<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco ASA5505 in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cisco-asa5505/m-p/1128380#M892460</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;what is your ASA software version.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;see below for new changes&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;no access-list Split_Tunnel_List remark The cooperate Network behind the ASA (OLD&lt;/P&gt;&lt;P&gt;no access-list Split_Tunnel_List standard permit 172.16.5.0 255.255.255.0  (OLD)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list basvpnsplit remark internal_access_standard      (NEW)&lt;/P&gt;&lt;P&gt;access-list basvpnsplit standard permit host 192.0.0.0 255.0.0.0  (NEW)&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;access-list basvpn_vpn_acl remark permit_any_extended (NEW)&lt;/P&gt;&lt;P&gt;access-list basvpn_vpn_acl extended permit ip any any  (NEW)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;group-policy basvpn internal &lt;/P&gt;&lt;P&gt;group-policy basvpn attributes &lt;/P&gt;&lt;P&gt;split-tunnel-network-list value basvpnsplit  (NEW)&lt;/P&gt;&lt;P&gt;vpn-filter value basvpn_vpn_acl              (NEW)&lt;/P&gt;&lt;P&gt;split-tunnel-policy tunnelspecified &lt;/P&gt;&lt;P&gt;no split-tunnel-network-list value Split_Tunnel_List  (OLD)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;if this doesnt work, because you have made few changes, its better to delete the the existing remote access VPN config in the ASDM. I then run the VPN wizard again but this time do not enable split tunneling in the wizard. configure split tunneling with the CLI. see the link i sent you before for split-tunnel.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Francisco&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 11 Dec 2008 18:11:15 GMT</pubDate>
    <dc:creator>francisco_1</dc:creator>
    <dc:date>2008-12-11T18:11:15Z</dc:date>
    <item>
      <title>Cisco ASA5505</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa5505/m-p/1128369#M892449</link>
      <description>&lt;P&gt;I have a cisco asa5505 with a base license. Can it be used for site to site and remote access vpn connection at the same time. I seem to be having problems using both options. The site to site is ok but when clients machines connect via remote access they are restricted from accessing resources on the inside interface. Please advise.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 14:24:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa5505/m-p/1128369#M892449</guid>
      <dc:creator>manamsamuel</dc:creator>
      <dc:date>2019-03-11T14:24:33Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASA5505</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa5505/m-p/1128370#M892450</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;yes you can. on the vpn group policy, you need to permit access to the internal network. i beleieve the default acl is any, any apply to the vpn policy group.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;look at this link for split-tunnel: &lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a0080702999.shtml" target="_blank"&gt;http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a0080702999.shtml&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Dec 2008 11:38:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa5505/m-p/1128370#M892450</guid>
      <dc:creator>francisco_1</dc:creator>
