<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Help In Configuring ASA in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/help-in-configuring-asa/m-p/2160789#M361098</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Sir,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you for the information I have check the command &amp;amp; followed a guide on the link below.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;DIV&gt;(MAIN SITE)&lt;P&gt;&lt;/P&gt;&lt;P&gt;Step 1: Add the Subnet of the Remote Site to the "Split Tunnel" for the remote VPN -done&lt;/P&gt;&lt;P&gt;Step 2: Turn On Hair Pinning -done&lt;/P&gt;&lt;P&gt;Step 3: Add the "Remote VPN Network" to the EXISTING site to site VPN on the Main Site. -done&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;(REMOTE SITE)&lt;/P&gt;&lt;P&gt;Step 4: Add a NAT Exemption on the Remote Site ASA&lt;/P&gt;&lt;P&gt;Step 5: Add the Remote VPN Pool to the EXISTING Site to Site VPN Access List&lt;/P&gt;&lt;/DIV&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="color: #222222; font-family: arial, sans-serif; background-color: #ffffff;"&gt;Details is on this link: &lt;A href="http://www.petenetlive.com/KB/Article/0000040.htm" style="color: #1155cc;" target="_blank"&gt;&lt;SPAN style="color: blue; font-size: 12pt; font-family: sans-serif; text-decoration: underline; "&gt;http://www.petenetlive.com/KB/Article/0000040.htm&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How can I check If my counter part already did step 4 &amp;amp; 5. Can it be seen on cisco asa packet trace. please see result.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/3/1/3/131313-Capture1.JPG" class="jive-image" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Again thank you sir for your support.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 06 Mar 2013 08:38:14 GMT</pubDate>
    <dc:creator>Ron Timbang</dc:creator>
    <dc:date>2013-03-06T08:38:14Z</dc:date>
    <item>
      <title>Help In Configuring ASA</title>
      <link>https://community.cisco.com/t5/network-security/help-in-configuring-asa/m-p/2160783#M361092</link>
      <description>&lt;P&gt;Hi Guys,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Good day!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Need your kind assistance in configuring ASA . Currently users can connect using VPN client. Users can access our local servers. The problem is vpn user cannot connect to servers that are located on our other site connected via site-to-site VPN. Do I need to configure static routes so the ASA knows how to route remote vpn users to our other site.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you in advance . I have attaced a diagram for reference.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 01:07:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/help-in-configuring-asa/m-p/2160783#M361092</guid>
      <dc:creator>Ron Timbang</dc:creator>
      <dc:date>2019-03-12T01:07:58Z</dc:date>
    </item>
    <item>
      <title>Help In Configuring ASA</title>
      <link>https://community.cisco.com/t5/network-security/help-in-configuring-asa/m-p/2160784#M361093</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ron&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There is not enough information here for us to be sure. But my first guess at your problem is that by default an ASA will not forward traffic back out the interface on which it arrived. So if your vpn user traffic comes in the interface named outside, then it will not forward that traffic back out interface outside. But that is probably where your site to site traffic goes. The way to solve this is to use the command that allows traffic same-security intra interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rick&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 01 Mar 2013 03:14:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/help-in-configuring-asa/m-p/2160784#M361093</guid>
      <dc:creator>Richard Burts</dc:creator>
      <dc:date>2013-03-01T03:14:41Z</dc:date>
    </item>
    <item>
      <title>Re: Help In Configuring ASA</title>
      <link>https://community.cisco.com/t5/network-security/help-in-configuring-asa/m-p/2160785#M361094</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Sir Richard,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you for the information. I got your point thanks alot! Please let me know the details on how to configure this. I am researching for a week now &amp;amp; I was able to read topic on "vpn hair pinning". Is this the same concept?&amp;nbsp; But the topic is very hard for me since I only have basic knowledge on Cisco ASA.&lt;/P&gt;&lt;P&gt;Is there a way to do this on ASDM?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you very much Sir..&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 01 Mar 2013 03:30:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/help-in-configuring-asa/m-p/2160785#M361094</guid>
      <dc:creator>Ron Timbang</dc:creator>
      <dc:date>2013-03-01T03:30:19Z</dc:date>
    </item>
    <item>
      <title>Help In Configuring ASA</title>
