<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: AnyConnect users cannot reach inside network and ASA? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/anyconnect-users-cannot-reach-inside-network-and-asa/m-p/2314169#M344578</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Karsten~ after the NAT has been moved to the above, VPN user can ping and access the inside network's computer now, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But the ASA firewall still cannot be accessed by VPN user.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For the ICMP-inspection, seems there is no big difference between turning it ON or OFF&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 16 Aug 2013 08:19:35 GMT</pubDate>
    <dc:creator>samhopealpha</dc:creator>
    <dc:date>2013-08-16T08:19:35Z</dc:date>
    <item>
      <title>AnyConnect users cannot reach inside network and ASA?</title>
      <link>https://community.cisco.com/t5/network-security/anyconnect-users-cannot-reach-inside-network-and-asa/m-p/2314165#M344570</link>
      <description>&lt;P&gt;Here is the envirnoment&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Firewall : ASA5510 9.1(2)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;ASDM : 7.1&lt;/P&gt;&lt;P&gt;Firewall IP : 192.168.88.1&lt;/P&gt;&lt;P&gt;Office Inside network : 192.168.88.x&lt;/P&gt;&lt;P&gt;AnyConnect VPN : 172.16.89.x&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Result #1: &lt;/P&gt;&lt;P&gt;Office user can &lt;/P&gt;&lt;P&gt;- access the Internet &lt;/P&gt;&lt;P&gt;- access to VPN User's computer&lt;/P&gt;&lt;P&gt;- access to ASA firewall&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Result #2:&lt;/P&gt;&lt;P&gt;VPN user can&lt;/P&gt;&lt;P&gt;- access the inside network&lt;/P&gt;&lt;P&gt;- access the Internet&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff0000;"&gt;- cannot ping/access inside network's computer&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff0000;"&gt;- cannot ping/access the ASA firewall&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Anybody could help where should I need to check?&lt;/P&gt;&lt;P&gt;Attached with the ASA configuration&lt;/P&gt;&lt;P&gt;Thanks in advance&lt;/P&gt;&lt;P&gt;Sam&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 02:26:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/anyconnect-users-cannot-reach-inside-network-and-asa/m-p/2314165#M344570</guid>
      <dc:creator>samhopealpha</dc:creator>
      <dc:date>2019-03-12T02:26:30Z</dc:date>
    </item>
    <item>
      <title>Re: AnyConnect users cannot reach inside network and ASA?</title>
      <link>https://community.cisco.com/t5/network-security/anyconnect-users-cannot-reach-inside-network-and-asa/m-p/2314166#M344572</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;there is no nat-exemption for your vpn:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;nat (inside,outside) source static INSIDE-88 INSIDE-88 destination static VPN-89 VPN-89 no-proxy-arp route-lookup description NAT-Exempt for VPN&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&amp;nbsp; &lt;BR /&gt;Don't stop after you've improved your network! Improve the world by lending money to the working poor: &lt;BR /&gt;&lt;A class="jive-link-external-small" href="http://www.kiva.org/invitedby/karsteni" rel="nofollow"&gt;http://www.kiva.org/invitedby/karsteni&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 16 Aug 2013 07:43:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/anyconnect-users-cannot-reach-inside-network-and-asa/m-p/2314166#M344572</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2013-08-16T07:43:18Z</dc:date>
    </item>
    <item>
      <title>Re: AnyConnect users cannot reach inside network and ASA?</title>
      <link>https://community.cisco.com/t5/network-security/anyconnect-users-cannot-reach-inside-network-and-asa/m-p/2314167#M344573</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;NAT added, but still the same result&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 16 Aug 2013 07:53:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/anyconnect-users-cannot-reach-inside-network-and-asa/m-p/2314167#M344573</guid>
      <dc:creator>samhopealpha</dc:creator>
      <dc:date>2013-08-16T07:53:11Z</dc:date>
    </item>
    <item>
      <title>Re: AnyConnect users cannot reach inside network and ASA?</title>
      <link>https://community.cisco.com/t5/network-security/anyconnect-users-cannot-reach-inside-network-and-asa/m-p/2314168#M344575</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;How do you test it?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For Ping you should add the ICMP-Inspection:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;policy-map global_policy&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt; class inspection_default&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;&amp;nbsp; inspect icmp &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And what is the difference between&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;Result #2:&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;VPN user can&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;- access the inside network&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff0000;"&gt;- cannot ping/access inside network's computer&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And I forgot to mention that the nat-exemption has to be inserted *above* the other nat-statements:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;nat &lt;STRONG&gt;1&lt;/STRONG&gt; (inside,outside) source ...&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&amp;nbsp; &lt;BR /&gt;Don't stop after you've improved your network! Improve the world by lending money to the working poor: &lt;BR /&gt;&lt;A class="jive-link-external-small" href="http://www.kiva.org/invitedby/karsteni" rel="nofollow"&gt;http://www.kiva.org/invitedby/karsteni&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 16 Aug 2013 07:58:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/anyconnect-users-cannot-reach-inside-network-and-asa/m-p/2314168#M344575</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2013-08-16T07:58:48Z</dc:date>
    </item>
    <item>
      <title>Re: AnyConnect users cannot reach inside network and ASA?</title>
      <link>https://community.cisco.com/t5/network-security/anyconnect-users-cannot-reach-inside-network-and-asa/m-p/2314169#M344578</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Karsten~ after the NAT has been moved to the above, VPN user can ping and access the inside network's computer now, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But the ASA firewall still cannot be accessed by VPN user.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For the ICMP-inspection, seems there is no big difference between turning it ON or OFF&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 16 Aug 2013 08:19:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/anyconnect-users-cannot-reach-inside-network-and-asa/m-p/2314169#M344578</guid>
      <dc:creator>samhopealpha</dc:creator>
      <dc:date>2013-08-16T08:19:35Z</dc:date>
    </item>
    <item>
      <title>AnyConnect users cannot reach inside network and ASA?</title>
      <link>https://community.cisco.com/t5/network-security/anyconnect-users-cannot-reach-inside-network-and-asa/m-p/2314170#M344579</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For management through the VPN you should probably use the &lt;STRONG&gt;"inside"&lt;/STRONG&gt; interface IP address by inserting the following command&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;management-access inside&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then you should be able to connect to the &lt;STRONG&gt;"inside"&lt;/STRONG&gt; IP address from VPN provided that the other configurations allow it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 16 Aug 2013 08:22:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/anyconnect-users-cannot-reach-inside-network-and-asa/m-p/2314170#M344579</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-08-16T08:22:52Z</dc:date>
    </item>
    <item>
      <title>Re: AnyConnect users cannot reach inside network and ASA?</title>
      <link>https://community.cisco.com/t5/network-security/anyconnect-users-cannot-reach-inside-network-and-asa/m-p/2314171#M344580</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks everybody!! all problems resolved !&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 16 Aug 2013 08:27:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/anyconnect-users-cannot-reach-inside-network-and-asa/m-p/2314171#M344580</guid>
      <dc:creator>samhopealpha</dc:creator>
      <dc:date>2013-08-16T08:27:39Z</dc:date>
    </item>
  </channel>
</rss>

