<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Remote Access - VPN in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/remote-access-vpn/m-p/914293#M956398</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;what about if my outside interface is not directly connected to the internet. My outside interface in my ASA5500 is conected to the ISP router but the ISP give me a 10.x.x.x/32 subnet.&lt;/P&gt;&lt;P&gt;The ISP routers forward to my firewall the subnet with the publict ip's.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 06 Mar 2008 14:09:26 GMT</pubDate>
    <dc:creator>Rafael Jimenez</dc:creator>
    <dc:date>2008-03-06T14:09:26Z</dc:date>
    <item>
      <title>Remote Access - VPN</title>
      <link>https://community.cisco.com/t5/network-security/remote-access-vpn/m-p/914291#M956392</link>
      <description>&lt;P&gt;I have the following configuration in an ASA5505-SEC-BUN-K8:&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlan1&lt;/P&gt;&lt;P&gt; nameif Servers&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt; ip address 192.168.80.1 255.255.255.0 &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlan10&lt;/P&gt;&lt;P&gt; nameif internet&lt;/P&gt;&lt;P&gt; security-level 0&lt;/P&gt;&lt;P&gt; ip address 10.0.11.99 255.255.0.0 &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlan90&lt;/P&gt;&lt;P&gt; nameif huespedes&lt;/P&gt;&lt;P&gt; security-level 40&lt;/P&gt;&lt;P&gt; ip address 192.168.90.1 255.255.255.0 &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlan201&lt;/P&gt;&lt;P&gt; nameif dmz&lt;/P&gt;&lt;P&gt; security-level 50&lt;/P&gt;&lt;P&gt; ip address 201.245.184.225 255.255.255.224 &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlan254&lt;/P&gt;&lt;P&gt; nameif bogota&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt; ip address 192.168.252.2 255.255.255.252 &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;I would like to know on which interface has to enable the vpn ;&lt;/P&gt;&lt;P&gt;crypto map ?????_map interface ????&lt;/P&gt;&lt;P&gt;crypto isakmp enable ?????&lt;/P&gt;&lt;P&gt;My outside interface is called internet.&lt;/P&gt;&lt;P&gt;If i have 30 public ips and the dmz vlan is using one of this public ip's , how need setup my vpn access?.&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 11:53:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/remote-access-vpn/m-p/914291#M956392</guid>
      <dc:creator>Rafael Jimenez</dc:creator>
      <dc:date>2019-03-11T11:53:15Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access - VPN</title>
      <link>https://community.cisco.com/t5/network-security/remote-access-vpn/m-p/914292#M956394</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I would recommend that you apply the crypto map on the interface where your default route is pointing to. The reason is, for Remote Access VPN, the user would be coming from any source IP and for the ASA to route the packets back to the VPN Client, a default route will scale much better. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Arul&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;** Please rate all helpful posts **&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 24 Jan 2008 22:40:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/remote-access-vpn/m-p/914292#M956394</guid>
      <dc:creator>ajagadee</dc:creator>
      <dc:date>2008-01-24T22:40:59Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access - VPN</title>
      <link>https://community.cisco.com/t5/network-security/remote-access-vpn/m-p/914293#M956398</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;what about if my outside interface is not directly connected to the internet. My outside interface in my ASA5500 is conected to the ISP router but the ISP give me a 10.x.x.x/32 subnet.&lt;/P&gt;&lt;P&gt;The ISP routers forward to my firewall the subnet with the publict ip's.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Mar 2008 14:09:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/remote-access-vpn/m-p/914293#M956398</guid>
      <dc:creator>Rafael Jimenez</dc:creator>
      <dc:date>2008-03-06T14:09:26Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access - VPN</title>
      <link>https://community.cisco.com/t5/network-security/remote-access-vpn/m-p/914294#M956400</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In that case you will not be able to terminate the Remote access VPN's on the firewall unless the ISP NAT's one of your public ip's to your external interface of your ASA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The only other way around this will be to use some of your public address space on the network between the firewall and ISP router.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Mar 2008 14:45:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/remote-access-vpn/m-p/914294#M956400</guid>
      <dc:creator>brettmilborrow</dc:creator>
      <dc:date>2008-03-06T14:45:24Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access - VPN</title>
      <link>https://community.cisco.com/t5/network-security/remote-access-vpn/m-p/914295#M956401</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;  you will enable on the internet.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 07 Mar 2008 07:11:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/remote-access-vpn/m-p/914295#M956401</guid>
      <dc:creator>onlyabhishek007</dc:creator>
      <dc:date>2008-03-07T07:11:10Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access - VPN</title>
      <link>https://community.cisco.com/t5/network-security/remote-access-vpn/m-p/914296#M956403</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;if I select the isp NAT option, how need setup the ASA to avoid the NAT-IPSEc issue?.&lt;/P&gt;&lt;P&gt;thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 07 Mar 2008 14:28:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/remote-access-vpn/m-p/914296#M956403</guid>
      <dc:creator>Rafael Jimenez</dc:creator>
      <dc:date>2008-03-07T14:28:35Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access - VPN</title>
      <link>https://community.cisco.com/t5/network-security/remote-access-vpn/m-p/914297#M956406</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You need to enable nat traversal with the following command:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"isakmp nat-traversal"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Good Luck!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 07 Mar 2008 23:33:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/remote-access-vpn/m-p/914297#M956406</guid>
      <dc:creator>brettmilborrow</dc:creator>
      <dc:date>2008-03-07T23:33:52Z</dc:date>
    </item>
  </channel>
</rss>

