<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA Remote VPN in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-remote-vpn/m-p/1534538#M607397</link>
    <description>&lt;P&gt;Hello Dears,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I m able to get IP address and domain name from ASA firewall group policy configs through Windows VPN Client&amp;nbsp; after connecting i m not able to do anything in my corporate network when i do remote desktop to my server i m not able to connect ,neither ping,nor telnet to any access switch,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff0000;"&gt;When i get IP Address from the pool i also get the Default gateway i dont know from where it is coming i have not specified any default gateway. &lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think i m missing something in configuration ???? Can anybody help me with this.&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 19:06:02 GMT</pubDate>
    <dc:creator>estelamathew</dc:creator>
    <dc:date>2019-03-11T19:06:02Z</dc:date>
    <item>
      <title>ASA Remote VPN</title>
      <link>https://community.cisco.com/t5/network-security/asa-remote-vpn/m-p/1534538#M607397</link>
      <description>&lt;P&gt;Hello Dears,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I m able to get IP address and domain name from ASA firewall group policy configs through Windows VPN Client&amp;nbsp; after connecting i m not able to do anything in my corporate network when i do remote desktop to my server i m not able to connect ,neither ping,nor telnet to any access switch,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff0000;"&gt;When i get IP Address from the pool i also get the Default gateway i dont know from where it is coming i have not specified any default gateway. &lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think i m missing something in configuration ???? Can anybody help me with this.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 19:06:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-remote-vpn/m-p/1534538#M607397</guid>
      <dc:creator>estelamathew</dc:creator>
      <dc:date>2019-03-11T19:06:02Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Remote VPN</title>
      <link>https://community.cisco.com/t5/network-security/asa-remote-vpn/m-p/1534539#M607398</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Most likely you're not using split-tunneling and that's why everything is being sent through the tunnel.&lt;/P&gt;&lt;P&gt;If you cannot reach anything on the server side, there could be some reasons:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. Check that NAT-T is enabled on both sides (on the ASA crypto isakmp nat-t and on the client side under the transport tab).&lt;/P&gt;&lt;P&gt;2. Check that there's no Firewall or device blocking ESP on either side.&lt;/P&gt;&lt;P&gt;3. As a test include the command ''management-access inside'' and make sure that you can PING the inside IP of the ASA from the VPN client.&lt;/P&gt;&lt;P&gt;4. When connected issue the command ''sh cry ips sa'' and check if packets are being encrypted/decrypted when sending traffic.&lt;/P&gt;&lt;P&gt;5. A normal problem is that the ASA's inside LAN don't have a route back to the VPN pool range, check this as well.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let us know how it goes.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Federico.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 07 Nov 2010 19:34:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-remote-vpn/m-p/1534539#M607398</guid>
      <dc:creator>Federico Coto Fajardo</dc:creator>
      <dc:date>2010-11-07T19:34:58Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Remote VPN</title>
      <link>https://community.cisco.com/t5/network-security/asa-remote-vpn/m-p/1534540#M607399</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;1. Check that NAT-T is enabled on both sides (on the ASA crypto&amp;nbsp; isakmp nat-t and on the client side under the transport tab).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;it is enabled on both the firewall and in the client.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2.&amp;nbsp; Check that there's no Firewall or device blocking ESP on either side&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i have openend every thing from outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3.&amp;nbsp; As a test include the command ''management-access inside'' and make&amp;nbsp; sure that you can PING the inside IP of the ASA from the VPN client.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;after putting this command it started pinging but it is not pinging the core switch the next hop of firewall on inside interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;4.&amp;nbsp; When connected issue the command ''sh cry ips sa'' and check if packets&amp;nbsp; are being encrypted/decrypted when sending traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASA(config)# sh crypto ipsec sa&lt;BR /&gt;interface: outside&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Crypto map tag: SYSTEM_DEFAULT_CRYPTO_MAP, seq num: 65535, local addr: 254.254.254.254&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; local ident (addr/mask/prot/port): (0.0.0.0/0.0.0.0/0/0)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; remote ident (addr/mask/prot/port): (10.X.122.50/255.255.255.255/0/0)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; current_peer: 18.135.2.X, username: XXX&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; dynamic allocated peer ip: 10.X.122.50&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; #pkts encaps: 9, #pkts encrypt: 9, #pkts digest: 9&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; #pkts decaps: 533, #pkts decrypt: 533, #pkts verify: 533&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; #pkts compressed: 0, #pkts decompressed: 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; #pkts not compressed: 9, #pkts comp failed: 0, #pkts decomp failed: 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; #pre-frag successes: 0, #pre-frag failures: 0, #fragments created: 