<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Remote access VPN in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/remote-access-vpn/m-p/2096554#M395091</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This ACL seems to define which networks are found behind the VPN connection when the user is connected wth the Client&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;access-list InExchange_VPN_splitTunnelAcl standard permit 10.42.10.0 255.255.255.0&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As you can see only one network is configured. You can add the other network simply by configuring another ACL line&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;access-list InExchange_VPN_splitTunnelAcl standard permit 10.42.1.0 255.255.255.0&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You will also need to take into account this while configuring NAT Exemption between this new LAN network and the VPN Pool that the users have.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It seems to me that the following NAT configurations are for the current VPN Client NAT Exemptions&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;nat (Inside,WAN1) source static any any destination static NETWORK_OBJ_10.42.10.224_27 NETWORK_OBJ_10.42.10.224_27 no-proxy-arp route-lookup&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As the Production network is on another firewall Interface. You need a similiar rule for that interface using the Production LAN and the VPN Pool used. By the way, which one is the pool you use? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is it this one?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;ip local pool Vpn_pool 10.42.10.231-10.42.10.245 mask 255.255.255.0&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 27 Nov 2012 10:34:00 GMT</pubDate>
    <dc:creator>Jouni Forss</dc:creator>
    <dc:date>2012-11-27T10:34:00Z</dc:date>
    <item>
      <title>Remote access VPN</title>
      <link>https://community.cisco.com/t5/network-security/remote-access-vpn/m-p/2096551#M395076</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a remote access VPN to our office network 10.42.10.0. however I have some web services that are located in a production network 10.42.1.0 that users in the office network need to access.&lt;/P&gt;&lt;P&gt;This is obviously no problem when using remote desktop to an office PC but when users with laptops remote in and try to access the website on the production network it does not work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there any way for the tunnel also to also allow traffic to the production network&amp;nbsp; for the remote hosts?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;/Hilmar&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 00:28:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/remote-access-vpn/m-p/2096551#M395076</guid>
      <dc:creator>IT Asitis</dc:creator>
      <dc:date>2019-03-12T00:28:33Z</dc:date>
    </item>
    <item>
      <title>Remote access VPN</title>
      <link>https://community.cisco.com/t5/network-security/remote-access-vpn/m-p/2096552#M395081</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This should be no problem at all.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But it all depends on your current firewall/VPN configurations.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you could post atleast part of your configuration or a complete configuration with any sensitive information removed (public IP addresses etc) we could go through it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you have a Full tunnel VPN Client configuration the problem is probably related to NAT and ACL configurations. If you are using Split Tunnel VPN you might need to add some network/host addresses to the Split tunnel ACL.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But as I said, would be easier if we could look at the configurations&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 27 Nov 2012 10:01:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/remote-access-vpn/m-p/2096552#M395081</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2012-11-27T10:01:11Z</dc:date>
    </item>
    <item>
      <title>Remote access VPN</title>
      <link>https://community.cisco.com/t5/network-security/remote-access-vpn/m-p/2096553#M395087</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have added the running config with afew IP modifications&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;/H&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 27 Nov 2012 10:21:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/remote-access-vpn/m-p/2096553#M395087</guid>
      <dc:creator>IT Asitis</dc:creator>
      <dc:date>2012-11-27T10:21:35Z</dc:date>
    </item>
    <item>
      <title>Remote access VPN</title>
      <link>https://community.cisco.com/t5/network-security/remote-access-vpn/m-p/2096554#M395091</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This ACL seems to define which networks are found behind the VPN connection when the user is connected wth the Client&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;access-list InExchange_VPN_splitTunnelAcl standard permit 10.42.10.0 255.255.255.0&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As you can see only one network is configured. You can add the other network simply by configuring another ACL line&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;access-list InExchange_VPN_splitTunnelAcl standard permit 10.42.1.0 255.255.255.0&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You will also need to take into account this while configuring NAT Exemption between this new LAN network and the VPN Pool that the users have.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It seems to me that the following NAT configurations are for the current VPN Client NAT Exemptions&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;nat (Inside,WAN1) source static any any destination static NETWORK_OBJ_10.42.10.224_27 NETWORK_OBJ_10.42.10.224_27 no-proxy-arp route-lookup&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As the Production network is on another firewall Interface. You need a similiar rule for that interface using the Production LAN and the VPN Pool used. By the way, which one is the pool you use? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is it this one?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;ip local pool Vpn_pool 10.42.10.231-10.42.10.245 mask 255.255.255.0&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 27 Nov 2012 10:34:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/remote-access-vpn/m-p/2096554#M395091</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2012-11-27T10:34:00Z</dc:date>
