cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
743
Views
7
Helpful
5
Replies

vpn client route

erikgrissom
Level 1
Level 1

Hi,

i have today a static vpn between site A and B that works fine, but when i vpn direct to site B and get a adress from the client vpn pool

i cant access site A.

i guess im missing a route on site A asa but dont really know how to fix it.

any help is appreciated.

Thanks.

1 Accepted Solution

Accepted Solutions

Luke Oxley
Level 1
Level 1
erikgrissom,

Thanks for your post. From your description, three things come to my mind.
1. As your VPN client address pool will differ from the internal subnet(s), you may not have included this subnet in your NAT exempt statement(s), so it'll be unable to traverse the site to site tunnel between Site-A and Site-B.
2. You have not permitted the client VPN pool subnet across the tunnel in the access control lists.
3. It could be a routing issue, however I highly doubt this, my money is on the issue being related to one of the above issues. Without seeing your configuration I cannot be sure.
Please have a look at the above points raised and check your configurations closely. Remember to check both sides, as the traffic needs to be allowed back in return from Site-A for this all to work.
If you are still having issues, please post a sanitised configuration (show run) from both Site-A and Site-B so I can get a better understanding of your environment. Hopefully we can resolve this fairly briefly.
I look forward to hearing back.

Thanks,
Luke


View solution in original post

5 Replies 5

Luke Oxley
Level 1
Level 1
erikgrissom,

Thanks for your post. From your description, three things come to my mind.
1. As your VPN client address pool will differ from the internal subnet(s), you may not have included this subnet in your NAT exempt statement(s), so it'll be unable to traverse the site to site tunnel between Site-A and Site-B.
2. You have not permitted the client VPN pool subnet across the tunnel in the access control lists.
3. It could be a routing issue, however I highly doubt this, my money is on the issue being related to one of the above issues. Without seeing your configuration I cannot be sure.
Please have a look at the above points raised and check your configurations closely. Remember to check both sides, as the traffic needs to be allowed back in return from Site-A for this all to work.
If you are still having issues, please post a sanitised configuration (show run) from both Site-A and Site-B so I can get a better understanding of your environment. Hopefully we can resolve this fairly briefly.
I look forward to hearing back.

Thanks,
Luke


Hi and thanks for trying to help me :-)

do you have any examples i can try?

the vpnpool im coming from is 10.10.7.0 and resides at network 10.140.7.0 were i have connected the vpn client.

//:Erik

Hey erikgrissom,

No problem, however you are going to have to help me out a bit more than that - otherwise I'm going at this blind.
I'd suggest double and triple checking as per my suggestions, if you cannot see anything untoward yourself then please post the sanitised configuration from both Site-A and Site-B.

Thanks,
Luke


Hi and thanks again,

your first reply got me on the right track.

i was missing a nat rule and after reading logs i also added the remote range to the static

vpn cryptomap.

//:Erik

erikgrissom,

Great, I'm please we got this sorted for you. Please remember to rate answers for content and mark them as correct :-)

Kind regards,
Luke Oxley


Review Cisco Networking for a $25 gift card