<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic remote access vpn ip pool cannot access vlan in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/remote-access-vpn-ip-pool-cannot-access-vlan/m-p/1183360#M877779</link>
    <description>&lt;P&gt;we have an ip pool allocated on the firewall (ASA 5520) for remote access vpn.  vpn users can access all internal resources with the exception of the following segments:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;192.168.200.0\24&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There are no ACL's on the vlan interface to block this traffic, the problem appears to be on the firewall.  Here's all the nonatI have for the IP pool segment (10.20.50.0\24):&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list inside_nat0_outbound extended permit ip 10.0.0.0 255.0.0.0 10.20.50.0 255.255.255.0&lt;/P&gt;&lt;P&gt;access-list inside_nat0_outbound extended permit ip 10.20.99.0 255.255.255.0 10.20.50.0 255.255.255.0&lt;/P&gt;&lt;P&gt;access-list inside_nat0_outbound extended permit ip any 10.20.50.0 255.255.255.0&lt;/P&gt;&lt;P&gt;access-list inside_nat0_outbound extended permit ip 192.168.4.0 255.255.255.0 10.20.50.0 255.255.255.0&lt;/P&gt;&lt;P&gt;access-list inside_nat0_outbound extended permit ip 192.168.200.0 255.255.255.0 10.20.50.0 255.255.255.0 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Again, the routing is not the problem.&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 14:35:50 GMT</pubDate>
    <dc:creator>ronshuster</dc:creator>
    <dc:date>2019-03-11T14:35:50Z</dc:date>
    <item>
      <title>remote access vpn ip pool cannot access vlan</title>
      <link>https://community.cisco.com/t5/network-security/remote-access-vpn-ip-pool-cannot-access-vlan/m-p/1183360#M877779</link>
      <description>&lt;P&gt;we have an ip pool allocated on the firewall (ASA 5520) for remote access vpn.  vpn users can access all internal resources with the exception of the following segments:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;192.168.200.0\24&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There are no ACL's on the vlan interface to block this traffic, the problem appears to be on the firewall.  Here's all the nonatI have for the IP pool segment (10.20.50.0\24):&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list inside_nat0_outbound extended permit ip 10.0.0.0 255.0.0.0 10.20.50.0 255.255.255.0&lt;/P&gt;&lt;P&gt;access-list inside_nat0_outbound extended permit ip 10.20.99.0 255.255.255.0 10.20.50.0 255.255.255.0&lt;/P&gt;&lt;P&gt;access-list inside_nat0_outbound extended permit ip any 10.20.50.0 255.255.255.0&lt;/P&gt;&lt;P&gt;access-list inside_nat0_outbound extended permit ip 192.168.4.0 255.255.255.0 10.20.50.0 255.255.255.0&lt;/P&gt;&lt;P&gt;access-list inside_nat0_outbound extended permit ip 192.168.200.0 255.255.255.0 10.20.50.0 255.255.255.0 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Again, the routing is not the problem.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 14:35:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/remote-access-vpn-ip-pool-cannot-access-vlan/m-p/1183360#M877779</guid>
      <dc:creator>ronshuster</dc:creator>
      <dc:date>2019-03-11T14:35:50Z</dc:date>
    </item>
    <item>
      <title>Re: remote access vpn ip pool cannot access vlan</title>
      <link>https://community.cisco.com/t5/network-security/remote-access-vpn-ip-pool-cannot-access-vlan/m-p/1183361#M877780</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What does the asdm real time log tells you? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;what interfaces in asa are these networks coming from? &lt;/P&gt;&lt;P&gt;10.20.99.0/24&lt;/P&gt;&lt;P&gt;192.168.4.0/24&lt;/P&gt;&lt;P&gt;192.168.200.0/24 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;what are your ASA nat statements look like in reference to these nat exempt acls, posting  sanatize config and some logs will help us in giving clues to what the problem could be. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 12 Jan 2009 23:44:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/remote-access-vpn-ip-pool-cannot-access-vlan/m-p/1183361#M877780</guid>
      <dc:creator>JORGE RODRIGUEZ</dc:creator>
      <dc:date>2009-01-12T23:44:35Z</dc:date>
    </item>
  </channel>
</rss>