    </item>
    <item>
      <title>Remote access VPN</title>
      <link>https://community.cisco.com/t5/network-security/remote-access-vpn/m-p/2096555#M395093</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Yes that is the vpn pool im using.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So add the access list and then another nat rule?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;/H&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 27 Nov 2012 10:38:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/remote-access-vpn/m-p/2096555#M395093</guid>
      <dc:creator>IT Asitis</dc:creator>
      <dc:date>2012-11-27T10:38:25Z</dc:date>
    </item>
    <item>
      <title>Remote access VPN</title>
      <link>https://community.cisco.com/t5/network-security/remote-access-vpn/m-p/2096556#M395095</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Basically you just need another line to the existing ACL &lt;STRONG&gt;InExchange_VPN_splitTunnelAcl &lt;/STRONG&gt;(the line in the last post)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I guess the NAT configuration should be something like this (using made up names for objects, dont have to be these)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;object network PRODUCTION-LAN&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; subnet 10.42.1.0 255.255.255.0&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;object network VPN-POOL&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; subnet 10.42.10.0 255.255.255.224&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;nat (Production,WAN1) source static PRODUCTION-LAN PRODUCTION-LAN destination static VPN-POOL VPN-POOL&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To me it seems you mostly use ASDM for configuration as there is a huge amount of objects and object-groups and they have very mixed naming scheme. It makes for a pretty agonizing expirience to read though in CLI format &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 27 Nov 2012 11:13:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/remote-access-vpn/m-p/2096556#M395095</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2012-11-27T11:13:16Z</dc:date>
    </item>
    <item>
      <title>Remote access VPN</title>
      <link>https://community.cisco.com/t5/network-security/remote-access-vpn/m-p/2096557#M395097</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;True the naming scheme could be better &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" height="16" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif" width="16"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have applied the configuration as you posted and i will try to test this tonight(cant test during office hours) and see if everything works.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ill get back tonight/tomorrow with the results.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your help so far.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;/Hilmar&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 27 Nov 2012 12:19:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/remote-access-vpn/m-p/2096557#M395097</guid>
      <dc:creator>IT Asitis</dc:creator>
      <dc:date>2012-11-27T12:19:32Z</dc:date>
    </item>
    <item>
      <title>Remote access VPN</title>
      <link>https://community.cisco.com/t5/network-security/remote-access-vpn/m-p/2096558#M395099</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; It works &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" height="16" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif" width="16"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;At first it didnt but then i changed the subnet mask for the following object to 255.255.255.0:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;object network VPN-POOL&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;subnet 10.42.10.0 255.255.255.224&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;After that i tested a website on a production server and also remote desktop from a laptop via VPN and it works.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks alot for your help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;/Hilmar&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; &lt;/STRONG&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 27 Nov 2012 20:56:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/remote-access-vpn/m-p/2096558#M395099</guid>
      <dc:creator>IT Asitis</dc:creator>
      <dc:date>2012-11-27T20:56:14Z</dc:date>
    </item>
    <item>
      <title>Remote access VPN</title>
      <link>https://community.cisco.com/t5/network-security/remote-access-vpn/m-p/2096559#M395100</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ah,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Typo there. Network address should have been 10.42.10.&lt;STRONG&gt;224&lt;/STRONG&gt; and mask 255.255.255.224. But I guess no reason to change anything since its working.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Glad to be of help &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 27 Nov 2012 21:49:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/remote-access-vpn/m-p/2096559#M395100</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2012-11-27T21:49:16Z</dc:date>
    </item>
  </channel>
</rss>

