<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Dear Amir, in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/remote-network-unreachable-when-using-vpn-client-through-asa/m-p/2504072#M234432</link>
    <description>&lt;P&gt;Dear Amir,&lt;/P&gt;
&lt;P&gt;Can you please provide what are the final settings need to be place and why?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;Sena&lt;/P&gt;</description>
    <pubDate>Tue, 17 May 2016 05:06:43 GMT</pubDate>
    <dc:creator>praveen.sena23</dc:creator>
    <dc:date>2016-05-17T05:06:43Z</dc:date>
    <item>
      <title>Remote network unreachable when using VPN client through ASA</title>
      <link>https://community.cisco.com/t5/network-security/remote-network-unreachable-when-using-vpn-client-through-asa/m-p/2504069#M234429</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;today i ran into a problem, of which I think that it is a ASA problem or bug.&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have a customer who has an ASA 5505 from us. He has only a few clients on the inside network, using address range 192.168.168.0.&lt;/P&gt;&lt;P&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/media/topology_12.jpg" class="migrated-markup-image" /&gt;&lt;/P&gt;&lt;P&gt;He needs also to manage some production analyzing tools in another company, where he builds up a tunnel via Shrewsoft VPN-Client and then connects to the remote host (192.168.0.10/24). A new interface is created by VPN-Client&amp;nbsp;(192.168.46.1) and the routing on the client is set properly:&lt;/P&gt;&lt;P&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/media/route.png" class="migrated-markup-image" /&gt;&lt;/P&gt;&lt;P&gt;With the old Zyxel FW this was working without problems. Without firewall (tethering over mobile-phone) it's also working perfectly.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But when the client is connected to ASA, there is a problem:&lt;/P&gt;&lt;P&gt;The remote client, that needs to be managed (192.168.0.10) isn't reachable.&amp;nbsp;There is nothing logged on ASA - because it's passing through the tunnel.&lt;/P&gt;&lt;P&gt;I have no access to the remote FW, but as it is working from every other network except the one behind ASA, i assume that the configuration should be ok there.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Things I've tried until now:&lt;/P&gt;&lt;P&gt;- permit ESP&lt;/P&gt;&lt;P&gt;- enable inspection for pptp and&amp;nbsp;ipsec-pass-thru&lt;/P&gt;&lt;P&gt;- access-list in- &amp;amp; outbound: permit gre any any, permit tcp pptp any any -&amp;gt; even permit IP any any in&amp;amp;out didn't help&lt;/P&gt;&lt;P&gt;- client: deactivate Windows firewall&lt;/P&gt;&lt;P&gt;- client: Wireshark-capture on tunnel-interface -&amp;gt; when pinging the remote client IP, I only get the ARP request and reply, no ICMP is started&lt;/P&gt;&lt;P&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/media/wireshark.png" class="migrated-markup-image" /&gt;&lt;/P&gt;&lt;P&gt;- client ARP table has the entry for 192.168.0.10 with MAC bb:bb:bb:bb:bb:00&lt;/P&gt;&lt;P&gt;- ASA has a default route outside and only 192.168.168.0/24 inside. 192.168.0.0/24 is not routed on the ASA.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Later, I also tried the same VPN-profile from our headquarters and detailed logging-server -&amp;gt;&amp;nbsp;same issue, tunnel connection OK, but 192.168.0.10 not reachable. Logging doen't show any permit/deny. Connecting over mobile connection (not going over ASA) -&amp;gt; tunnel ok, ping &amp;amp; RDP ok.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would be thankful for any kind of solution!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance,&lt;/P&gt;&lt;P&gt;Amir&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 04:51:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/remote-network-unreachable-when-using-vpn-client-through-asa/m-p/2504069#M234429</guid>
      <dc:creator>amir.glibic</dc:creator>
      <dc:date>2019-03-12T04:51:23Z</dc:date>
    </item>
    <item>
      <title>Hi, Can you pull anykind of</title>
      <link>https://community.cisco.com/t5/network-security/remote-network-unreachable-when-using-vpn-client-through-asa/m-p/2504070#M234430</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you pull anykind of statistics of the VPN Client software when the VPN connection is active to see if any traffic is encapsulated/encrypted?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you list the connections from the client PC on the ASA when the VPN connection is active?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;show conn | inc 192.168.168.x&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Have you enabled Transparent Tunneling (UDP/4500) on the Client software so that the VPN connection works through a Dynamic PAT translation that the local ASA is probably using for internal hosts connections to the Internet?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;</description>
      <pubDate>Thu, 02 Oct 2014 13:29:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/remote-network-unreachable-when-using-vpn-client-through-asa/m-p/2504070#M234430</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2014-10-02T13:29:16Z</dc:date>
    </item>
    <item>
      <title>Hi Jouni, a big Thanks to you</title>
      <link>https://community.cisco.com/t5/network-security/remote-network-unreachable-when-using-vpn-client-through-asa/m-p/2504071#M234431</link>
      <description>&lt;P&gt;Hi Jouni,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;a big Thanks to you!&lt;/P&gt;&lt;P&gt;It was the NAT-Traversal setting in the Shrewsoft-Client. As we always use cisco and have a default profile where it is always enabled, I didn't even think of that.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;BR&lt;BR /&gt;Amir&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 02 Oct 2014 14:04:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/remote-network-unreachable-when-using-vpn-client-through-asa/m-p/2504071#M234431</guid>
      <dc:creator>amir.glibic</dc:creator>
      <dc:date>2014-10-02T14:04:03Z</dc:date>
    </item>
    <item>
      <title>Dear Amir,</title>
      <link>https://community.cisco.com/t5/network-security/remote-network-unreachable-when-using-vpn-client-through-asa/m-p/2504072#M234432</link>
      <description>&lt;P&gt;Dear Amir,&lt;/P&gt;
&lt;P&gt;Can you please provide what are the final settings need to be place and why?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;Sena&lt;/P&gt;</description>
      <pubDate>Tue, 17 May 2016 05:06:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/remote-network-unreachable-when-using-vpn-client-through-asa/m-p/2504072#M234432</guid>
      <dc:creator>praveen.sena23</dc:creator>
      <dc:date>2016-05-17T05:06:43Z</dc:date>
    </item>
    <item>
      <title>Hi,</title>
      <link>https://community.cisco.com/t5/network-security/remote-network-unreachable-when-using-vpn-client-through-asa/m-p/2504073#M234433</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;it was just the checkbox "enable NAT-Traversal" in the Shrewsoft Client Software. No changes on the FW necessary. Cisco VPN-Client/AnyConnect has this setting enabled by default, in Shrewsoft it isn't.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;BR,&lt;/P&gt;
&lt;P&gt;Amir&lt;/P&gt;</description>
      <pubDate>Tue, 17 May 2016 07:25:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/remote-network-unreachable-when-using-vpn-client-through-asa/m-p/2504073#M234433</guid>
      <dc:creator>amir.glibic</dc:creator>
      <dc:date>2016-05-17T07:25:53Z</dc:date>
    </item>
  </channel>
</rss>

