cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
410
Views
0
Helpful
4
Replies

Cannot connect to other vpn clients (ASA)

HHeydarov
Level 1
Level 1

Hi friends.

I have a cisco ASA 5520 device configured with IPsec remote access VPN (ASA version 9.0)

I can connect INSIDE and DMZ network, but not able to access other clients connected to same VPN.

For example if I have 2 clients connected to VPN,(172.16.66.21 and 172.16.66.22) these both clients are not able to communicate with each other.

How can I fix this problem?

Thanks in advance.

1 Accepted Solution

Accepted Solutions

Aditya Ganjoo
Cisco Employee
Cisco Employee

Hi,

You need to configure same-security-traffic permit intra-interface on the ASA.

Also in the split tunnel ACL you need to add the VPN pool.

Regards,

Aditya

Please rate helpful posts and mark correct answers.

View solution in original post

4 Replies 4

Aditya Ganjoo
Cisco Employee
Cisco Employee

Hi,

You need to configure same-security-traffic permit intra-interface on the ASA.

Also in the split tunnel ACL you need to add the VPN pool.

Regards,

Aditya

Please rate helpful posts and mark correct answers.

Dear friend,

I have already configured same-security-traffic permit intra-interface on ASA and split tunnel standart access-list.

Hello,

You need to no-nat VPN traffic for communication client-client.

Example:

object network VPN-POOL
subnet 10.0.0.0 255.255.255.240
nat (OUTSIDE,OUTSIDE) 1 source static VPN-POOL VPN-POOL destination static VPN-POOL VPN-POOL

//Cristian

HHeydarov
Level 1
Level 1

can anybody help me?

Review Cisco Networking products for a $25 gift card