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; #PMTUs sent: 0, #PMTUs rcvd: 0, #decapsulated frgs needing reassembly: 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; #send errors: 0, #recv errors: 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; local crypto endpt.: 202.109.253.253/4500, remote crypto endpt.: 188.135.2.215/6405&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; path mtu 1500, ipsec overhead 82, media mtu 1500&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; current outbound spi: D32067D8&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; current inbound spi : B66D5F1D&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; inbound esp sas:&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; spi: 0xB66D5F1D (3060621085)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; transform: esp-aes esp-sha-hmac no compression&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; in use settings ={RA, Tunnel,&amp;nbsp; NAT-T-Encaps, }&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; slot: 0, conn_id: 98304, crypto-map: SYSTEM_DEFAULT_CRYPTO_MAP&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; sa timing: remaining key lifetime (sec): 28262&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; IV size: 16 bytes&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; replay detection support: Y&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Anti replay bitmap:&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0xFFFFFFFF 0xFFFFFFFF&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; outbound esp sas:&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; spi: 0xD32067D8 (3542116312)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; transform: esp-aes esp-sha-hmac no compression&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; in use settings ={RA, Tunnel,&amp;nbsp; NAT-T-Encaps, }&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; slot: 0, conn_id: 98304, crypto-map: SYSTEM_DEFAULT_CRYPTO_MAP&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; sa timing: remaining key lifetime (sec): 28253&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; IV size: 16 bytes&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; replay detection support: Y&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Anti replay bitmap:&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0x00000000 0x00000001&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;5. A normal&amp;nbsp; problem is that the ASA's inside LAN don't have a route back to the VPN&amp;nbsp; pool range, check this as well.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can see the host route for the vpn client by sh route output on ASA, On core switch the default route is pointing to ASA still i m not able to ping the core.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 07 Nov 2010 20:22:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-remote-vpn/m-p/1534540#M607399</guid>
      <dc:creator>estelamathew</dc:creator>
      <dc:date>2010-11-07T20:22:43Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Remote VPN</title>
      <link>https://community.cisco.com/t5/network-security/asa-remote-vpn/m-p/1534541#M607400</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you can PING the ASA's inside IP but not the internal LAN (and you have the routing correct), maybe you have overlapping issue.&lt;/P&gt;&lt;P&gt;Is the VPN pool range part of the internal network IP addressing scheme?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Federico.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 08 Nov 2010 00:38:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-remote-vpn/m-p/1534541#M607400</guid>
      <dc:creator>Federico Coto Fajardo</dc:creator>
      <dc:date>2010-11-08T00:38:56Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Remote VPN</title>
      <link>https://community.cisco.com/t5/network-security/asa-remote-vpn/m-p/1534542#M607401</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you have NAT exemption configurecd on the ASA for traffic destined from the internal LAN to the pool of IPs.? Please post a sanitized config here if possible.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Prapanch&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 08 Nov 2010 02:00:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-remote-vpn/m-p/1534542#M607401</guid>
      <dc:creator>praprama</dc:creator>
      <dc:date>2010-11-08T02:00:07Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Remote VPN</title>
      <link>https://community.cisco.com/t5/network-security/asa-remote-vpn/m-p/1534543#M607402</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Dear's,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;here are the related configuration for the remote VPN:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt; i have enable ip any any from outside interface and aslo&lt;/LI&gt;&lt;LI&gt; i enable sysopt command to permit anything from vpn client,&lt;/LI&gt;&lt;LI&gt;i have specified route inside tunneled&lt;/LI&gt;&lt;LI&gt;My corporate pool is 10.75.0.0 255.255.0.0 from that i m using the below pool for vpn.ip local pool pool 10.75.166.1-10.75.166.10 mask 255.255.255.0&lt;/LI&gt;&lt;LI&gt;when i change the pool i m not able to ping&amp;nbsp; the inside interface of firewall from firewall i m able to ping the client but from client i m not able to ping the inside interface.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;after doing the above stilli can t access the internal network,Any clues dears,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip local pool pool 10.75.166.1-10.75.166.10 mask 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list inside_nat0_outbound extended permit ip any 10.75.166 0 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (inside) 0 access-list inside_nat0_outbound.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For spli tunneling&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list split_tunnel standard permit any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;group-policy XX internal&lt;BR /&gt;group-policy XX attributes&lt;BR /&gt; dns-server value X&amp;gt;X&amp;gt;X&amp;gt;X&lt;BR /&gt; vpn-tunnel-protocol IPSec&lt;BR /&gt; split-tunnel-policy tunnelspecified&lt;BR /&gt; split-tunnel-network-list value split_tunnel&lt;BR /&gt; default-domain value XX.XX.gov.uk&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;tunnel-group XXX type remote-access&lt;BR /&gt;tunnel-group XXX general-attributes&lt;BR /&gt; address-pool pool&lt;BR /&gt; default-group-policy XX&lt;BR /&gt;tunnel-group XXX ipsec-attributes&lt;BR /&gt; pre-shared-key *****&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 08 Nov 2010 06:18:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-remote-vpn/m-p/1534543#M607402</guid>
