11-24-2008 04:30 PM - edited 03-11-2019 07:17 AM
Hello,
We currently have an ASA 5510 setup for remote VPN purpose only. My question is, is it better to run VPN-POOL on ASA with the same subnet of the INSIDE interface or have the VPN-POOL on a separate subnet. I notice if we have the POOL on the same subnet as the INSIDE interface then VPN client also receives the INSIDE interface include in their gateway address VPN adapter.
Example
Outside IP 192.168.0.1
Inside IP 192.168.100.1
VPN-POOL 192.168.100.50-192.168.100.100
Or
VPN-POOL 192.168.200.50-192.168.200.100
11-24-2008 04:41 PM
Always separate. Use the 200 pool.
11-24-2008 05:39 PM
If x.200 is the case then will disable split-tunneling still work? We would like to see all user traffic in and out on their pc. Thanks
11-24-2008 11:05 PM
it will work, but you cna t access your inside hosts
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide