06-24-2008 07:36 AM - edited 03-11-2019 06:03 AM
I have a vpn tunnel between a asa 5510 and a pix 506. I have the tunnel established. From the 506 I can access devices thru the tunnel. But on the 5510 side the inside acl is blocking traffic even though I have the interesting traffic exempt from the nat. Any ideas on why this would happen?
06-24-2008 08:06 AM
add a command sysopt connection permit-vpn
06-24-2008 08:49 AM
That's already enabled. I have 3 other vpns working currently.
see attached.
06-24-2008 09:03 AM
06-25-2008 01:11 AM
First thought is that the last line of the nat access list should be removed.
access-list inside_nat0_outbound extended permit ip 192.168.0.0 255.255.0.0 10.17.132.0 255.255.255.0
I think it conflicts with the SPRINGS-VPN acl
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide