&lt;BR /&gt;clock timezone CEST 1&lt;BR /&gt;clock summer-time CEDT recurring last Sun Mar 2:00 last Sun Oct 3:00&lt;BR /&gt;dns domain-lookup inside&lt;BR /&gt;dns server-group DefaultDNS&lt;BR /&gt; name-server 192.168.1.220&lt;BR /&gt; domain-name office.frontiersin.org&lt;BR /&gt;same-security-traffic permit intra-interface&lt;BR /&gt;object network obj_any&lt;BR /&gt; subnet 0.0.0.0 0.0.0.0&lt;BR /&gt;object network obj-0.0.0.0&lt;BR /&gt; subnet 0.0.0.0 0.0.0.0&lt;BR /&gt;object network NETWORK_OBJ_192.168.20.0_24&lt;BR /&gt; subnet 192.168.20.0 255.255.255.0&lt;BR /&gt;object network obj_inside&lt;BR /&gt; subnet 192.168.1.0 255.255.255.0&lt;BR /&gt; description Lan&lt;BR /&gt;object network obj_anyconnectpool&lt;BR /&gt; subnet 192.168.20.0 255.255.255.0&lt;BR /&gt;object network inside_net&lt;BR /&gt;object network obj-AnyconnectPool&lt;BR /&gt;object network Rackspace_Cloud&lt;BR /&gt; subnet 10.176.0.0 255.240.0.0&lt;BR /&gt;object network VPN-LOCAL-TEST&lt;BR /&gt; subnet 192.168.24.0 255.255.248.0&lt;BR /&gt;object network VPN-REMOTE-TEST&lt;BR /&gt; subnet 10.176.0.0 255.240.0.0&lt;BR /&gt;object network AD-Server&lt;BR /&gt; host 192.168.1.220&lt;BR /&gt;object network inside&lt;BR /&gt;object network vpnpool&lt;BR /&gt;object-group network AZURE-INTEGRATION-SUBNET&lt;BR /&gt; description Subnet for Integration Environments on Azure&lt;BR /&gt; network-object 192.168.128.0 255.255.128.0&lt;BR /&gt; network-object *****************************&lt;BR /&gt;object-group network LOCAL-INSIDE-NETWORK&lt;BR /&gt; description Local Subnet&lt;BR /&gt; network-object 192.168.0.0 255.255.248.0&lt;BR /&gt;object-group service WinRDP tcp&lt;BR /&gt; description Windows Remote Desktop Connection&lt;BR /&gt; port-object eq 3389&lt;BR /&gt;object-group service DM_INLINE_SERVICE_1&lt;BR /&gt; service-object icmp &lt;BR /&gt; service-object tcp destination eq www &lt;BR /&gt; service-object tcp destination eq https &lt;BR /&gt;object-group network DM_INLINE_NETWORK_1&lt;BR /&gt; network-object object NETWORK_OBJ_192.168.20.0_24&lt;BR /&gt; network-object object obj_inside&lt;BR /&gt;object-group network obj-anyconnect&lt;BR /&gt;object-group network DM_INLINE_NETWORK_2&lt;BR /&gt; network-object object NETWORK_OBJ_192.168.20.0_24&lt;BR /&gt; network-object object obj_anyconnectpool&lt;BR /&gt; network-object object obj_inside&lt;BR /&gt;object-group network DM_INLINE_NETWORK_3&lt;BR /&gt; network-object object NETWORK_OBJ_192.168.20.0_24&lt;BR /&gt; network-object object obj_anyconnectpool&lt;BR /&gt; network-object object obj_inside&lt;BR /&gt;access-list AnyConnect_Client_Local_Print extended deny ip any4 any4 &lt;BR /&gt;access-list AnyConnect_Client_Local_Print extended permit tcp any4 any4 eq lpd &lt;BR /&gt;access-list AnyConnect_Client_Local_Print remark IPP: Internet Printing Protocol&lt;BR /&gt;access-list AnyConnect_Client_Local_Print extended permit tcp any4 any4 eq 631 &lt;BR /&gt;access-list AnyConnect_Client_Local_Print remark Windows printing port&lt;BR /&gt;access-list AnyConnect_Client_Local_Print extended permit tcp any4 any4 eq 9100 &lt;BR /&gt;access-list AnyConnect_Client_Local_Print remark mDNS: multicast DNS protocol&lt;BR /&gt;access-list AnyConnect_Client_Local_Print extended permit udp any4 host 224.0.0.251 eq 5353 &lt;BR /&gt;access-list AnyConnect_Client_Local_Print remark LLMNR: Link Local Multicast Name Resolution protocol&lt;BR /&gt;access-list AnyConnect_Client_Local_Print extended permit udp any4 host 224.0.0.252 eq 5355 &lt;BR /&gt;access-list AnyConnect_Client_Local_Print remark TCP/NetBIOS protocol&lt;BR /&gt;access-list AnyConnect_Client_Local_Print extended permit tcp any4 any4 eq 137 &lt;BR /&gt;access-list AnyConnect_Client_Local_Print extended permit udp any4 any4 eq netbios-ns &lt;BR /&gt;access-list 101 extended permit ip object-group LOCAL-INSIDE-NETWORK object-group AZURE-INTEGRATION-SUBNET &lt;BR /&gt;access-list inside_access_in extended permit ip any any &lt;BR /&gt;access-list Local_LAN_Access remark Client Local LAN Access&lt;BR /&gt;access-list Local_LAN_Access standard permit 192.168.0.0 255.255.248.0 &lt;BR /&gt;access-list global_access extended permit ip object-group DM_INLINE_NETWORK_2 any &lt;BR /&gt;access-list AnyConnet remark Allow users VPN can connect to internet&lt;BR /&gt;access-list AnyConnet extended permit object-group DM_INLINE_SERVICE_1 object NETWORK_OBJ_192.168.20.0_24 any &lt;BR /&gt;access-list natoutvpn extended permit ip 192.168.20.0 255.255.255.0 any &lt;BR /&gt;access-list anyconnect extended permit ip 192.168.20.0 255.255.255.0 any &lt;BR /&gt;access-list outside_cryptomap_1 extended permit ip object VPN-LOCAL-TEST object VPN-REMOTE-TEST &lt;BR /&gt;access-list INSIDE-NAT0 remark NAT0 for VPN&lt;BR /&gt;access-list INSIDE-NAT0 extended permit ip 192.168.1.0 255.255.255.0 192.168.20.0 255.255.255.0 &lt;BR /&gt;access-list outside_access_in extended permit ip object-group DM_INLINE_NETWORK_3 any &lt;BR /&gt;access-list nonat extended permit ip 192.168.1.0 255.255.255.0 192.168.20.0 255.255.255.0 &lt;BR /&gt;access-list SPLIT_TUNNEL extended permit ip 192.168.1.0 255.255.255.0 any &lt;BR /&gt;pager lines 24&lt;BR /&gt;logging enable&lt;BR /&gt;logging asdm informational&lt;BR /&gt;mtu outside 1500&lt;BR /&gt;mtu inside 1500&lt;BR /&gt;no failover&lt;BR /&gt;icmp unreachable rate-limit 1 burst-size 1&lt;BR /&gt;asdm image disk0:/asdm-762.bin&lt;BR /&gt;no asdm history enable&lt;BR /&gt;arp timeout 14400&lt;BR /&gt;no arp permit-nonconnected&lt;BR /&gt;nat (inside,outside) source static LOCAL-INSIDE-NETWORK LOCAL-INSIDE-NETWORK destination static AZURE-INTEGRATION-SUBNET AZURE-INTEGRATION-SUBNET&lt;BR /&gt;nat (inside,outside) source static obj_inside obj_inside destination static obj_anyconnectpool obj_anyconnectpool no-proxy-arp route-lookup&lt;BR /&gt;nat (inside,any) source static obj_inside obj_inside destination static obj_anyconnectpool obj_anyconnectpool no-proxy-arp description NONAT&lt;BR /&gt;nat (inside,outside) source dynamic NETWORK_OBJ_192.168.20.0_24 interface&lt;BR /&gt;nat (inside,outside) source static obj_inside obj_inside destination static NETWORK_OBJ_192.168.20.0_24 NETWORK_OBJ_192.168.20.0_24&lt;BR /&gt;nat (inside,outside) source static any any destination static NETWORK_OBJ_192.168.20.0_24 NETWORK_OBJ_192.168.20.0_24 no-proxy-arp route-lookup&lt;BR /&gt;nat (inside,outside) source static any any destination static obj_inside obj_inside no-proxy-arp route-lookup&lt;BR /&gt;nat (any,outside) source dynamic DM_INLINE_NETWORK_1 interface&lt;BR /&gt;nat (inside,outside) source dynamic any interface&lt;BR /&gt;nat (outside,outside) source dynamic NETWORK_OBJ_192.168.20.0_24 interface&lt;BR /&gt;nat (inside,outside) source dynamic obj_inside interface&lt;BR /&gt;nat (outside,outside) source dynamic obj_inside interface&lt;BR /&gt;!&lt;BR /&gt;nat (outside,outside) after-auto source dynamic obj_anyconnectpool interface&lt;BR /&gt;access-group outside_access_in in interface outside&lt;BR /&gt;access-group inside_access_in in interface inside&lt;BR /&gt;access-group global_access global&lt;BR /&gt;route outside 0.0.0.0 0.0.0.0 212.243.