cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
747
Views
0
Helpful
1
Replies

Hairpinning not working

kkasanto
Level 1
Level 1

We recently retired an old Cisco ASA5510 firewall and the old VPN Client - and installed a Cisco 5508-X firewall instead. We have a few L2L Vpn connections going in to the box, and they work well, also we use Anyconnect for client connectivity. We need these remote network to be accessible from the VPN client, and even though i have set the same-security-traffic settings and made sure the remote networks are in the Secured routes on the client - it does not work.

 

The hairpinning worked on the old setup, so i am pretty sure things are correctly set from the remote networks, and i suspect something in the new box to be wrong.

 

Any ideas i can look for ?

 

Kenneth Karlsson

1 Reply 1

Run packet trace to see how traffic getting through ASA. You need to run
while VPN SAs are active to see the traffic. Use decrypted keyword to
simulate IPSec decrypted packet
Review Cisco Networking for a $25 gift card