      <dc:date>2008-12-11T11:38:08Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASA5505</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa5505/m-p/1128371#M892451</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Done all but clients still can't access network resources. Here is my config..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;access-list basvpn_splitTunnelAcl standard permit any &lt;/P&gt;&lt;P&gt;access-list inside_nat0_outbound extended permit ip any 192.0.0.224 255.255.255.224 &lt;/P&gt;&lt;P&gt;access-list inside_nat0_outbound extended permit ip 192.0.0.0 255.255.0.0 Wxxx 255.255.0.0 &lt;/P&gt;&lt;P&gt;access-list inside_nat0_outbound extended permit ip 192.0.0.0 255.255.0.0 192.0.0.224 255.255.255.224 &lt;/P&gt;&lt;P&gt;access-list outside_1_cryptomap extended permit ip 192.0.0.0 255.255.0.0 Wxxx 255.255.0.0 &lt;/P&gt;&lt;P&gt;access-list civpn_splitTunnelAcl standard permit 192.0.0.0 255.255.0.0 &lt;/P&gt;&lt;P&gt;ip local pool basvpnpool 192.0.0.230-192.0.0.250 mask 255.255.0.0&lt;/P&gt;&lt;P&gt;global (outside) 1 interface&lt;/P&gt;&lt;P&gt;nat (inside) 0 access-list inside_nat0_outbound&lt;/P&gt;&lt;P&gt;nat (inside) 1 0.0.0.0 0.0.0.0&lt;/P&gt;&lt;P&gt;route outside 0.0.0.0 0.0.0.0 62.xx.xxx.xx 1&lt;/P&gt;&lt;P&gt;http server enable&lt;/P&gt;&lt;P&gt;http 192.0.0.0 255.255.0.0 inside&lt;/P&gt;&lt;P&gt;no snmp-server location&lt;/P&gt;&lt;P&gt;no snmp-server contact&lt;/P&gt;&lt;P&gt;crypto ipsec transform-set ESP-AES-128-SHA esp-aes esp-sha-hmac &lt;/P&gt;&lt;P&gt;crypto ipsec transform-set ESP-AES-256-MD5 esp-aes-256 esp-md5-hmac &lt;/P&gt;&lt;P&gt;crypto ipsec transform-set ESP-DES-MD5 esp-des esp-md5-hmac &lt;/P&gt;&lt;P&gt;crypto ipsec transform-set ESP-AES-256-SHA esp-aes-256 esp-sha-hmac &lt;/P&gt;&lt;P&gt;crypto ipsec transform-set ESP-AES-128-MD5 esp-aes esp-md5-hmac &lt;/P&gt;&lt;P&gt;crypto ipsec transform-set ESP-DES-SHA esp-des esp-sha-hmac &lt;/P&gt;&lt;P&gt;crypto ipsec transform-set ESP-AES-192-MD5 esp-aes-192 esp-md5-hmac &lt;/P&gt;&lt;P&gt;crypto ipsec transform-set ESP-AES-192-SHA esp-aes-192 esp-sha-hmac &lt;/P&gt;&lt;P&gt;crypto ipsec transform-set ESP-3DES-MD5 esp-3des esp-md5-hmac &lt;/P&gt;&lt;P&gt;crypto ipsec transform-set ESP-3DES-SHA esp-3des esp-sha-hmac &lt;/P&gt;&lt;P&gt;crypto dynamic-map SYSTEM_DEFAULT_CRYPTO_MAP 65535 set pfs &lt;/P&gt;&lt;P&gt;crypto dynamic-map SYSTEM_DEFAULT_CRYPTO_MAP 65535 set transform-set ESP-AES-128-SHA ESP-AES-128-MD5 ESP-AES-192-SHA ESP-AES-192-MD5 ESP-AES-256-SHA ESP-AES-256-MD5 ESP-3DES-SHA ESP-3DES-MD5 ESP-DES-SHA ESP-DES-MD5&lt;/P&gt;&lt;P&gt;crypto map outside_map 1 match address outside_1_cryptomap&lt;/P&gt;&lt;P&gt;crypto map outside_map 1 set pfs &lt;/P&gt;&lt;P&gt;crypto map outside_map 1 set peer 62.xx.xxx.xxx &lt;/P&gt;&lt;P&gt;crypto map outside_map 1 set transform-set ESP-3DES-SHA&lt;/P&gt;&lt;P&gt;crypto map outside_map 65535 ipsec-isakmp dynamic SYSTEM_DEFAULT_CRYPTO_MAP&lt;/P&gt;&lt;P&gt;crypto map outside_map interface outside&lt;/P&gt;&lt;P&gt;crypto isakmp enable outside&lt;/P&gt;&lt;P&gt;crypto isakmp policy 10&lt;/P&gt;&lt;P&gt;authentication pre-share&lt;/P&gt;&lt;P&gt; encryption 3des&lt;/P&gt;&lt;P&gt; hash sha&lt;/P&gt;&lt;P&gt; group 2&lt;/P&gt;&lt;P&gt; lifetime 86400&lt;/P&gt;&lt;P&gt;no crypto isakmp nat-traversal&lt;/P&gt;&lt;P&gt;client-update enable&lt;/P&gt;&lt;P&gt;telnet timeout 5&lt;/P&gt;&lt;P&gt;ssh timeout 5&lt;/P&gt;&lt;P&gt;console timeout 0&lt;/P&gt;&lt;P&gt;tunnel-group-list enable&lt;/P&gt;&lt;P&gt;group-policy basvpn internal&lt;/P&gt;&lt;P&gt;group-policy basvpn attributes&lt;/P&gt;&lt;P&gt; wins-server value 192.0.0.22 192.0.0.21&lt;/P&gt;&lt;P&gt; dns-server value 192.0.0.23 192.0.0.22&lt;/P&gt;&lt;P&gt; vpn-tunnel-protocol IPSec l2tp-ipsec svc &lt;/P&gt;&lt;P&gt; split-tunnel-policy tunnelspecified&lt;/P&gt;&lt;P&gt;split-tunnel-network-list value basvpn_splitTunnelAcl&lt;/P&gt;&lt;P&gt; default-domain value centerprise.co.uk&lt;/P&gt;&lt;P&gt;group-policy civpn internal&lt;/P&gt;&lt;P&gt;group-policy civpn attributes&lt;/P&gt;&lt;P&gt; wins-server value 192.0.0.22 192.0.0.21&lt;/P&gt;&lt;P&gt; dns-server value 192.0.0.23 192.0.0.22&lt;/P&gt;&lt;P&gt; vpn-tunnel-protocol IPSec svc &lt;/P&gt;&lt;P&gt; split-tunnel-policy tunnelspecified&lt;/P&gt;&lt;P&gt; split-tunnel-network-list value civpn_splitTunnelAcl&lt;/P&gt;&lt;P&gt; default-domain value centerprise.co.uk&lt;/P&gt;&lt;P&gt;tunnel-group basvpn type remote-access&lt;/P&gt;&lt;P&gt;tunnel-group basvpn general-attributes&lt;/P&gt;&lt;P&gt; address-pool basvpnpool&lt;/P&gt;&lt;P&gt; authentication-server-group ciscobox&lt;/P&gt;&lt;P&gt; default-group-policy basvpn&lt;/P&gt;&lt;P&gt;tunnel-group basvpn ipsec-attributes&lt;/P&gt;&lt;P&gt; pre-shared-key *&lt;/P&gt;&lt;P&gt;tunnel-group 62.xxx.xx.xxx type ipsec-l2l&lt;/P&gt;&lt;P&gt;tunnel-group 62.xxx.xx.xxx ipsec-attributes&lt;/P&gt;&lt;P&gt; pre-shared-key *&lt;/P&gt;&lt;P&gt;tunnel-group civpn type remote-access&lt;/P&gt;&lt;P&gt;tunnel-group civpn general-attributes&lt;/P&gt;&lt;P&gt; address-pool basvpnpool&lt;/P&gt;&lt;P&gt; authentication-server-group ciscobox&lt;/P&gt;&lt;P&gt;default-group-policy civpn&lt;/P&gt;&lt;P&gt;tunnel-group civpn webvpn-attributes&lt;/P&gt;&lt;P&gt; group-alias centerprise enable&lt;/P&gt;&lt;P&gt;tunnel-group civpn ipsec-attributes&lt;/P&gt;&lt;P&gt; pre-shared-key *&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;class-map inspection_default&lt;/P&gt;&lt;P&gt; match default-inspection-traffic&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;policy-map type inspect dns preset_dns_map&lt;/P&gt;&lt;P&gt; parameters&lt;/P&gt;&lt;P&gt;  message-length maximum 512&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Dec 2008 12:04:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa5505/m-p/1128371#M892451</guid>
      <dc:creator>manamsamuel</dc:creator>
      <dc:date>2008-12-11T12:04:02Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASA5505</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa5505/m-p/1128372#M892452</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Samuel,&lt;/P&gt;&lt;P&gt;  Try the following change&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip local VPN_pool basvpnpool 172.16.5.1-172.16.5.254 mask 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;tunnel-group basvpn general-attributes &lt;/P&gt;&lt;P&gt;address-pool VPN_pool&lt;/P&gt;&lt;P&gt;no address-pool basvpnpool &lt;/P&gt;&lt;P&gt;tunnel-group civpn general-attributes &lt;/P&gt;&lt;P&gt;address-pool VPN_pool&lt;/P&gt;&lt;P&gt;no address-pool basvpnpool &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;no ip local pool basvpnpool 192.0.0.230-192.0.0.250 mask 255.255.0.0 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list basvpn_splitTunnelAcl standard permit 192.0.0.0 255.255.0.0 &lt;/P&gt;&lt;P&gt;no access-list basvpn_splitTunnelAcl standard permit any &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;crypto isakmp nat-traversal 20&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;no crypto ipsec transform-set ESP-AES-128-SHA esp-aes esp-sha-hmac &lt;/P&gt;&lt;P&gt;no crypto ipsec transform-set ESP-AES-256-MD5 esp-aes-256 esp-md5-hmac &lt;/P&gt;&lt;P&gt;no crypto ipsec transform-set ESP-DES-MD5 esp-des esp-md5-hmac &lt;/P&gt;&lt;P&gt;no crypto ipsec transform-set ESP-AES-256-SHA esp-aes-256 esp-sha-hmac &lt;/P&gt;&lt;P&gt;no crypto ipsec transform-set ESP-AES-128-MD5 esp-aes esp-md5-hmac &lt;/P&gt;&lt;P&gt;no crypto ipsec transform-set ESP-DES-SHA esp-des esp-sha-hmac &lt;/P&gt;&lt;P&gt;no crypto ipsec transform-set ESP-AES-192-MD5 esp-aes-192 esp-md5-hmac &lt;/P&gt;&lt;P&gt;no crypto ipsec transform-set ESP-AES-192-SHA esp-aes-192 esp-sha-hmac &lt;/P&gt;&lt;P&gt;no crypto ipsec transform-set ESP-3DES-MD5 esp-3des esp-md5-hmac &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;no crypto dynamic-map SYSTEM_DEFAULT_CRYPTO_MAP 65535 set transform-set ESP-AES-128-SHA ESP-AES-128-MD5 ESP-AES-192-SHA ESP-AES-192-MD5 ESP-AES-256-SHA ESP-AES-256-MD5 ESP-3DES-SHA