<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hi Anukalp, Please follow the in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/vpn-ra/m-p/2552187#M236992</link>
    <description>&lt;P&gt;&lt;SPAN style="color: rgb(119, 119, 119); font-size: 14px; background-color: rgb(247, 247, 247);"&gt;Hi Anukalp,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: rgb(119, 119, 119); font-size: 14px; background-color: rgb(247, 247, 247);"&gt;Please follow the configuration guide from Cisco link below.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;http://www.cisco.com/c/en/us/td/docs/security/asa/asa91/configuration/vpn/asa_91_vpn_config/vpn_remote_access.html&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you have a question, let me know.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;Rizwan Rafeek.&lt;/P&gt;</description>
    <pubDate>Mon, 30 Jun 2014 15:32:47 GMT</pubDate>
    <dc:creator>rizwanr74</dc:creator>
    <dc:date>2014-06-30T15:32:47Z</dc:date>
    <item>
      <title>VPN-RA</title>
      <link>https://community.cisco.com/t5/network-security/vpn-ra/m-p/2552184#M236987</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hi Experts..&lt;/P&gt;&lt;P&gt;&amp;nbsp;Pls help me setting up remote access VPN, i want VPN access to setup with my ip address which is not configured on outside interface. Also all inside ip (say 0.0.0.0) are getting nat with outside interface ip. So in this scenario how is it possible.&lt;/P&gt;&lt;P&gt;--------------------------------------------------------------------------------------------&lt;/P&gt;&lt;P&gt;ASA# sh ip&lt;BR /&gt;System IP Addresses:&lt;BR /&gt;Interface&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Name&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; IP address&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Subnet mask&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Method&lt;BR /&gt;GigabitEthernet0/0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; outside&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; X.X.X.5&amp;nbsp;&amp;nbsp; 255.255.255.0&amp;nbsp;&amp;nbsp; manual&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;object network obj_any&lt;BR /&gt;&amp;nbsp;nat (inside,outside) dynamic interface&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;object network obj_any&lt;BR /&gt;&amp;nbsp;subnet 0.0.0.0 0.0.0.0&lt;/P&gt;&lt;P&gt;route outside 0.0.0.0 0.0.0.0&amp;nbsp;X.X.X.6 1&lt;BR /&gt;----------------------------------------------------------------------------------------------&lt;/P&gt;&lt;P&gt;I want to setup VPN with X.X.X.11 ip. Pls suggest how could i do this.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 04:24:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-ra/m-p/2552184#M236987</guid>
      <dc:creator>Anukalp S</dc:creator>
      <dc:date>2019-03-12T04:24:20Z</dc:date>
    </item>
    <item>
      <title>Hi Anukalp, What is the</title>
      <link>https://community.cisco.com/t5/network-security/vpn-ra/m-p/2552185#M236989</link>
      <description>&lt;P&gt;Hi Anukalp,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What is the version of your ASA?&lt;/P&gt;&lt;P&gt;You want to setup IPSec client base Remote access vpn?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 30 Jun 2014 15:11:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-ra/m-p/2552185#M236989</guid>
      <dc:creator>rizwanr74</dc:creator>
      <dc:date>2014-06-30T15:11:07Z</dc:date>
    </item>
    <item>
      <title> Hi.ASA software version is 9</title>
      <link>https://community.cisco.com/t5/network-security/vpn-ra/m-p/2552186#M236991</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hi.&lt;/P&gt;&lt;P&gt;ASA software version is 9.1(2), yes i want to setup IPSec client base RA VPN.&lt;/P&gt;</description>
      <pubDate>Mon, 30 Jun 2014 15:25:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-ra/m-p/2552186#M236991</guid>
      <dc:creator>Anukalp S</dc:creator>
      <dc:date>2014-06-30T15:25:12Z</dc:date>
    </item>
    <item>
      <title>Hi Anukalp, Please follow the</title>
      <link>https://community.cisco.com/t5/network-security/vpn-ra/m-p/2552187#M236992</link>
