<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hairpinning for Webvpn in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/hairpinning-for-webvpn/m-p/1825277#M460431</link>
    <description>&lt;P&gt; Hi!&amp;nbsp; Its my first time to post here not sure how it works.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Im having problems configuring Hairpinning thru WebVPN but it works with IPSEC.&amp;nbsp; For testing I tried to used same address-pool and split tunnel policy and already enabled same-security and nat bypass for internal traffic.&amp;nbsp; Everything works fine IPSEC except for WebVPN and for the WebVPN users they can access resources behind the firewall but not thru haripinning (outside interface).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 22:20:54 GMT</pubDate>
    <dc:creator>jasontatom</dc:creator>
    <dc:date>2019-03-11T22:20:54Z</dc:date>
    <item>
      <title>Hairpinning for Webvpn</title>
      <link>https://community.cisco.com/t5/network-security/hairpinning-for-webvpn/m-p/1825277#M460431</link>
      <description>&lt;P&gt; Hi!&amp;nbsp; Its my first time to post here not sure how it works.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Im having problems configuring Hairpinning thru WebVPN but it works with IPSEC.&amp;nbsp; For testing I tried to used same address-pool and split tunnel policy and already enabled same-security and nat bypass for internal traffic.&amp;nbsp; Everything works fine IPSEC except for WebVPN and for the WebVPN users they can access resources behind the firewall but not thru haripinning (outside interface).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 22:20:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/hairpinning-for-webvpn/m-p/1825277#M460431</guid>
      <dc:creator>jasontatom</dc:creator>
      <dc:date>2019-03-11T22:20:54Z</dc:date>
    </item>
    <item>
      <title>Hairpinning for Webvpn</title>
      <link>https://community.cisco.com/t5/network-security/hairpinning-for-webvpn/m-p/1825278#M460433</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Jason&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Its been a while sicen I have done this, but here is a config that I used a while back for this (asa 8.0.2). The rest of the config as per standard&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface Ethernet0/0&lt;/P&gt;&lt;P&gt; nameif outside&lt;/P&gt;&lt;P&gt; security-level 0&lt;/P&gt;&lt;P&gt; ip address 20.1.1.1 255.255.255.0 &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;same-security-traffic permit intra-interface&lt;/P&gt;&lt;P&gt;ip local pool vpn_user_pool 20.1.1.200-20.1.1.220 mask 255.255.255.0&lt;/P&gt;&lt;P&gt;webvpn&lt;/P&gt;&lt;P&gt; enable outside&lt;/P&gt;&lt;P&gt; svc image disk0:/sslclient-win-1.1.4.176.pkg 1&lt;/P&gt;&lt;P&gt; svc enable&lt;/P&gt;&lt;P&gt;group-policy msw-grp internal&lt;/P&gt;&lt;P&gt;group-policy msw-grp attributes&lt;/P&gt;&lt;P&gt; vpn-tunnel-protocol svc &lt;/P&gt;&lt;P&gt; webvpn&lt;/P&gt;&lt;P&gt;&amp;nbsp; svc ask none default svc&lt;/P&gt;&lt;P&gt;username mwinnett password vukFd0JFOKL2l7IE encrypted privilege 15&lt;/P&gt;&lt;P&gt;tunnel-group DefaultWEBVPNGroup general-attributes&lt;/P&gt;&lt;P&gt; address-pool vpn_users&lt;/P&gt;&lt;P&gt; address-pool vpn_user_pool&lt;/P&gt;&lt;P&gt; default-group-policy msw-grp&lt;/P&gt;&lt;P&gt;prompt hostname context &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ciscoasa(config)# sh vpn-sessiondb svc&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Session Type: SVC&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Username&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : mwinnett&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Index&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 6&lt;/P&gt;&lt;P&gt;Assigned IP&amp;nbsp; : 20.1.1.200&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Public IP&amp;nbsp;&amp;nbsp;&amp;nbsp; : 10.48.67.22&lt;/P&gt;&lt;P&gt;Protocol&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : Clientless SSL-Tunnel&lt;/P&gt;&lt;P&gt;Encryption&amp;nbsp;&amp;nbsp; : RC4&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Hashing&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : SHA1&lt;/P&gt;&lt;P&gt;Bytes Tx&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 45779&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Bytes Rx&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 19750&lt;/P&gt;&lt;P&gt;Group Policy : msw-grp&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Tunnel Group : DefaultWEBVPNGroup&lt;/P&gt;&lt;P&gt;Login Time&amp;nbsp;&amp;nbsp; : 17:14:35 UTC Thu Sep 13 2007&lt;/P&gt;&lt;P&gt;Duration&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 0h:01m:02s&lt;/P&gt;&lt;P&gt;NAC Result&amp;nbsp;&amp;nbsp; : Unknown&lt;/P&gt;&lt;P&gt;VLAN Mapping : N/A&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; VLAN&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : none&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 13 Feb 2012 16:04:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/hairpinning-for-webvpn/m-p/1825278#M460433</guid>
      <dc:creator>mwinnett</dc:creator>
      <dc:date>2012-02-13T16:04:19Z</dc:date>
    </item>
  </channel>
</rss>