      <dc:creator>estelamathew</dc:creator>
      <dc:date>2010-11-08T06:18:00Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Remote VPN</title>
      <link>https://community.cisco.com/t5/network-security/asa-remote-vpn/m-p/1534544#M607403</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The corporate pool is 10.75.0.0 255.255.0.0 and the VPN range is 10.75.166.1-10.75.166.10 mask&amp;nbsp; 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do the following:&lt;/P&gt;&lt;P&gt;Attempt to connect from the VPN client.&lt;/P&gt;&lt;P&gt;Say you get IP 10.75.166.1/24&lt;/P&gt;&lt;P&gt;Add this route to the internal device: ip route 10.75.166.1 255.255.255.255 INSIDE_IP_ASA&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The idea is that you connect your VPN client and add the route specifically back to the ASA from your corporate LAN and see if it works.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Federico.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 08 Nov 2010 16:33:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-remote-vpn/m-p/1534544#M607403</guid>
      <dc:creator>Federico Coto Fajardo</dc:creator>
      <dc:date>2010-11-08T16:33:16Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Remote VPN</title>
      <link>https://community.cisco.com/t5/network-security/asa-remote-vpn/m-p/1534545#M607404</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Federico,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It is pinging from core to vpn client but i m not able to ping from vpn client to core neither ASA inside interface.Also i m not able to do RDP to servers nor telent to access switches.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 08 Nov 2010 17:02:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-remote-vpn/m-p/1534545#M607404</guid>
      <dc:creator>estelamathew</dc:creator>
      <dc:date>2010-11-08T17:02:52Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Remote VPN</title>
      <link>https://community.cisco.com/t5/network-security/asa-remote-vpn/m-p/1534546#M607405</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you're PINGing fine in one direction is working. Don't you have the windows firewall enabled on the client?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Federico.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 08 Nov 2010 17:04:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-remote-vpn/m-p/1534546#M607405</guid>
      <dc:creator>Federico Coto Fajardo</dc:creator>
      <dc:date>2010-11-08T17:04:21Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Remote VPN</title>
      <link>https://community.cisco.com/t5/network-security/asa-remote-vpn/m-p/1534547#M607406</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Dear,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I saw this it is disabled, i m not able to do RDP to servers nor access to any access switches.I can ping from the access switches but i cant ping from vpn client,&amp;nbsp;&amp;nbsp; very much strange pings menas packets and come back then why client is not able to ping when permit ip any any is enabled on outside interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 08 Nov 2010 17:06:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-remote-vpn/m-p/1534547#M607406</guid>
      <dc:creator>estelamathew</dc:creator>
      <dc:date>2010-11-08T17:06:56Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Remote VPN</title>
      <link>https://community.cisco.com/t5/network-security/asa-remote-vpn/m-p/1534548#M607407</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Seems to me its a routing issue.&lt;/P&gt;&lt;P&gt;Your corporate LAN should have a route to the VPN clients pointing to the ASA (you mentioned there's a default gateway in place), but since the VPN range is included in the corporate range I think the corporate devices think they should keep the traffic local.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you make sure and include a route statement back to the ASA for the VPN client on every device?&lt;/P&gt;&lt;P&gt;Or if using a dynamic routing protocol you can have the ASA inject the route using RRI.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Federico.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 08 Nov 2010 17:10:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-remote-vpn/m-p/1534548#M607407</guid>
      <dc:creator>Federico Coto Fajardo</dc:creator>
      <dc:date>2010-11-08T17:10:30Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Remote VPN</title>
      <link>https://community.cisco.com/t5/network-security/asa-remote-vpn/m-p/1534549#M607408</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Federico&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I removed the route and reload the core switch itis pinging by the default route ,there is no dynamic routing protocol all is static on core pointing to ASA for default and networks with specific next&amp;nbsp; hop&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;.I can ping from the access switches but i cant ping from vpn client,&amp;nbsp;&amp;nbsp;&amp;nbsp; very much strange pings means packets goes and come back then why client is&amp;nbsp; not able to ping when permit ip any any is enabled on outside interface.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 08 Nov 2010 17:13:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-remote-vpn/m-p/1534549#M607408</guid>
      <dc:creator>estelamathew</dc:creator>
      <dc:date>2010-11-08T17:13:30Z</dc:date>
    </item>
  </channel>
</rss>