      <link>https://community.cisco.com/t5/network-security/help-in-configuring-asa/m-p/2160786#M361095</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi Ron,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I agree with Richard, just wanted to add that you should also ensure the client's IP subnet is permitted through the site to site tunnel.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 01 Mar 2013 03:41:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/help-in-configuring-asa/m-p/2160786#M361095</guid>
      <dc:creator>smetieh001</dc:creator>
      <dc:date>2013-03-01T03:41:53Z</dc:date>
    </item>
    <item>
      <title>Re: Help In Configuring ASA</title>
      <link>https://community.cisco.com/t5/network-security/help-in-configuring-asa/m-p/2160787#M361096</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Sir,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you for the information I already coordinated to the other site to allow client's IP subnet. Do you have an idea on what specific commands I need to configure ? Thank you..&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 01 Mar 2013 04:37:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/help-in-configuring-asa/m-p/2160787#M361096</guid>
      <dc:creator>Ron Timbang</dc:creator>
      <dc:date>2013-03-01T04:37:05Z</dc:date>
    </item>
    <item>
      <title>Help In Configuring ASA</title>
      <link>https://community.cisco.com/t5/network-security/help-in-configuring-asa/m-p/2160788#M361097</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ron&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The command that you need is &lt;/P&gt;&lt;PRE&gt;&lt;STRONG&gt;same-security-traffic permit intra-interface&lt;/STRONG&gt;&lt;/PRE&gt;&lt;P&gt;you might also want to use&lt;/P&gt;&lt;PRE&gt;&lt;STRONG&gt;same-security-traffic permit inter-interface&lt;/STRONG&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For more information you might try this link&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/asa/asa72/configuration/guide/intparam.html#wp1039276"&gt;http://www.cisco.com/en/US/docs/security/asa/asa72/configuration/guide/intparam.html#wp1039276&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rick&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 01 Mar 2013 18:17:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/help-in-configuring-asa/m-p/2160788#M361097</guid>
      <dc:creator>Richard Burts</dc:creator>
      <dc:date>2013-03-01T18:17:11Z</dc:date>
    </item>
    <item>
      <title>Re: Help In Configuring ASA</title>
      <link>https://community.cisco.com/t5/network-security/help-in-configuring-asa/m-p/2160789#M361098</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Sir,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you for the information I have check the command &amp;amp; followed a guide on the link below.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;DIV&gt;(MAIN SITE)&lt;P&gt;&lt;/P&gt;&lt;P&gt;Step 1: Add the Subnet of the Remote Site to the "Split Tunnel" for the remote VPN -done&lt;/P&gt;&lt;P&gt;Step 2: Turn On Hair Pinning -done&lt;/P&gt;&lt;P&gt;Step 3: Add the "Remote VPN Network" to the EXISTING site to site VPN on the Main Site. -done&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;(REMOTE SITE)&lt;/P&gt;&lt;P&gt;Step 4: Add a NAT Exemption on the Remote Site ASA&lt;/P&gt;&lt;P&gt;Step 5: Add the Remote VPN Pool to the EXISTING Site to Site VPN Access List&lt;/P&gt;&lt;/DIV&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="color: #222222; font-family: arial, sans-serif; background-color: #ffffff;"&gt;Details is on this link: &lt;A href="http://www.petenetlive.com/KB/Article/0000040.htm" style="color: #1155cc;" target="_blank"&gt;&lt;SPAN style="color: blue; font-size: 12pt; font-family: sans-serif; text-decoration: underline; "&gt;http://www.petenetlive.com/KB/Article/0000040.htm&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How can I check If my counter part already did step 4 &amp;amp; 5. Can it be seen on cisco asa packet trace. please see result.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/3/1/3/131313-Capture1.JPG" class="jive-image" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Again thank you sir for your support.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Mar 2013 08:38:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/help-in-configuring-asa/m-p/2160789#M361098</guid>
      <dc:creator>Ron Timbang</dc:creator>
      <dc:date>2013-03-06T08:38:14Z</dc:date>
    </item>
    <item>
      <title>Re: Help In Configuring ASA</title>
      <link>https://community.cisco.com/t5/network-security/help-in-configuring-asa/m-p/2160790#M361099</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi ,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Today I can now telnet to the site on port 80. &amp;amp; packet trace is successful.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But still cannot access the site.&lt;SPAN __jive_emoticon_name="plain" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/tiny_mce3/plugins/jiveemoticons/images/spacer.gif"&gt;&lt;/SPAN&gt;. Ping also fails. Does it mean that the problem is with the remote site?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you..&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Mar 2013 04:36:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/help-in-configuring-asa/m-p/2160790#M361099</guid>
