<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic So I restored the original in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/remote-access-vpn-users-cannot-access-inside-network-on-asa-5505/m-p/2748730#M192464</link>
    <description>&lt;P&gt;Correct Answer:&lt;/P&gt;&lt;P&gt;So I restored the original configuration and changed the inside network address range and found that, while the packet tracer still failed, physically, the network&amp;nbsp;began working correctly instantly.&lt;/P&gt;&lt;P&gt;It appears that the clients inside address range falling within the reserved&amp;nbsp;link-local range was causing the ASA to drop packets.&lt;/P&gt;&lt;P&gt;The inside network has now been modified, problem solved.&lt;/P&gt;</description>
    <pubDate>Tue, 29 Sep 2015 02:43:04 GMT</pubDate>
    <dc:creator>cliveschneider</dc:creator>
    <dc:date>2015-09-29T02:43:04Z</dc:date>
    <item>
      <title>remote access VPN users cannot access inside network on ASA 5505</title>
      <link>https://community.cisco.com/t5/network-security/remote-access-vpn-users-cannot-access-inside-network-on-asa-5505/m-p/2748724#M192458</link>
      <description>&lt;P&gt;I have configured a Cisco ASA 5505 with remote access VPN&amp;nbsp;as follows:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;ASA outside:&amp;nbsp;192.168.0.254/24&lt;/LI&gt;&lt;LI&gt;ASA&amp;nbsp;inside&amp;nbsp;169.254.1.254/24&amp;nbsp;&lt;/LI&gt;&lt;LI&gt;VPN address pool: 192.168.3.0/24&lt;/LI&gt;&lt;LI&gt;inside network: 169.254.1.0/24&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;The VPN pool of hosts should have full access to the inside network. Config file is attached.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As far as I can tell, the NAT rules and access rules are correct (Im obviously missing something) but VPN remote access hosts cannot contact the inside network. I have trued varouos combinations of NAT and access rules and cannot get the VPN network talking to the inside network.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 06:28:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/remote-access-vpn-users-cannot-access-inside-network-on-asa-5505/m-p/2748724#M192458</guid>
      <dc:creator>cliveschneider</dc:creator>
      <dc:date>2019-03-12T06:28:55Z</dc:date>
    </item>
    <item>
      <title>Remove these lines and try it</title>
      <link>https://community.cisco.com/t5/network-security/remote-access-vpn-users-cannot-access-inside-network-on-asa-5505/m-p/2748725#M192459</link>
      <description>&lt;P&gt;Remove these lines and try it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;global (inside) 2 interface&lt;BR /&gt;nat (outside) 2 vpn-network 255.255.255.0 outside&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;access-group inside_access_in in interface inside&lt;BR /&gt;access-group inside_access_out out interface inside&lt;/P&gt;</description>
      <pubDate>Mon, 24 Aug 2015 14:58:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/remote-access-vpn-users-cannot-access-inside-network-on-asa-5505/m-p/2748725#M192459</guid>
      <dc:creator>rizwanr74</dc:creator>
      <dc:date>2015-08-24T14:58:30Z</dc:date>
    </item>
    <item>
      <title>Hi rizwanr74, That didnt work</title>
      <link>https://community.cisco.com/t5/network-security/remote-access-vpn-users-cannot-access-inside-network-on-asa-5505/m-p/2748726#M192460</link>
      <description>&lt;P&gt;Hi rizwanr74,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;That didnt work, on a Windows machine connected over VPN, I get&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: Arial, Helvetica, sans-serif; font-size: 14px; line-height: 21px;"&gt;Ping:transmit failed. General failure.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;when I try ping an inside device, like there is no route on the ASA?&lt;/P&gt;</description>
      <pubDate>Tue, 25 Aug 2015 20:02:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/remote-access-vpn-users-cannot-access-inside-network-on-asa-5505/m-p/2748726#M192460</guid>
      <dc:creator>cliveschneider</dc:creator>
      <dc:date>2015-08-25T20:02:56Z</dc:date>
    </item>
    <item>
      <title>Can you remove the below line</title>
      <link>https://community.cisco.com/t5/network-security/remote-access-vpn-users-cannot-access-inside-network-on-asa-5505/m-p/2748727#M192461</link>