ESP-3DES-MD5 ESP-DES-SHA ESP-DES-MD5 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;crypto dynamic-map SYSTEM_DEFAULT_CRYPTO_MAP 65535 set transform-set ESP-3DES-SHA &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;no access-list inside_nat0_outbound extended permit ip 192.0.0.0 255.255.0.0 192.0.0.224 255.255.255.224 &lt;/P&gt;&lt;P&gt;access-list inside_nat0_outbound extended permit ip 192.0.0.0 255.255.0.0 172.16.5.0 255.255.255.240&lt;/P&gt;&lt;P&gt;no access-list inside_nat0_outbound extended permit ip any 192.0.0.224 255.255.255.224 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Dec 2008 12:56:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa5505/m-p/1128372#M892452</guid>
      <dc:creator>Alan Huseyin Kayahan</dc:creator>
      <dc:date>2008-12-11T12:56:01Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASA5505</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa5505/m-p/1128373#M892453</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have made the changes but no luck. I also discovered that when i apply the same configuration to a new asa5505 box without a site to site config it works but both site to site and remote access cannot work on the same box. Is this a license related issue as i currently have a base license.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Dec 2008 15:01:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa5505/m-p/1128373#M892453</guid>
      <dc:creator>manamsamuel</dc:creator>
      <dc:date>2008-12-11T15:01:17Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASA5505</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa5505/m-p/1128374#M892454</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;are u saying that both basvpn, civpn vpn group cannot access anything on the inside?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;how is the ASA connected to the inside network. is it connected to a layer 3 switch?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;after making the config changes Huseyin asked you to do, can you post the current config on the ASA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Francisco. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Dec 2008 16:06:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa5505/m-p/1128374#M892454</guid>
      <dc:creator>francisco_1</dc:creator>
      <dc:date>2008-12-11T16:06:12Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASA5505</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa5505/m-p/1128375#M892455</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Samuel,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;After the users are connected and you do a show crypto ipsec sa, do u see packets making to the ASA. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, Is it a requirement to assign the Pool of IP Addresses for the VPN Client from your internal subnet. While, technically this should work, I have seen more issues when configuring VPN Pool from the internal subnet. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you change the VPN Pool of IP Address to something totally different from your inside subnet and then do the testing. You also, need to change the Split Tunnel and NAT 0 ACL to reflect the new pool of ip addresses. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Arul&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;*Pls rate if it helps*&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Dec 2008 16:27:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa5505/m-p/1128375#M892455</guid>
      <dc:creator>ajagadee</dc:creator>