      <dc:creator>Ron Timbang</dc:creator>
      <dc:date>2013-03-08T04:36:53Z</dc:date>
    </item>
    <item>
      <title>Re: Help In Configuring ASA</title>
      <link>https://community.cisco.com/t5/network-security/help-in-configuring-asa/m-p/2160791#M361100</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="background-color: #f7fafb; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;Hi Sir Burts ,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #f7fafb; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;Today I can now telnet to the site on port 80. &amp;amp; packet trace is successful from ASA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #f7fafb; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;But still cannot access the site.&lt;SPAN __jive_emoticon_name="plain"&gt;&lt;/SPAN&gt;. Ping also fails. Does it mean that the problem is with the remote site?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #f7fafb; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;Thank you..&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Mar 2013 07:10:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/help-in-configuring-asa/m-p/2160791#M361100</guid>
      <dc:creator>Ron Timbang</dc:creator>
      <dc:date>2013-03-08T07:10:42Z</dc:date>
    </item>
    <item>
      <title>Re: Help In Configuring ASA</title>
      <link>https://community.cisco.com/t5/network-security/help-in-configuring-asa/m-p/2160792#M361101</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ron&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am not clear whether you are saying that these are issues when you are in a VPN session or are these problems in general. Clarification would be appreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rick&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Mar 2013 23:00:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/help-in-configuring-asa/m-p/2160792#M361101</guid>
      <dc:creator>Richard Burts</dc:creator>
      <dc:date>2013-03-08T23:00:43Z</dc:date>
    </item>
    <item>
      <title>Re: Help In Configuring ASA</title>
      <link>https://community.cisco.com/t5/network-security/help-in-configuring-asa/m-p/2160793#M361102</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Sir Burts / Guys,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am now able to access the site. Thank you very much for the help. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Problem is not now that I can access it using vpn-client but cannot access on ssl-web vpn. Any ideas?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think i need to create another dicussion for this topic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 Mar 2013 10:02:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/help-in-configuring-asa/m-p/2160793#M361102</guid>
      <dc:creator>Ron Timbang</dc:creator>
      <dc:date>2013-03-11T10:02:15Z</dc:date>
    </item>
    <item>
      <title>Re: Help In Configuring ASA</title>
      <link>https://community.cisco.com/t5/network-security/help-in-configuring-asa/m-p/2160794#M361103</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ron&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My first guess would be to ask if the address used as the source address for access when using ssl-web is different from the address assigned to clients for access. Assuming that they are different I would then guess that the access rules that allow client access do not permit access for the address used by ssl-web.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Perhaps a new discussion for this question would be appropriate.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rick&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 Mar 2013 12:24:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/help-in-configuring-asa/m-p/2160794#M361103</guid>
      <dc:creator>Richard Burts</dc:creator>
      <dc:date>2013-03-11T12:24:25Z</dc:date>
    </item>
    <item>
      <title>Re: Help In Configuring ASA</title>
      <link>https://community.cisco.com/t5/network-security/help-in-configuring-asa/m-p/2160795#M361104</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Sir Burts,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I already check ip address &amp;amp; pool is same woth vpn client. Please let me know if you have ideas on how to troubleshoot this issue. Again thank you. &lt;/P&gt;&lt;P&gt;Please see link for the new discussion.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" href="https://community.cisco.com/message/3879617#3879617"&gt;https://supportforums.cisco.com/message/3879617#3879617&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 12 Mar 2013 03:14:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/help-in-configuring-asa/m-p/2160795#M361104</guid>
      <dc:creator>Ron Timbang</dc:creator>
      <dc:date>2013-03-12T03:14:53Z</dc:date>
    </item>
  </channel>
</rss>