      <description>&lt;P&gt;&lt;SPAN style="color: rgb(119, 119, 119); font-size: 14px; background-color: rgb(247, 247, 247);"&gt;Hi Anukalp,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: rgb(119, 119, 119); font-size: 14px; background-color: rgb(247, 247, 247);"&gt;Please follow the configuration guide from Cisco link below.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;http://www.cisco.com/c/en/us/td/docs/security/asa/asa91/configuration/vpn/asa_91_vpn_config/vpn_remote_access.html&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you have a question, let me know.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;Rizwan Rafeek.&lt;/P&gt;</description>
      <pubDate>Mon, 30 Jun 2014 15:32:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-ra/m-p/2552187#M236992</guid>
      <dc:creator>rizwanr74</dc:creator>
      <dc:date>2014-06-30T15:32:47Z</dc:date>
    </item>
    <item>
      <title>This is not possible, the VPN</title>
      <link>https://community.cisco.com/t5/network-security/vpn-ra/m-p/2552188#M236993</link>
      <description>&lt;P&gt;This is not possible, the VPN must terminate on the ASA interface.&lt;/P&gt;&lt;P&gt;an option would be to place a switch between your ASA and your ISP router and then create subinterfaces on your outside interface.&amp;nbsp; Assign the wanted VPN IP to one of the subinterfaces and terminate the VPN on that interface.&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;so, if you decide or are able to go this route, you could do the following:&lt;/P&gt;&lt;P&gt;interface gig0/0.10&lt;BR /&gt;vlan 10&lt;BR /&gt;security-level 0&lt;BR /&gt;nameif VPN_int&lt;BR /&gt;ip add x.x.x.11 255.255.255.0&lt;/P&gt;&lt;P&gt;ip local pool VPNPOOL 10.10.10.1-10.10.10.10&lt;/P&gt;&lt;P&gt;crypto ikev1 policy 5&lt;BR /&gt;&amp;nbsp;authentication pre-share&lt;BR /&gt;&amp;nbsp;encryption aes&lt;BR /&gt;&amp;nbsp;hash sha&lt;BR /&gt;&amp;nbsp;group 5&lt;/P&gt;&lt;P&gt;crypto ipsec ikev1 transform-set VPNSET esp-aes esp-sha-hmac&lt;BR /&gt;crypto dynamic-map DYNMAP 65535 set ikev1 transform-set VPNSET&lt;BR /&gt;crypto dynamic-map DYNMAP 65535 set reverse-route&lt;BR /&gt;crypto map VPNMAP 65535 ipsec-isakmp dynamic DYNMAP&lt;BR /&gt;crypto map VPNMAP interface outside&lt;/P&gt;&lt;P&gt;crypto ikev1 enable outside&lt;/P&gt;&lt;P&gt;tunnel-group VPNGROUP type remote-access&lt;/P&gt;&lt;P&gt;tunnel-group NAME-OF-VPN-TUNNEL general-attributes&lt;BR /&gt;&amp;nbsp; address-pool VPNPOOL&lt;BR /&gt;tunnel-group VPNGROUP ipsec-attributes&lt;BR /&gt;&amp;nbsp;ikev1 pre-shared-key PASSWORD&lt;/P&gt;&lt;P&gt;management-access inside&lt;/P&gt;&lt;P&gt;--&lt;/P&gt;&lt;P&gt;Please remember to select a correct answer and rate helpful posts&lt;/P&gt;</description>
      <pubDate>Mon, 30 Jun 2014 15:44:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-ra/m-p/2552188#M236993</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2014-06-30T15:44:34Z</dc:date>
    </item>
    <item>
      <title>  Hi Rizwan.. I know the RA</title>
      <link>https://community.cisco.com/t5/network-security/vpn-ra/m-p/2552189#M236994</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;Hi Rizwan..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I know the RA VPN configuration, my concern is.. could we configure IPSec client base VPN with the ip which is not configured on outside interface but with diferent ip from same segment.&lt;/P&gt;</description>
      <pubDate>Mon, 30 Jun 2014 15:50:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-ra/m-p/2552189#M236994</guid>
      <dc:creator>Anukalp S</dc:creator>
      <dc:date>2014-06-30T15:50:32Z</dc:date>
    </item>
    <item>
      <title>Please see my previous answer</title>
      <link>https://community.cisco.com/t5/network-security/vpn-ra/m-p/2552190#M236995</link>
      <description>&lt;P&gt;Please see my previous answer and suggested resolution for your issue.&amp;nbsp; But in short it is not possible to terminate a VPN tunnel to an IP that is not configured on an ASA interface&lt;/P&gt;&lt;P&gt;--&lt;/P&gt;&lt;P&gt;Please remember to select a correct answer and rate helpful posts&lt;/P&gt;</description>
      <pubDate>Mon, 30 Jun 2014 15:52:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-ra/m-p/2552190#M236995</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2014-06-30T15:52:43Z</dc:date>
    </item>
    <item>
      <title> Thanks Marius.. but if i</title>