      <dc:date>2008-12-11T16:27:03Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASA5505</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa5505/m-p/1128376#M892456</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;yes both groups cannot access inside network and am connected to a layer 3 hp switch with all port in vlan 1.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have another cisco ASA5505 box and i configured it for remote access only and all remote clients can access the inside network. If i decide to add site to site service on the same box the remote clients will be denied access to inside interface. So am currently using 2 cisco asa5505, one for site to site vpn to my branch office and the second for remote access clients only.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Dec 2008 17:12:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa5505/m-p/1128376#M892456</guid>
      <dc:creator>manamsamuel</dc:creator>
      <dc:date>2008-12-11T17:12:26Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASA5505</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa5505/m-p/1128377#M892457</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;post your current config from the ASA not working...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Dec 2008 17:15:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa5505/m-p/1128377#M892457</guid>
      <dc:creator>francisco_1</dc:creator>
      <dc:date>2008-12-11T17:15:45Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASA5505</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa5505/m-p/1128378#M892458</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I changed the vpn pool ip to 172.16.5.0 network but still having the same problem. I had to use a spare asa5505 box for remote access vpn only and is all working ok. The question is; why can't i have both site to site and remote access working on one box?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Dec 2008 17:17:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa5505/m-p/1128378#M892458</guid>
      <dc:creator>manamsamuel</dc:creator>
      <dc:date>2008-12-11T17:17:11Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASA5505</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa5505/m-p/1128379#M892459</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;hostname Basvpn&lt;/P&gt;&lt;P&gt;enable password 8Ry2YjIyt7RRXU24 encrypted&lt;/P&gt;&lt;P&gt;names&lt;/P&gt;&lt;P&gt;name 192.1.0.0 Wxxx description Wxxx Remote LAN&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlan1&lt;/P&gt;&lt;P&gt; nameif inside&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt; ip address 192.0.0.7 255.255.0.0 &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlan2&lt;/P&gt;&lt;P&gt; nameif outside&lt;/P&gt;&lt;P&gt; security-level 0&lt;/P&gt;&lt;P&gt; ip address xxx.xx.xx4.84 255.255.255.240 &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/7&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;passwd 2KFQnbNIdI.2KYOU encrypted&lt;/P&gt;&lt;P&gt;ftp mode passive&lt;/P&gt;&lt;P&gt;access-list Split_Tunnel_List remark The cooperate Network behind the ASA&lt;/P&gt;&lt;P&gt;access-list Split_Tunnel_List standard permit 172.16.5.0 255.255.255.0 &lt;/P&gt;&lt;P&gt;access-list inside_nat0_outbound extended permit ip 192.0.0.0 255.255.0.0 Wales 255.255.0.0 &lt;/P&gt;&lt;P&gt;access-list inside_nat0_outbound extended permit ip any 172.16.5.0 255.255.255.0 &lt;/P&gt;&lt;P&gt;access-list outside_1_cryptomap extended permit ip 192.0.0.0 255.255.0.0 Wales 255.255.0.0 &lt;/P&gt;&lt;P&gt;pager lines 24&lt;/P&gt;&lt;P&gt;logging enable&lt;/P&gt;&lt;P&gt;logging asdm informational&lt;/P&gt;&lt;P&gt;mtu outside 1500&lt;/P&gt;&lt;P&gt;mtu inside 1500&lt;/P&gt;&lt;P&gt;ip local pool basvpnpool 172.16.5.1-172.16.5.254 mask 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;icmp unreachable rate-limit 1 burst-size 1&lt;/P&gt;&lt;P&gt;asdm image disk0:/asdm-611.bin&lt;/P&gt;&lt;P&gt;no asdm history enable&lt;/P&gt;&lt;P&gt;arp timeout 14400&lt;/P&gt;&lt;P&gt;global (outside) 1 interface&lt;/P&gt;&lt;P&gt;nat (inside) 0 access-list inside_nat0_outbound&lt;/P&gt;&lt;P&gt;nat (inside) 1 0.0.0.0 0.0.0.0&lt;/P&gt;&lt;P&gt;route outside 0.0.0.0 0.0.0.0 xxx.xxx.x4.94 1&lt;/P&gt;&lt;P&gt;timeout xlate 3:00:00&lt;/P&gt;&lt;P&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02&lt;/P&gt;&lt;P&gt;timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00&lt;/P&gt;&lt;P&gt;timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00&lt;/P&gt;&lt;P&gt;timeout uauth 0:05:00 absolute&lt;/P&gt;&lt;P&gt;dynamic-access-policy-record DfltAccessPolicy&lt;/P&gt;&lt;P&gt;aaa-server ciscobox protocol radius&lt;/P&gt;&lt;P&gt;aaa-server ciscobox host 192.0.0.23&lt;/P&gt;&lt;P&gt; timeout 5&lt;/P&gt;&lt;P&gt; key xxxxxxx&lt;/P&gt;&lt;P&gt;http server enable&lt;/P&gt;&lt;P&gt;http 192.0.0.0 255.255.0.0 inside&lt;/P&gt;&lt;P&gt;no snmp-server location&lt;/P&gt;&lt;P&gt;no snmp-server contact&lt;/P&gt;&lt;P&gt;snmp-server enable traps snmp authentication linkup linkdown coldstart&lt;/P&gt;&lt;P&gt;crypto ipsec transform-set ESP-3DES-SHA esp-3des esp-sha-hmac &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;crypto dynamic-map SYSTEM_DEFAULT_CRYPTO_MAP 65535 set pfs &lt;/P&gt;&lt;P&gt;crypto dynamic-map SYSTEM_DEFAULT_CRYPTO_MAP 65535 set transform-set ESP-3DES-SHA&lt;/P&gt;&lt;P&gt;crypto map outside_map 1 match address outside_1_cryptomap&lt;/P&gt;&lt;P&gt;crypto map outside_map 1 set pfs &lt;/P&gt;&lt;P&gt;crypto map outside_map 1 set peer xxx.xxx.x3.1xx&lt;/P&gt;&lt;P&gt;crypto map outside_map 1 set transform-set ESP-3DES-SHA&lt;/P&gt;&lt;P&gt;crypto map outside_map 65535 ipsec-isakmp dynamic SYSTEM_DEFAULT_CRYPTO_MAP&lt;/P&gt;&lt;P&gt;crypto map outside_map interface outside&lt;/P&gt;&lt;P&gt;crypto isakmp enable outside&lt;/P&gt;&lt;P&gt;crypto isakmp policy 10&lt;/P&gt;&lt;P&gt; authentication pre-share&lt;/P&gt;&lt;P&gt; encryption 3des&lt;/P&gt;&lt;P&gt; hash sha&lt;/P&gt;&lt;P&gt; group 2&lt;/P&gt;&lt;P&gt; lifetime 86400&lt;/P&gt;&lt;P&gt;client-update enable&lt;/P&gt;&lt;P&gt;telnet timeout 5&lt;/P&gt;&lt;P&gt;ssh timeout 5&lt;/P&gt;&lt;P&gt;console timeout 0&lt;/P&gt;&lt;P&gt;dhcpd auto_config outside&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;threat-detection basic-threat&lt;/P&gt;&lt;P&gt;threat-detection statistics&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;webvpn&lt;/P&gt;&lt;P&gt; tunnel-group-list enable&lt;/P&gt;&lt;P&gt;group-policy basvpn internal&lt;/P&gt;&lt;P&gt;group-policy basvpn attributes&lt;/P&gt;&lt;P&gt; wins-server value 192.0.0.21 192.0.0.22&lt;/P&gt;&lt;P&gt; dns-server value 192.0.0.23 192.0.0.22&lt;/P&gt;&lt;P&gt; vpn-tunnel-protocol IPSec &lt;/P&gt;&lt;P&gt; split-tunnel-policy tunnelspecified&lt;/P&gt;&lt;P&gt; split-tunnel-network-list value Split_Tunnel_List&lt;/P&gt;&lt;P&gt; default-domain value centxxxxx.com&lt;/P&gt;&lt;P&gt;tunnel-group basvpn type remote-access&lt;/P&gt;&lt;P&gt;tunnel-group basvpn general-attributes&lt;/P&gt;&lt;P&gt; address-pool basvpnpool&lt;/P&gt;&lt;P&gt; authentication-server-group ciscobox&lt;/P&gt;&lt;P&gt; default-group-policy basvpn&lt;/P&gt;&lt;P&gt;tunnel-group basvpn ipsec-attributes&lt;/P&gt;&lt;P&gt; pre-shared-key *&lt;/P&gt;&lt;P&gt;tunnel-group 6xx.xxxx.xxxx type ipsec-l2l&lt;/P&gt;&lt;P&gt;tunnel-group 6xx.xxxx.xxxx ipsec-attributes&lt;/P&gt;&lt;P&gt; pre-shared-key *&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;class-map inspection_default&lt;/P&gt;&lt;P&gt; match default-inspection-traffic&lt;/P&gt;&lt;P&gt;policy-map type inspect dns preset_dns_map&lt;/P&gt;&lt;P&gt; parameters&lt;/P&gt;&lt;P&gt;  message-length maximum 512&lt;/P&gt;&lt;P&gt;policy-map global_policy&lt;/P&gt;&lt;P&gt; class inspection_default&lt;/P&gt;&lt;P&gt;  inspect dns preset_dns_map &lt;/P&gt;&lt;P&gt;  inspect ftp &lt;/P&gt;&lt;P&gt;  inspect h323 h225 &lt;/P&gt;&lt;P&gt;  inspect h323 ras &lt;/P&gt;&lt;P&gt;  inspect rsh &lt;/P&gt;&lt;P&gt;  inspect rtsp &lt;/P&gt;&lt;P&gt;  inspect esmtp &lt;/P&gt;&lt;P&gt;  inspect sqlnet &lt;/P&gt;&lt;P&gt;  inspect skinny  &lt;/P&gt;&lt;P&gt;  inspect sunrpc &lt;/P&gt;&lt;P&gt;  inspect xdmcp &lt;/P&gt;&lt;P&gt;  inspect sip  &lt;/P&gt;&lt;P&gt;  inspect netbios &lt;/P&gt;&lt;P&gt;  inspect tftp &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;service-policy global_policy global&lt;/P&gt;&lt;P&gt;prompt hostname context &lt;/P&gt;&lt;P&gt;Cryptochecksum:ff2de0ced4fd3b6d966d5e79683dfefb&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Dec 2008 17:26:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa5505/m-p/1128379#M892459</guid>
      <dc:creator>manamsamuel</dc:creator>
      <dc:date>2008-12-11T17:26:43Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASA5505</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa5505/m-p/1128380#M892460</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;what is your ASA software version.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;see below for new changes&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;no access-list Split_Tunnel_List remark The cooperate Network behind the ASA (OLD&lt;/P&gt;&lt;P&gt;no access-list Split_Tunnel_List standard permit 172.16.5.0 255.255.255.0  (OLD)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list basvpnsplit remark internal_access_standard      (NEW)&lt;/P&gt;&lt;P&gt;access-list basvpnsplit standard permit host 192.0.0.0 255.0.0.0  (NEW)&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;access-list basvpn_vpn_acl remark permit_any_extended (NEW)&lt;/P&gt;&lt;P&gt;access-list basvpn_vpn_acl extended permit ip any any  (NEW)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;group-policy basvpn internal &lt;/P&gt;&lt;P&gt;group-policy basvpn attributes &lt;/P&gt;&lt;P&gt;split-tunnel-network-list value basvpnsplit  (NEW)&lt;/P&gt;&lt;P&gt;vpn-filter value basvpn_vpn_acl              (NEW)&lt;/P&gt;&lt;P&gt;split-tunnel-policy tunnelspecified &lt;/P&gt;&lt;P&gt;no split-tunnel-network-list value Split_Tunnel_List  (OLD)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;if this doesnt work, because you have made few changes, its better to delete the the existing remote access VPN config in the ASDM. I then run the VPN wizard again but this time do not enable split tunneling in the wizard. configure split tunneling with the CLI. see the link i sent you before for split-tunnel.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Francisco&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Dec 2008 18:11:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa5505/m-p/1128380#M892460</guid>
      <dc:creator>francisco_1</dc:creator>
      <dc:date>2008-12-11T18:11:15Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASA5505</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa5505/m-p/1128381#M892461</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Francisco,&lt;/P&gt;&lt;P&gt;Still not working after all changes;&lt;/P&gt;&lt;P&gt;sh run&lt;/P&gt;&lt;P&gt;: Saved&lt;/P&gt;&lt;P&gt;:&lt;/P&gt;&lt;P&gt;ASA Version 8.0(3) &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;hostname Basvpn&lt;/P&gt;&lt;P&gt;enable password 8Ry2YjIyt7RRXU24 encrypted&lt;/P&gt;&lt;P&gt;names&lt;/P&gt;&lt;P&gt;name 192.1.0.0 Wxxx description Wxxxx Remote LAN&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlan1&lt;/P&gt;&lt;P&gt; nameif inside&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt; ip address 192.0.0.7 255.255.0.0 &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlan2&lt;/P&gt;&lt;P&gt; nameif outside&lt;/P&gt;&lt;P&gt; security-level 0&lt;/P&gt;&lt;P&gt; ip address 62x.xx.xxx.xx 255.255.255.240 &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/0&lt;/P&gt;&lt;P&gt; switchport