***.*** 1&lt;BR /&gt;timeout xlate 3:00:00&lt;BR /&gt;timeout pat-xlate 0:00:30&lt;BR /&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02&lt;BR /&gt;timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00&lt;BR /&gt;timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00&lt;BR /&gt;timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute&lt;BR /&gt;timeout tcp-proxy-reassembly 0:01:00&lt;BR /&gt;timeout floating-conn 0:00:00&lt;BR /&gt;dynamic-access-policy-record DfltAccessPolicy&lt;BR /&gt;user-identity default-domain LOCAL&lt;BR /&gt;http server enable&lt;BR /&gt;http 192.168.1.0 255.255.255.0 inside&lt;BR /&gt;snmp-server group Frontiers v3 auth &lt;BR /&gt;snmp-server host inside 192.168.1.201 community ***** version 2c&lt;BR /&gt;snmp-server location Rack&lt;BR /&gt;snmp-server contact Vitor Fonseca&lt;BR /&gt;snmp-server community *****&lt;BR /&gt;sysopt connection tcpmss 1350&lt;BR /&gt;sysopt connection preserve-vpn-flows&lt;BR /&gt;crypto ipsec ikev1 transform-set AZURE-TRANSFORM esp-aes-256 esp-sha-hmac &lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-3DES-MD5 esp-3des esp-md5-hmac &lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-DES-MD5 esp-des esp-md5-hmac &lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-3DES-SHA esp-3des esp-sha-hmac &lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-128-SHA esp-aes esp-sha-hmac &lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-192-SHA esp-aes-192 esp-sha-hmac &lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-128-MD5 esp-aes esp-md5-hmac &lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-192-MD5 esp-aes-192 esp-md5-hmac &lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-256-SHA esp-aes-256 esp-sha-hmac &lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-256-MD5 esp-aes-256 esp-md5-hmac &lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-DES-SHA esp-des esp-sha-hmac &lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-128-SHA-TRANS esp-aes esp-sha-hmac &lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-128-SHA-TRANS mode transport&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-128-MD5-TRANS esp-aes esp-md5-hmac &lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-128-MD5-TRANS mode transport&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-192-SHA-TRANS esp-aes-192 esp-sha-hmac &lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-192-SHA-TRANS mode transport&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-192-MD5-TRANS esp-aes-192 esp-md5-hmac &lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-192-MD5-TRANS mode transport&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-256-SHA-TRANS esp-aes-256 esp-sha-hmac &lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-256-SHA-TRANS mode transport&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-256-MD5-TRANS esp-aes-256 esp-md5-hmac &lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-256-MD5-TRANS mode transport&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-3DES-SHA-TRANS esp-3des esp-sha-hmac &lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-3DES-SHA-TRANS mode transport&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-3DES-MD5-TRANS esp-3des esp-md5-hmac &lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-3DES-MD5-TRANS mode transport&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-DES-SHA-TRANS esp-des esp-sha-hmac &lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-DES-SHA-TRANS mode