      <description>&lt;P&gt;Can you remove the below&amp;nbsp;line and try it?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;access-group outside_access_out out interface outside&lt;/P&gt;</description>
      <pubDate>Tue, 25 Aug 2015 20:40:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/remote-access-vpn-users-cannot-access-inside-network-on-asa-5505/m-p/2748727#M192461</guid>
      <dc:creator>rizwanr74</dc:creator>
      <dc:date>2015-08-25T20:40:23Z</dc:date>
    </item>
    <item>
      <title>Hi rizwanr74,That didn't work</title>
      <link>https://community.cisco.com/t5/network-security/remote-access-vpn-users-cannot-access-inside-network-on-asa-5505/m-p/2748728#M192462</link>
      <description>&lt;P&gt;&lt;SPAN style="font-size:12px;"&gt;&lt;SPAN style="font-family:arial,helvetica,sans-serif;"&gt;Hi rizwanr74,&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:12px;"&gt;&lt;SPAN style="font-family:arial,helvetica,sans-serif;"&gt;That&amp;nbsp;didn't&amp;nbsp;work either. I ran the&amp;nbsp;packet tracer and an implicit access rule is denying access, even though there is a configured rule that should override it.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:12px;"&gt;&lt;SPAN style="font-family:arial,helvetica,sans-serif;"&gt;See screenshot attached.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:12px;"&gt;&lt;SPAN style="font-family:arial,helvetica,sans-serif;"&gt;The clients inside network was for some reason configured as&amp;nbsp;169.254.1.0/24, which is&amp;nbsp;is which is in the reserved link-local address&amp;nbsp;range that Microsoft dishes out to hosts when they cant find a DHCP server.&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:12px;"&gt;&lt;SPAN style="font-family:arial,helvetica,sans-serif;"&gt;Is there any chance the ASA wont route traffic to that address range for that reason?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:12px;"&gt;&lt;SPAN style="font-family:arial,helvetica,sans-serif;"&gt;I've set up a couple of ASA 5505s now with similar configs and havent had seen issue before.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 29 Aug 2015 01:53:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/remote-access-vpn-users-cannot-access-inside-network-on-asa-5505/m-p/2748728#M192462</guid>
      <dc:creator>cliveschneider</dc:creator>
      <dc:date>2015-08-29T01:53:41Z</dc:date>
    </item>
    <item>
      <title>I just changed the inside</title>
      <link>https://community.cisco.com/t5/network-security/remote-access-vpn-users-cannot-access-inside-network-on-asa-5505/m-p/2748729#M192463</link>
      <description>&lt;P&gt;I just changed the inside interface and network as a test (I didn't actually change the inside network devices) and I'm still being blocked by the same access rule, so it may be unrelated to being within the reserved link-local address range.&lt;/P&gt;&lt;P&gt;Interestingly, however, attempting to ping the inside network on a Windows machine from the VPN network, the result has changed from:&lt;/P&gt;&lt;P&gt;PING: transmit failed. General failure.&lt;/P&gt;&lt;P&gt;to:&lt;/P&gt;&lt;P&gt;Request timed out.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 29 Aug 2015 02:11:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/remote-access-vpn-users-cannot-access-inside-network-on-asa-5505/m-p/2748729#M192463</guid>
      <dc:creator>cliveschneider</dc:creator>
      <dc:date>2015-08-29T02:11:52Z</dc:date>
    </item>
    <item>
      <title>So I restored the original</title>
      <link>https://community.cisco.com/t5/network-security/remote-access-vpn-users-cannot-access-inside-network-on-asa-5505/m-p/2748730#M192464</link>
      <description>&lt;P&gt;Correct Answer:&lt;/P&gt;&lt;P&gt;So I restored the original configuration and changed the inside network address range and found that, while the packet tracer still failed, physically, the network&amp;nbsp;began working correctly instantly.&lt;/P&gt;&lt;P&gt;It appears that the clients inside address range falling within the reserved&amp;nbsp;link-local range was causing the ASA to drop packets.&lt;/P&gt;&lt;P&gt;The inside network has now been modified, problem solved.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2015 02:43:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/remote-access-vpn-users-cannot-access-inside-network-on-asa-5505/m-p/2748730#M192464</guid>
      <dc:creator>cliveschneider</dc:creator>
      <dc:date>2015-09-29T02:43:04Z</dc:date>
    </item>
  </channel>
</rss>

