cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
731
Views
2
Helpful
4
Replies

Cisco Firepower Anyconnect failuer

saids3
Level 1
Level 1

Anyconnect is not able to connect to the server error!!

Firewall in BVI mode -  

 

 

1 Accepted Solution

Accepted Solutions

The nat rule of anyconnect is wrong. you need to exempt the vpn pool and the local subnet in order to reach the resource behind the Firewall. the rule you have it wont all you to connect the vpn AC behind the firewall.

your nat rule should be in this order. I am writing the ASA code as I dont have FTD so you can work it around.

nat(inside,outside) source static local-network local-network destin static vpn-pool vpn-pool no proxy arp route-lookup.

 

 

please do not forget to rate.

View solution in original post

4 Replies 4

Your failure description is quite vague ...

But at least you have to make sure that the NAT-exemption rule is above the general internet rule. And I would configure this in the same logic as the "normal" NAT rule: From "any" to "outside". 

I'm sorry for the lack of information! 

I'm trying to VPN my office from ouside network like a cafe or any other source wifi! I'm not able to get this right!! 

@Karsten Iwen @Sheraz.Salim  @Rob Ingram This is what happened when I shift anyconnect nat to the top - 

1. I can connect through anyconnect working perfectly but the second nat will stop working (OPEN-DSM). 

2. I can't ping my inside network like 10.206.167.111 

The nat rule of anyconnect is wrong. you need to exempt the vpn pool and the local subnet in order to reach the resource behind the Firewall. the rule you have it wont all you to connect the vpn AC behind the firewall.

your nat rule should be in this order. I am writing the ASA code as I dont have FTD so you can work it around.

nat(inside,outside) source static local-network local-network destin static vpn-pool vpn-pool no proxy arp route-lookup.

 

 

please do not forget to rate.
Review Cisco Networking for a $25 gift card