      <link>https://community.cisco.com/t5/network-security/vpn-ra/m-p/2552191#M236996</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks Marius.. but if i create a sub interface then i need to assign name to this interface other than outside and i have put default route vai outside interface and since ASA can not accept two default routes so people sitting on public network would they be able to reach X.X.X.11 ip.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Pls clear this out.&lt;/P&gt;</description>
      <pubDate>Mon, 30 Jun 2014 16:31:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-ra/m-p/2552191#M236996</guid>
      <dc:creator>Anukalp S</dc:creator>
      <dc:date>2014-06-30T16:31:24Z</dc:date>
    </item>
    <item>
      <title>That is true, the ASA can not</title>
      <link>https://community.cisco.com/t5/network-security/vpn-ra/m-p/2552192#M236997</link>
      <description>&lt;P&gt;That is true, the ASA can not have two active default routes.&amp;nbsp; so the interface you intend to for the VPN must also be the one that has the default route configured for it.&lt;/P&gt;&lt;P&gt;--&lt;/P&gt;&lt;P&gt;Please remember to select a correct answer and rate helpful posts&lt;/P&gt;</description>
      <pubDate>Mon, 30 Jun 2014 16:37:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-ra/m-p/2552192#M236997</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2014-06-30T16:37:49Z</dc:date>
    </item>
    <item>
      <title>Thanks Marius for clearing</title>
      <link>https://community.cisco.com/t5/network-security/vpn-ra/m-p/2552193#M236998</link>
      <description>&lt;P&gt;Thanks Marius for clearing thus out.&lt;/P&gt;</description>
      <pubDate>Mon, 30 Jun 2014 16:50:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-ra/m-p/2552193#M236998</guid>
      <dc:creator>Anukalp S</dc:creator>
      <dc:date>2014-06-30T16:50:18Z</dc:date>
    </item>
    <item>
      <title>No problem.Thank you for the</title>
      <link>https://community.cisco.com/t5/network-security/vpn-ra/m-p/2552194#M236999</link>
      <description>&lt;P&gt;No problem.&lt;/P&gt;&lt;P&gt;Thank you for the rating &lt;IMG alt="smiley" height="23" src="https://supportforums.cisco.com/profiles/commons/libraries/ckeditor/plugins/smiley/images/regular_smile.png" title="smiley" width="23" /&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 30 Jun 2014 16:53:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-ra/m-p/2552194#M236999</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2014-06-30T16:53:27Z</dc:date>
    </item>
    <item>
      <title>Hi Anukalp, Sorry didn't</title>
      <link>https://community.cisco.com/t5/network-security/vpn-ra/m-p/2552195#M237000</link>
      <description>&lt;P&gt;Hi Anukalp,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Sorry didn't understand your question before.&lt;/P&gt;&lt;P&gt;"&lt;SPAN style="color: rgb(119, 119, 119); font-size: 14px;"&gt;ip which is not configured on outside interface but with diferent ip from same segment."&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: rgb(119, 119, 119); font-size: 14px;"&gt;Yes you can for Anyconnect, as a matter of fact, I have done exactly same setup on my ASA but for IPSec no.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: rgb(119, 119, 119); font-size: 14px;"&gt;thanks&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: rgb(119, 119, 119); font-size: 14px;"&gt;Rizwan Rafeek.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 30 Jun 2014 17:17:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-ra/m-p/2552195#M237000</guid>
      <dc:creator>rizwanr74</dc:creator>
      <dc:date>2014-06-30T17:17:38Z</dc:date>
    </item>
    <item>
      <title>@Rizwan - This is</title>
      <link>https://community.cisco.com/t5/network-security/vpn-ra/m-p/2552196#M237001</link>
      <description>&lt;P&gt;@Rizwan - This is unfortunately not possible on the ASA.&amp;nbsp; Both IPsec and AnyConnect must terminate on the ASA interface so that the ASA can inspect ingress and egress traffic for interesting traffic.&lt;/P&gt;&lt;P&gt;--&lt;/P&gt;&lt;P&gt;Please remember to select a correct answer and rate helpful posts&lt;/P&gt;</description>
      <pubDate>Mon, 30 Jun 2014 17:34:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-ra/m-p/2552196#M237001</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2014-06-30T17:34:46Z</dc:date>
    </item>
  </channel>
</rss>

