cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1192
Views
1
Helpful
13
Replies

VPN IP on ASA

Hi Members,

How to check where the Client to Site VPN IP is configured on ASA.I have gone through the running config but cannot see it

13 Replies 13

client to Site VPN ? can you more elaborate ??

FredrikW73
Level 1
Level 1

If you are looking for the IP-interface used for Remote Access VPNs then you can find it here:

Configuration tab/Remote Access VPN menu/Network (Client) Access/AnyConnect Connection Profiles/
Under this section you can define "Access Interfaces" used for SSL access or IPsec access.

I have checked these settings, dont find any IP configured ..

Actually i want to know where its configured which am not able to find.

The IP-address used for VPN is the address of the interface defined for use by VPN
(as found under "Access Interfaces" section mentioned above).

Find IP-adresses of interfaces here:
Configuration tab/Device Setup menu/Interface Settings/Interfaces

Cross-reference that IP-address info with the config of which interface is defined for use by VPN.

Hi,

I have chekced these settings cannot find that Public IP configured on any of the interface

Attaching the screenshot for your reference.

Client_VPN.jpg

Could be that your VPN-ASA is located behing another firewall doing NAT.

zenobia
Level 1
Level 1

If the Cisco AnyConnect window isn’t open: Click on the system tray icon, located near the date and time in the task bar

Click the advanced options button in the lower left corner of the VPN client window. The icon will look like a gear.

In the new window that opens, look in the Statistics tab under Address Information and the IP address provided by the VPN will be the line that reads “Client (IPv4).”

Barcode Label Maker by : https://www.barcodelabelmaker.org

Anyconnect.jpg

 

Here is the screenshot.

My Point is where is the VPN IP is configured on the ASA. For Site-Site VPN IP is configured on the Router. For Client VPN where its configured on the ASA.

The webvpn enable in interface this interface ip will be what anyconnect use as IP to vpn to asa.

The anyconnect have two ip

One public ip (not configurable) you can see it via 

Show vpn-sessiondb anyconnect

Other is private ip which is configured by 

1- pool' pool name appear under group policy/tunnel group and pool subnet appear in global mode of cli of asa 

2-dhcp server' it config appear under group-policy/tunnel group of anyaconnect 

That all ip anyconnect use.

Thanks all for your valuable inputs to help me out.

I have found the IP its not configured on any of the Firewall Interface. Its in the Router as per below. Can someone help me to understand the below command.

ip nat inside source static 172.17.17.250 94.201.95.252 extendable

 

which IP you found I explain that there are many IP, which one ?

"ip nat inside source static 172.17.17.250 94.201.95.252 extendable"

That is a statement for a static 1:1 address translation.

Traffic coming in with destination 94.201.95.252 is translated to 172.17.17.250
i.e. the final destination is the IP address of the interface with the name "outside" on your VPN-ASA.

There is nothing configured on the ASA. Below command is configured on the Router which i believe is for VPN Access, vpn IP is 94.201.95.252

ip nat inside source static 172.17.17.250 94.201.95.252 extendable

Review Cisco Networking for a $25 gift card