transport&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-DES-MD5-TRANS esp-des esp-md5-hmac &lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-DES-MD5-TRANS mode transport&lt;BR /&gt;crypto ipsec ikev2 ipsec-proposal DES&lt;BR /&gt; protocol esp encryption des&lt;BR /&gt; protocol esp integrity sha-1 md5&lt;BR /&gt;crypto ipsec ikev2 ipsec-proposal 3DES&lt;BR /&gt; protocol esp encryption 3des&lt;BR /&gt; protocol esp integrity sha-1 md5&lt;BR /&gt;crypto ipsec ikev2 ipsec-proposal AES&lt;BR /&gt; protocol esp encryption aes&lt;BR /&gt; protocol esp integrity sha-1 md5&lt;BR /&gt;crypto ipsec ikev2 ipsec-proposal AES192&lt;BR /&gt; protocol esp encryption aes-192&lt;BR /&gt; protocol esp integrity sha-1 md5&lt;BR /&gt;crypto ipsec ikev2 ipsec-proposal AES256&lt;BR /&gt; protocol esp encryption aes-256&lt;BR /&gt; protocol esp integrity sha-1 md5&lt;BR /&gt;crypto ipsec security-association lifetime seconds 3600&lt;BR /&gt;crypto ipsec security-association lifetime kilobytes 102400000&lt;BR /&gt;crypto ipsec security-association pmtu-aging infinite&lt;BR /&gt;crypto dynamic-map SYSTEM_DEFAULT_CRYPTO_MAP 65535 set ikev1 transform-set ESP-AES-128-SHA &lt;BR /&gt;crypto dynamic-map SYSTEM_DEFAULT_CRYPTO_MAP 65535 set ikev2 ipsec-proposal AES256 AES192 AES 3DES DES&lt;BR /&gt;crypto map outside_map 65535 ipsec-isakmp dynamic SYSTEM_DEFAULT_CRYPTO_MAP&lt;BR /&gt;crypto map inside_map 65535 ipsec-isakmp dynamic SYSTEM_DEFAULT_CRYPTO_MAP&lt;BR /&gt;crypto map inside_map interface inside&lt;BR /&gt;crypto map AZURE-CRYPTO-MAP 1 match address outside_cryptomap_1&lt;BR /&gt;crypto map AZURE-CRYPTO-MAP 1 set peer 95.138.146.99 &lt;BR /&gt;crypto map AZURE-CRYPTO-MAP 1 set ikev1 transform-set ESP-AES-128-SHA E&lt;BR /&gt;crypto map AZURE-CRYPTO-MAP 1 set ikev2 ipsec-proposal DES 3DES AES AES192 AES256&lt;BR /&gt;crypto map AZURE-CRYPTO-MAP 100 match address 101&lt;BR /&gt;crypto map AZURE-CRYPTO-MAP 100 set peer 40.118.110.96 13.81.110.78 &lt;BR /&gt;crypto map AZURE-CRYPTO-MAP 100 set ikev1 transform-set AZURE-TRANSFORM&lt;BR /&gt;crypto map AZURE-CRYPTO-MAP 65535 ipsec-isakmp dynamic SYSTEM_DEFAULT_CRYPTO_MAP&lt;BR /&gt;crypto map AZURE-CRYPTO-MAP interface outside&lt;BR /&gt;crypto ca trustpoint _SmartCallHome_ServerCA&lt;BR /&gt; no validation-usage&lt;BR /&gt; crl configure&lt;BR /&gt;crypto ca trustpoint ASDM_TrustPoint0&lt;BR /&gt; enrollment terminal&lt;BR /&gt; subject-name CN=lausanne-vpn.frontiersin.net&lt;BR /&gt; keypair cert.key&lt;BR /&gt; crl configure&lt;BR /&gt;crypto ca trustpool policy&lt;BR /&gt;crypto ca certificate chain _SmartCallHome_ServerCA&lt;BR /&gt; certificate *******************&lt;BR /&gt; **********************************&lt;BR /&gt; **********************************&lt;BR /&gt; **********************************&lt;BR /&gt; quit&lt;BR /&gt;crypto ca certificate chain ASDM_TrustPoint0&lt;BR /&gt; certificate *******************&lt;BR /&gt; **********************************&lt;BR /&gt; **********************************&lt;BR /&gt; **********************************&lt;BR /&gt; quit&lt;BR /&gt;crypto ikev2 policy 1&lt;BR /&gt; encryption aes-256&lt;BR /&gt; integrity sha&lt;BR /&gt; group 5 2&lt;BR /&gt; prf sha&lt;BR /&gt; lifetime seconds 86400&lt;BR /&gt;crypto ikev2 policy 10&lt;BR /&gt; encryption aes-192&lt;BR /&gt; integrity sha&lt;BR /&gt; group 5 2&lt;BR /&gt; prf sha&lt;BR /&gt; lifetime seconds 86400&lt;BR /&gt;crypto ikev2 policy 20&lt;BR /&gt; encryption aes&lt;BR /&gt; integrity sha&lt;BR /&gt; group 5 2&lt;BR /&gt; prf sha&lt;BR /&gt; lifetime seconds 86400&lt;BR /&gt;crypto ikev2 policy 30&lt;BR /&gt; encryption 3des&lt;BR /&gt; integrity sha&lt;BR /&gt; group 5 2&lt;BR /&gt; prf sha&lt;BR /&gt; lifetime seconds 86400&lt;BR /&gt;crypto ikev2 policy 40&lt;BR /&gt; encryption des&lt;BR /&gt; integrity sha&lt;BR /&gt; group 5 2&lt;BR /&gt; prf sha&lt;BR /&gt; lifetime seconds 86400&lt;BR /&gt;crypto ikev2 enable outside client-services port 443&lt;BR /&gt;crypto ikev2 remote-access trustpoint ASDM_TrustPoint0&lt;BR /&gt;crypto ikev1 enable outside&lt;BR /&gt;crypto ikev1 enable inside&lt;BR /&gt;crypto ikev1 policy 5&lt;BR /&gt; authentication pre-share&lt;BR /&gt; encryption aes-256&lt;BR /&gt; hash sha&lt;BR /&gt; group 2&lt;BR /&gt; lifetime 28800&lt;BR /&gt;telnet timeout 5&lt;BR /&gt;no ssh stricthostkeycheck&lt;BR /&gt;ssh timeout 5&lt;BR /&gt;ssh key-exchange group dh-group1-sha1&lt;BR /&gt;console timeout 0&lt;BR /&gt;threat-detection basic-threat&lt;BR /&gt;threat-detection statistics&lt;BR /&gt;threat-detection statistics tcp-intercept rate-interval 30 burst-rate 400 average-rate 200&lt;BR /&gt;ssl trust-point ASDM_TrustPoint0 inside&lt;BR /&gt;ssl trust-point ASDM_TrustPoint0 outside&lt;BR /&gt;webvpn&lt;BR /&gt; enable outside&lt;BR /&gt; anyconnect image disk0:/anyconnect-win-3.1.03103-k9.pkg 1&lt;BR /&gt; anyconnect enable&lt;BR /&gt; tunnel-group-list enable&lt;BR /&gt;group-policy GroupPolicy_lausanne-vpn internal&lt;BR /&gt;group-policy GroupPolicy_lausanne-vpn attributes&lt;BR /&gt; wins-server none&lt;BR /&gt; dns-server value 192.168.1.220&lt;BR /&gt; vpn-tunnel-protocol ssl-client &lt;BR /&gt; split-tunnel-policy tunnelall&lt;BR /&gt; default-domain value office.frontiersin.org&lt;BR /&gt; split-tunnel-all-dns enable&lt;BR /&gt;group-policy GroupPolicy_95.138.***.*** internal&lt;BR /&gt;group-policy GroupPolicy_95.138.***.*** attributes&lt;BR /&gt; vpn-tunnel-protocol ikev1 ikev2 &lt;BR /&gt;username vafa.sarmas password *************&lt;BR /&gt;username vitor.fonseca password **************&lt;BR /&gt;tunnel-group lausanne-vpn type remote-access&lt;BR /&gt;tunnel-group lausanne-vpn general-attributes&lt;BR /&gt; address-pool VPN_DHCP&lt;BR /&gt; default-group-policy GroupPolicy_lausanne-vpn&lt;BR /&gt;tunnel-group lausanne-vpn webvpn-attributes&lt;BR /&gt; group-alias lausanne-vpn enable&lt;BR /&gt;tunnel-group 40.118.***.*** type ipsec-l2l&lt;BR /&gt;tunnel-group 40.118.***.*** ipsec-attributes&lt;BR /&gt; ikev1 pre-shared-key *****&lt;BR /&gt;tunnel-group 13.81.***.*** type ipsec-l2l&lt;BR /&gt;tunnel-group 13.81.***.*** ipsec-attributes&lt;BR /&gt; ikev1 pre-shared-key *****&lt;BR /&gt;tunnel-group 95.138.***.*** type ipsec-l2l&lt;BR /&gt;tunnel-group 95.138.***.*** general-attributes&lt;BR /&gt; default-group-policy GroupPolicy_95.138.***.***&lt;BR /&gt;tunnel-group 95.138.***.*** ipsec-attributes&lt;BR /&gt; ikev1 pre-shared-key *****&lt;BR /&gt; ikev2 remote-authentication pre-shared-key *****&lt;BR /&gt; ikev2 local-authentication pre-shared-key *****&lt;BR /&gt;!&lt;BR /&gt;class-map icmp-class&lt;BR /&gt; match default-inspection-traffic&lt;BR /&gt;class-map inspection_default&lt;BR /&gt; match default-inspection-traffic&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;policy-map type inspect dns preset_dns_map&lt;BR /&gt; parameters&lt;BR /&gt; message-length maximum client auto&lt;BR /&gt; message-length maximum 512&lt;BR /&gt;policy-map icmp_policyexit&lt;BR /&gt;policy-map icmp_policy&lt;BR /&gt; class icmp-class&lt;BR /&gt; inspect icmp &lt;BR /&gt;policy-map global_policy&lt;BR /&gt; class inspection_default&lt;BR /&gt; inspect dns preset_dns_map &lt;BR /&gt; inspect ftp &lt;BR /&gt; inspect h323 h225 &lt;BR /&gt; inspect h323 ras &lt;BR /&gt; inspect rsh &lt;BR /&gt; inspect rtsp &lt;BR /&gt; inspect esmtp &lt;BR /&gt; inspect sqlnet &lt;BR /&gt; inspect skinny &lt;BR /&gt; inspect sunrpc &lt;BR /&gt; inspect xdmcp &lt;BR /&gt; inspect sip &lt;BR /&gt; inspect netbios &lt;BR /&gt; inspect tftp &lt;BR /&gt; inspect ip-options &lt;BR /&gt; class class-default&lt;BR /&gt; user-statistics accounting&lt;BR /&gt;!