- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
02-11-2011 06:24 AM - edited 03-11-2019 12:49 PM
Hi,
I've just setup my first AnyConnect remote acccess vpn on a 5505 running 8.4(1). Everything works except I'm not getting a default gateway for my remote access vpn connection.I can't see where in the profile to set that up. Can someone point me to that setting please?
Solved! Go to Solution.
- Labels:
-
NGFW Firewalls
Accepted Solutions

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
02-11-2011 08:25 AM
as far as I rememeber you won't receive a default gateway on your client. You will get the specific routes to the internal network, this same networks are the ones defined in the access lists for split tunneling. Split tunneling will permit that you can navigate to the internet using your clients internet connection and still be able to comunicate to the networks across the VPN.
Let me know if this answers your question.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
02-11-2011 09:23 AM
make sure those networks are included in the split tunnel ACLs and make sure the ASA know how to get to those internal networks.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
02-11-2011 06:34 AM
Please refer to the following configuartion:
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
02-11-2011 09:17 AM
sorry we haven't gotten our partner status setup yet but will soon

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
02-11-2011 08:25 AM
as far as I rememeber you won't receive a default gateway on your client. You will get the specific routes to the internal network, this same networks are the ones defined in the access lists for split tunneling. Split tunneling will permit that you can navigate to the internet using your clients internet connection and still be able to comunicate to the networks across the VPN.
Let me know if this answers your question.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
02-11-2011 09:16 AM
thanks!
then I'm not getting the routes I need
this network has a transit network on the inside, not the client's network which is one hop away
so I can't ssh or ping or get to any internal devices on the client's networks after connecting
where do I setup routes for vpn clients ?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
02-11-2011 09:23 AM
make sure those networks are included in the split tunnel ACLs and make sure the ASA know how to get to those internal networks.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
02-11-2011 09:42 AM
thanks! must be split tunnel acl since ASA knows all about those networks.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
02-11-2011 06:54 PM
Sorry, I change a avalibale link to you:
http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a0080975e83.shtml