access vlan 2&lt;/P&gt;&lt;P&gt;interface Ethernet0/7&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list Split_Tunnel_List remark The corporate network behind the ASA&lt;/P&gt;&lt;P&gt;access-list Split_Tunnel_List standard permit 10.0.1.0 255.255.255.0 &lt;/P&gt;&lt;P&gt;access-list inside_nat0_outbound extended permit ip any 172.16.5.0 255.255.255.0 &lt;/P&gt;&lt;P&gt;access-list inside_nat0_outbound extended permit ip 192.0.0.0 255.255.0.0 10.0.1.0 255.255.255.192 &lt;/P&gt;&lt;P&gt;access-list outside_1_cryptomap extended permit ip 192.0.0.0 255.255.0.0 Wxxx 255.255.0.0 &lt;/P&gt;&lt;P&gt;ip local pool basvpnpool 10.0.1.1-10.0.1.50 mask 255.255.255.0&lt;/P&gt;&lt;P&gt;asdm image disk0:/asdm-611.bin&lt;/P&gt;&lt;P&gt;global (outside) 1 interface&lt;/P&gt;&lt;P&gt;nat (inside) 0 access-list inside_nat0_outbound&lt;/P&gt;&lt;P&gt;nat (inside) 1 0.0.0.0 0.0.0.0&lt;/P&gt;&lt;P&gt;route outside 0.0.0.0 0.0.0.0 6xx.xx.xxx.xxx 1&lt;/P&gt;&lt;P&gt;dynamic-access-policy-record DfltAccessPolicy&lt;/P&gt;&lt;P&gt;aaa-server ciscobox protocol radius&lt;/P&gt;&lt;P&gt;aaa-server ciscobox host 192.0.0.23&lt;/P&gt;&lt;P&gt; timeout 5&lt;/P&gt;&lt;P&gt;http server enable&lt;/P&gt;&lt;P&gt;http 192.0.0.0 255.255.0.0 inside&lt;/P&gt;&lt;P&gt;snmp-server enable traps snmp authentication linkup linkdown coldstart&lt;/P&gt;&lt;P&gt;crypto ipsec transform-set ESP-3DES-SHA esp-3des esp-sha-hmac &lt;/P&gt;&lt;P&gt;crypto dynamic-map SYSTEM_DEFAULT_CRYPTO_MAP 65535 set pfs &lt;/P&gt;&lt;P&gt;crypto dynamic-map SYSTEM_DEFAULT_CRYPTO_MAP 65535 set transform-set ESP-3DES-SHA&lt;/P&gt;&lt;P&gt;crypto map outside_map 1 match address outside_1_cryptomap&lt;/P&gt;&lt;P&gt;crypto map outside_map 1 set pfs &lt;/P&gt;&lt;P&gt;crypto map outside_map 1 set peer 6xx.xx.xx.xxx &lt;/P&gt;&lt;P&gt;crypto map outside_map 1 set transform-set ESP-3DES-SHA&lt;/P&gt;&lt;P&gt;crypto map outside_map 65535 ipsec-isakmp dynamic SYSTEM_DEFAULT_CRYPTO_MAP&lt;/P&gt;&lt;P&gt;crypto map outside_map interface outside&lt;/P&gt;&lt;P&gt;crypto isakmp enable outside&lt;/P&gt;&lt;P&gt;crypto isakmp policy 10&lt;/P&gt;&lt;P&gt; authentication pre-share&lt;/P&gt;&lt;P&gt; encryption 3des&lt;/P&gt;&lt;P&gt; hash sha&lt;/P&gt;&lt;P&gt; group 2&lt;/P&gt;&lt;P&gt; lifetime 86400&lt;/P&gt;&lt;P&gt;webvpn&lt;/P&gt;&lt;P&gt; tunnel-group-list enable&lt;/P&gt;&lt;P&gt;group-policy basvpn internal&lt;/P&gt;&lt;P&gt;group-policy basvpn attributes&lt;/P&gt;&lt;P&gt;wins-server value 192.0.0.21 192.0.0.22&lt;/P&gt;&lt;P&gt; dns-server value 192.0.0.23 192.0.0.22&lt;/P&gt;&lt;P&gt; vpn-tunnel-protocol IPSec &lt;/P&gt;&lt;P&gt; split-tunnel-policy tunnelspecified&lt;/P&gt;&lt;P&gt; split-tunnel-network-list value Split_Tunnel_List&lt;/P&gt;&lt;P&gt; default-domain value cenxxxxx.cm&lt;/P&gt;&lt;P&gt;tunnel-group basvpn type remote-access&lt;/P&gt;&lt;P&gt;tunnel-group basvpn general-attributes&lt;/P&gt;&lt;P&gt; address-pool basvpnpool&lt;/P&gt;&lt;P&gt; authentication-server-group ciscobox&lt;/P&gt;&lt;P&gt; default-group-policy basvpn&lt;/P&gt;&lt;P&gt;tunnel-group basvpn ipsec-attributes&lt;/P&gt;&lt;P&gt; pre-shared-key *&lt;/P&gt;&lt;P&gt;tunnel-group 6xx.xx.xx.xxx type ipsec-l2l&lt;/P&gt;&lt;P&gt;tunnel-group 6xx.xxx.xxx.xxx ipsec-attributes&lt;/P&gt;&lt;P&gt; pre-shared-key *&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt; parameters&lt;/P&gt;&lt;P&gt;  message-length maximum 512&lt;/P&gt;&lt;P&gt;policy-map global_policy&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;service-policy global_policy global&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 Dec 2008 10:47:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa5505/m-p/1128381#M892461</guid>
      <dc:creator>manamsamuel</dc:creator>
      <dc:date>2008-12-12T10:47:50Z</dc:date>
    </item>
  </channel>
</rss>