&lt;BR /&gt;service-policy global_policy global&lt;BR /&gt;service-policy icmp_policy interface outside&lt;BR /&gt;prompt hostname context &lt;BR /&gt;call-home reporting anonymous&lt;BR /&gt;hpm topN enable&lt;BR /&gt;Cryptochecksum:**********************************&lt;BR /&gt;: end&lt;BR /&gt;asdm image disk0:/asdm-762.bin&lt;BR /&gt;no asdm history enable&lt;/PRE&gt;</description>
      <pubDate>Tue, 12 Mar 2019 08:37:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/anyconnect-access-to-internal-network/m-p/3001278#M144377</guid>
      <dc:creator>frontiersin</dc:creator>
      <dc:date>2019-03-12T08:37:39Z</dc:date>
    </item>
    <item>
      <title>Hi,</title>
      <link>https://community.cisco.com/t5/network-security/anyconnect-access-to-internal-network/m-p/3001279#M144379</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;Looks like you have the relevant NATs in place.&amp;nbsp;Is the firewall the default gateway for your internal network?, If not, do you require a route directing traffic for 192.168.20.0/24 back to your firewall.&lt;/P&gt;
&lt;P&gt;Also, ensure you have permitted access to the internal network if you have a VPN filter in place.&lt;/P&gt;</description>
      <pubDate>Tue, 06 Dec 2016 21:58:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/anyconnect-access-to-internal-network/m-p/3001279#M144379</guid>
      <dc:creator>mattjones03</dc:creator>
      <dc:date>2016-12-06T21:58:06Z</dc:date>
    </item>
    <item>
      <title>Hello Mattjones03</title>
      <link>https://community.cisco.com/t5/network-security/anyconnect-access-to-internal-network/m-p/3001280#M144380</link>
      <description>&lt;P&gt;Hello Mattjones03&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;First many thanks for your quick reply. Because this a lab, I think you are correct and the problem is my firewall this not the default &lt;SPAN&gt;gateway in my internal network.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I will put this in place and after I will test again.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks again.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Dec 2016 07:11:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/anyconnect-access-to-internal-network/m-p/3001280#M144380</guid>
      <dc:creator>frontiersin</dc:creator>
      <dc:date>2016-12-07T07:11:54Z</dc:date>
    </item>
    <item>
      <title>You are welcome.</title>
      <link>https://community.cisco.com/t5/network-security/anyconnect-access-to-internal-network/m-p/3001281#M144382</link>
      <description>&lt;P&gt;You are welcome.&lt;/P&gt;
&lt;P&gt;Let us know how you get on with this.&lt;/P&gt;
&lt;P&gt;Please mark your question as answered/resolved if it indeed resolves your question&lt;/P&gt;</description>
      <pubDate>Wed, 07 Dec 2016 07:39:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/anyconnect-access-to-internal-network/m-p/3001281#M144382</guid>
      <dc:creator>mattjones03</dc:creator>
      <dc:date>2016-12-07T07:39:00Z</dc:date>
    </item>
  </channel>
</rss>

