11-11-2010 07:01 AM - edited 03-11-2019 12:07 PM
Hi
I have configured remote access VPN with local pool in ASA firewall however im accessing all the resources(my private network such as servers ) through asa firewall after getting connected the VPN but i cant the mailing server through webmail(ports like 80).Please check the configs.
Solved! Go to Solution.
11-11-2010 07:26 AM
Hello,
Would you please take a look at the split tunneling list? Where is the OWA server located?
Cheers.
Mike
11-11-2010 07:26 AM
Hello,
Would you please take a look at the split tunneling list? Where is the OWA server located?
Cheers.
Mike
11-11-2010 09:04 AM
Hi,
It seems the OWA has 192.168.100.1 correct?
That IP is internal to the ASA via a static route.
In order for you to be able to reach that server via port 80, the server must be included in the nat0 ACL.
Question.
Can you PING 192.168.100.1 from the VPN client?
I just want to make sure that packets from the VPN client reaches the server and that the problem is specifically with the port 80.
Federico.
11-12-2010 10:39 PM
Hi....thanks.
Yes.I can ping 192.168.100.1 from the vpn client.
But i can't access web mail from the vpn client.
11-14-2010 07:04 PM
Hi
The OWA sserver is located at my Corporate office and the server ip is 192.168.100.1.After getting connected the vpn client,im pinging the server ip i.e 192.168.100.1 but i cant access my webmail.
R u considering the problem is at 80 port?
11-13-2010 01:33 AM
My OWA server locataed at my corperate office.
11-15-2010 05:26 AM
Do you have a route on the 10.10.20.2 router, pointing the VPN pool back to the ASA ??
a route like,
ip route 172.16.1.0 255.255.255.0 10.10.20 1 ??
Cheers,
Nash.
11-15-2010 08:37 PM
Hi.....Thanks,
But VPN ip pool was 182.16.1.1-182.16.1.10.Whenever he connected the vpn client,it will assigned this network 182.16.1.0
Can i put this command,
ip route 182.16.1.0 255.255.255.0 10.10.20.1?..
Please advice me.
Thanks.
11-15-2010 08:48 PM
Hi,
Was that a typo 182 in place of 172 ??
I saw the pool as 172.16.1.0/24 in the configuration.
Yeah, you could add that route
ip route 172.16.1.0 255.255.255.0 10.10.20.1
If it is 182
then
ip route 182.16.1.0 255.255.255.0 10.10.20.1
Let me know how it goes.
Cheers,
Nash.
11-15-2010 09:06 PM
Hi.....
When i put this command,it is saying,
IFASA#
IFASA#config terminal
IFASA(config)#
IFASA(config)# ip route 172.16.1.0 255.255.255.0 10.10.20.1
ERROR: % invalid input deteced at '^' maker
IFASA(config)#
Please advice me.
Thanks.
11-15-2010 09:08 PM
Are you adding that route on 10.10.20.2 router ??
Cheers,
Nash
11-15-2010 09:34 PM
Hi......
Ya.....i put this command the router.
the command was ,
ip route 172.16.1.0 255.255.255.0 10.10.20.1
Thanks.
11-15-2010 09:56 PM
What kind of a device is the 10.10.20.2 ??
is that an ASA or a Router ??
Cheers,
Nash.
11-15-2010 10:37 PM
Hi.......
10.10.20.2 this kind of divice is that an ASA.
Thanks.
11-15-2010 11:29 PM
On what interface is the 10.10.20.2 Ip address configured ??
Depending on the interface name,please add the following,
route "interface name" 172.16.10.0 255.255.255.0 10.10.20.1
For ex, if the 10.10.20.2 ip address is configured on the outside interface,
add
route outside 172.16.10.0 255.255.255.0 10.10.20.1
Cheers,
Nash.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide