<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA5516 &amp; VPN help in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa5516-vpn-help/m-p/3010636#M147043</link>
    <description>&lt;P&gt;Hi All&lt;/P&gt;
&lt;P&gt;Hoping someone might be able to help us. We use a Cisco ASA5516 ASA version 9.6(2) and noticed some odd results while monitoring network traffic which we can't explain.&lt;/P&gt;
&lt;P&gt;We have around 10 remote offices that connect back to head office through a VPN connection (mix of adsl, vdsl via cisco 880 series routers) back into the firewall. Now we have noticed that if a user sitting on a pc on the network browses the internet the Source IP shows as the IP address of the computer the user is on and the destination ip is the address of the web site, however, anyone who comes in via VPN shows their vpn ip address as the Source IP but rather than the IP address of the site they visit is shows the ip address of our main domain controller.&lt;/P&gt;
&lt;P&gt;Is that normal behaviour or is there some part of the configuration that we got wrong?&lt;/P&gt;
&lt;P&gt;Cheers&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 08:52:01 GMT</pubDate>
    <dc:creator>timrichards1</dc:creator>
    <dc:date>2019-03-12T08:52:01Z</dc:date>
    <item>
      <title>ASA5516 &amp; VPN help</title>
      <link>https://community.cisco.com/t5/network-security/asa5516-vpn-help/m-p/3010636#M147043</link>
      <description>&lt;P&gt;Hi All&lt;/P&gt;
&lt;P&gt;Hoping someone might be able to help us. We use a Cisco ASA5516 ASA version 9.6(2) and noticed some odd results while monitoring network traffic which we can't explain.&lt;/P&gt;
&lt;P&gt;We have around 10 remote offices that connect back to head office through a VPN connection (mix of adsl, vdsl via cisco 880 series routers) back into the firewall. Now we have noticed that if a user sitting on a pc on the network browses the internet the Source IP shows as the IP address of the computer the user is on and the destination ip is the address of the web site, however, anyone who comes in via VPN shows their vpn ip address as the Source IP but rather than the IP address of the site they visit is shows the ip address of our main domain controller.&lt;/P&gt;
&lt;P&gt;Is that normal behaviour or is there some part of the configuration that we got wrong?&lt;/P&gt;
&lt;P&gt;Cheers&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 08:52:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5516-vpn-help/m-p/3010636#M147043</guid>
      <dc:creator>timrichards1</dc:creator>
      <dc:date>2019-03-12T08:52:01Z</dc:date>
    </item>
    <item>
      <title>Please see the configuration</title>
      <link>https://community.cisco.com/t5/network-security/asa5516-vpn-help/m-p/3010637#M147044</link>
      <description>&lt;P&gt;Please see the configuration guide for Site to site and Client VPN for ASA 9.6 with the below urls.&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://www.cisco.com/c/en/us/support/security/asa-5500-series-next-generation-firewalls/products-installation-and-configuration-guides-list.html" target="_blank"&gt;http://www.cisco.com/c/en/us/support/security/asa-5500-series-next-generation-firewalls/products-installation-and-configuration-guides-list.html&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://www.cisco.com/c/en/us/td/docs/security/asa/asa96/configuration/vpn/asa-96-vpn-config.html" target="_blank"&gt;http://www.cisco.com/c/en/us/td/docs/security/asa/asa96/configuration/vpn/asa-96-vpn-config.html&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://www.cisco.com/c/en/us/td/docs/security/asa/asa96/asdm76/vpn/asdm-76-vpn-config.html" target="_blank"&gt;http://www.cisco.com/c/en/us/td/docs/security/asa/asa96/asdm76/vpn/asdm-76-vpn-config.html&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Hope to help.&lt;/P&gt;</description>
      <pubDate>Thu, 02 Feb 2017 18:03:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5516-vpn-help/m-p/3010637#M147044</guid>
      <dc:creator>syeda3</dc:creator>
      <dc:date>2017-02-02T18:03:38Z</dc:date>
    </item>
    <item>
      <title>many thanks for your reply.</title>
      <link>https://community.cisco.com/t5/network-security/asa5516-vpn-help/m-p/3010638#M147045</link>
      <description>&lt;P&gt;many thanks for your reply. The problem is that we didn't setup the asa a third party did it for us and I'm fairly new to asa configuration&lt;/P&gt;</description>
      <pubDate>Thu, 02 Feb 2017 19:54:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5516-vpn-help/m-p/3010638#M147045</guid>
      <dc:creator>timrichards1</dc:creator>
      <dc:date>2017-02-02T19:54:14Z</dc:date>
    </item>
    <item>
      <title>Where do you see the source</title>
      <link>https://community.cisco.com/t5/network-security/asa5516-vpn-help/m-p/3010639#M147046</link>
      <description>&lt;P&gt;Where do you see the source and destination ip address of the flow? Do you have some monitoring tool looking into the traffic sent across the network? Ideally only the source of the traffic should change between VPN and internal users. The only other aspect I can think of is that VPN users have some sort of proxy setting sending all traffic to some other location causing the destination to be shown as Domain controller.&lt;/P&gt;</description>
      <pubDate>Thu, 02 Feb 2017 20:26:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5516-vpn-help/m-p/3010639#M147046</guid>
      <dc:creator>Rahul Govindan</dc:creator>
      <dc:date>2017-02-02T20:26:45Z</dc:date>
    </item>
    <item>
      <title>Hey, thanks for your reply.</title>
      <link>https://community.cisco.com/t5/network-security/asa5516-vpn-help/m-p/3010640#M147047</link>
      <description>&lt;P&gt;Hey, thanks for your reply. We use the monitoring available in the ASDM then select Logging under Monitoring. When we test web surfing from any vpn connection be it via the anyconnect client or remote office via the vpn tunnel established via the on site cisco 887va router we see the host pc ip address under source then the main DC ip address rather than the web site address.&lt;/P&gt;
&lt;P&gt;I have attached a snip.&lt;/P&gt;</description>
      <pubDate>Thu, 02 Feb 2017 20:38:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5516-vpn-help/m-p/3010640#M147047</guid>
      <dc:creator>timrichards1</dc:creator>
      <dc:date>2017-02-02T20:38:58Z</dc:date>
    </item>
    <item>
      <title>What you are looking at is</title>
      <link>https://community.cisco.com/t5/network-security/asa5516-vpn-help/m-p/3010641#M147048</link>
      <description>&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;What you are looking at is the real and mapped source as per the translation rules. It does not show destination:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;http://www.cisco.com/c/en/us/td/docs/security/asa/syslog-guide/syslogs/logmsgs1.html&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;This syslog id does not show destination ip address. So, your host 10.10.21.192 is getting translated to 210.55.20.210 and source port is 42004.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;You need to check other syslogs surrounding the connection to see the actual connection.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;-&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;AJ&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 02 Feb 2017 22:41:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5516-vpn-help/m-p/3010641#M147048</guid>
      <dc:creator>Ajay Saini</dc:creator>
      <dc:date>2017-02-02T22:41:55Z</dc:date>
    </item>
  </channel>
</rss>

