cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
Announcements

Welcome to Cisco Firewalls Community


249
Views
0
Helpful
17
Replies

ASA WEB VPN

Hi,

There is a web server hosted on internet nobody can access it from internet except allowed IPs.
so we can access it from our prem but not from internet.
we created sslvpn on Cisco ASA and added the URL of the web server as bookmark but it doesn't work.
we found that ASA the traffic to internet directly not through the Proxy,
how we can make ASA to send the traffic to this URL to the proxy?

Regards

Everyone's tags (2)
17 REPLIES 17
VIP Advisor

Re: ASA WEB VPN

As per my understading

 

when the user connect to your network using VPN they are not able to access the URL, which was access through your Local Lan but not on VPN.

 

if this case, is your LAN using Proxy settings, or WCCP to send traffic to proxy Server.

 

Explain how is your Lan access to this URL, flow model.

 

BB
*** Rate All Helpful Responses ***

Re: ASA WEB VPN

Thank you for your response,



from local lan the traffic goes to ASA a policy based routing forwards http and https to the proxy.

but when the user clicks the bookmark the traffic goes directly to internet without passing the proxy.

i need to make it go to the proxy.


VIP Advisor

Re: ASA WEB VPN

but when the user clicks the bookmark the traffic goes directly to internet without passing the proxy.

 

This you mean VPN user ? in this case you need to use same policy to route to proxy. (for the IP range for the VPN Range).

 

BB
*** Rate All Helpful Responses ***

Re: ASA WEB VPN

yes clientless ssl vpn user, there is no ip range because this is client less vpn , if i change same policy the remaining 9000 users well be affected i want to configure the bookmark only to go to the proxy, but how ?
Highlighted
VIP Advisor

Re: ASA WEB VPN

as suggested other post we need more details to assist further on this problem.

BB
*** Rate All Helpful Responses ***
Contributor

Re: ASA WEB VPN

You have more details? What is happening when you try? Is the link showing up in the webvpn portal? What error are you experiencing?

Thanks,

George

Re: ASA WEB VPN


@gbekmezi-DD wrote:
You have more details? What is happening when you try? Is the link showing up in the webvpn portal? What error are you experiencing?

Thanks,

George

yes the link showing in the portal,the traffic goes to internet but as the web server do not accept traffic except from our proxy ip the web page does not open, we need a way to make the traffic go to the proxy I wonder if there is a method to add the proxy IP to the group policy to make this particular bookmark to go to the proxy

VIP Advisor

Re: ASA WEB VPN

Since you are redirecting the Traffic to proxy using PBR, you need to identify the VPN user IP block and route the same to proxy for that URL IP, so proxy will can allow your VPN users to access that URL.

 

If you think this is issue with your other users and Service impact.

 

for testing create a another vpn user group with new IP range, test it, if that works deploy same for all other users.

 

Make Sense ?

 

BB
*** Rate All Helpful Responses ***

Re: ASA WEB VPN

there is NO vpn user ip BECAUSE this is CLIENTLESS vpn

Re: ASA WEB VPN

there is NO VPN USER IP BECAUSE this is CLIENTLESS SSL VPN through portal

Re: ASA WEB VPN

yes make sense but there is a little problem there is NO IP RANGE and NO IP POOL BECAUSE THIS IS CLIENTLESS SSL VPN



VIP Advisor

Re: ASA WEB VPN

Can you post webvpn part of  configuration.

BB
*** Rate All Helpful Responses ***
Contributor

Re: ASA WEB VPN

What kind of proxy are you using and what network equipment exists between the ASA and the web server? Can you use WCCP to redirect the traffic sourced from the ASA to the internal web server to your proxy?

Re: ASA WEB VPN

the traffic coming from the users to the ASA where there is policy based routing to forward http and https to bluecoat.


do you mean that it is possible to use wccp to forward the traffic of this bookmark to bluecoat and keep all remaining traffic as it is , is this possible ?