<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA5505: WebVPN not working after adding second vlan in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa5505-webvpn-not-working-after-adding-second-vlan/m-p/2347102#M310291</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Patrick,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your response, I figured as much.. Ended up resetting it to factory defaults and rebuilding the configuration from there. Couldn't for the life of me get that entry out. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As for the intention, not a clue, I wonder how it came in as well..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anyway, it's back working again now, so thanks a lot!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;John&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sat, 26 Oct 2013 18:00:24 GMT</pubDate>
    <dc:creator>JohnSimons</dc:creator>
    <dc:date>2013-10-26T18:00:24Z</dc:date>
    <item>
      <title>ASA5505: WebVPN not working after adding second vlan</title>
      <link>https://community.cisco.com/t5/network-security/asa5505-webvpn-not-working-after-adding-second-vlan/m-p/2347099#M310285</link>
      <description>&lt;P&gt;Hey Guys,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have added a second vlan on our ASA5505 for the wireless network (yes, I know it's not a router) and now webvpn has stopped working. Basically what happens is the ASA tries to unnat the request (which I think it shouldn't) and because of a static entry I seem to be unable to remove it resolves to the wrong network.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/legacy/6/6/1/163166-unnatting%20cisco%20asa.png" alt="unnatting cisco asa.png" class="jive-image-thumbnail jive-image" onclick="" width="450" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The rule is&lt;/P&gt;&lt;P&gt;static (wireless,outside) interface gw_wireless netmask 255.255.255.255 dns &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The acl entry for the webvpn port is:&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp any host outside_ip object-group custom_webvpn log debugging&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;webvpn&lt;/P&gt;&lt;P&gt; port 444&lt;/P&gt;&lt;P&gt; enable outside&lt;/P&gt;&lt;P&gt; dtls port 444&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope you can help me with my problem, if I need to give any more details please let me know...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;John&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 02:56:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5505-webvpn-not-working-after-adding-second-vlan/m-p/2347099#M310285</guid>
      <dc:creator>JohnSimons</dc:creator>
      <dc:date>2019-03-12T02:56:13Z</dc:date>
    </item>
    <item>
      <title>ASA5505: WebVPN not working after adding second vlan</title>
      <link>https://community.cisco.com/t5/network-security/asa5505-webvpn-not-working-after-adding-second-vlan/m-p/2347100#M310287</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi John,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You need to remove that static NAT entry.&lt;/P&gt;&lt;P&gt;What it does is statically nat everything coming to the outside interface to 0.0.0.0 on the wireless interface and that doesn't make sense.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ciscoasa(config)# static (inside,outside) interface 0.0.0.0 netmask &lt;SPAN style="font-size: 10pt;"&gt;255.255.255.255 dns&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;WARNING: static redireting all traffics at outside interface;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;WARNING: all services terminating at outside interface are disabled.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What was intended with that static statement?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Patrick&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 25 Oct 2013 19:50:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5505-webvpn-not-working-after-adding-second-vlan/m-p/2347100#M310287</guid>
      <dc:creator>Patrick Moubarak</dc:creator>
      <dc:date>2013-10-25T19:50:24Z</dc:date>
    </item>
    <item>
      <title>ASA5505: WebVPN not working after adding second vlan</title>
      <link>https://community.cisco.com/t5/network-security/asa5505-webvpn-not-working-after-adding-second-vlan/m-p/2347101#M310289</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello John,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Agree with Patrick (kudos to u) .&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What you need instead of performing a one to one translation for the wireless router is to do a port-forwarding, I guess you are looking to manage the device remotely so do the following&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,outside) tcp interface 443 &lt;SPAN style="font-size: 10pt;"&gt;gw_wireless 443&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;access-list out_in permit tcp any host interface_ip_address eq 443&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rate all of the helpful posts!!! &lt;BR /&gt; &lt;BR /&gt;Regards, &lt;BR /&gt; &lt;BR /&gt;Jcarvaja &lt;BR /&gt; &lt;BR /&gt;&lt;SPAN&gt;Follow me on &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://laguiadelnetworking.com"&gt;http://laguiadelnetworking.com&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 25 Oct 2013 23:17:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5505-webvpn-not-working-after-adding-second-vlan/m-p/2347101#M310289</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2013-10-25T23:17:23Z</dc:date>
    </item>
    <item>
      <title>ASA5505: WebVPN not working after adding second vlan</title>
      <link>https://community.cisco.com/t5/network-security/asa5505-webvpn-not-working-after-adding-second-vlan/m-p/2347102#M310291</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Patrick,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your response, I figured as much.. Ended up resetting it to factory defaults and rebuilding the configuration from there. Couldn't for the life of me get that entry out. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As for the intention, not a clue, I wonder how it came in as well..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anyway, it's back working again now, so thanks a lot!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;John&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 26 Oct 2013 18:00:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5505-webvpn-not-working-after-adding-second-vlan/m-p/2347102#M310291</guid>
      <dc:creator>JohnSimons</dc:creator>
      <dc:date>2013-10-26T18:00:24Z</dc:date>
    </item>
  </channel>
</rss>

