<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SSL and IPSEC to get to the remote site in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ssl-and-ipsec-to-get-to-the-remote-site/m-p/1620757#M559635</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This would perfectly work to your favour, as that is the only option you have for clientless SSL vpn access towards the IPSec tunnel.&lt;/P&gt;&lt;P&gt;Clientless SSL VPN will proxy the connection using the closest interface where the traffic is supposed to be routed to, hence in your scenario:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I assume that both SSL VPN and IPSec VPN are terminated on the firewall outside interface, right? and since the clientless resources that you are planning to access is behind the remote VPN, then the clientless SSL VPN will proxy the connection from the ASA outside interface as the IPSec VPN is terminated on the ASA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 18 Mar 2011 01:53:58 GMT</pubDate>
    <dc:creator>Jennifer Halim</dc:creator>
    <dc:date>2011-03-18T01:53:58Z</dc:date>
    <item>
      <title>SSL and IPSEC to get to the remote site</title>
      <link>https://community.cisco.com/t5/network-security/ssl-and-ipsec-to-get-to-the-remote-site/m-p/1620756#M559629</link>
      <description>&lt;P&gt;We have the following situation...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We want to have the ability to SSL to the firewall (reason is we need a clientLESS solution that can be initiated from anywhere) and then be able to access a remote which is on the other side of the VPN tunnel.&amp;nbsp; The catch is here...the remote VPN site will only accept the traffic if the source address is the 'interface' address of the firewall, here's a pic:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="mailto:user@home" target="_blank"&gt;user@home&lt;/A&gt; --SSL--&amp;gt; firewall ---IPSEC VPN---&amp;gt; remote site&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;again, the remote site only allows access if the traffic is coming from the outside interface of the firewall.... so the whole point of the SSL is to security proxy the session from home via the firewall.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;any thoughts?&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 20:08:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ssl-and-ipsec-to-get-to-the-remote-site/m-p/1620756#M559629</guid>
      <dc:creator>network770</dc:creator>
      <dc:date>2019-03-11T20:08:45Z</dc:date>
    </item>
    <item>
      <title>Re: SSL and IPSEC to get to the remote site</title>
      <link>https://community.cisco.com/t5/network-security/ssl-and-ipsec-to-get-to-the-remote-site/m-p/1620757#M559635</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This would perfectly work to your favour, as that is the only option you have for clientless SSL vpn access towards the IPSec tunnel.&lt;/P&gt;&lt;P&gt;Clientless SSL VPN will proxy the connection using the closest interface where the traffic is supposed to be routed to, hence in your scenario:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I assume that both SSL VPN and IPSec VPN are terminated on the firewall outside interface, right? and since the clientless resources that you are planning to access is behind the remote VPN, then the clientless SSL VPN will proxy the connection from the ASA outside interface as the IPSec VPN is terminated on the ASA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 18 Mar 2011 01:53:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ssl-and-ipsec-to-get-to-the-remote-site/m-p/1620757#M559635</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2011-03-18T01:53:58Z</dc:date>
    </item>
  </channel>
</rss>

