cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
304
Views
0
Helpful
5
Replies

Cisco FPR-1010 ASDM vpn Full Tunneling

AndersMattsson
Level 1
Level 1

Hi guys!

I'm pretty new to Cisco routers and learning alot from configuring a Firepower 1010. At the moment I can't use CLI as the router is in another place. I would benefit from doing this through ASDM since I'm using VPN to get to the server which manage the Cisco router. VPN split-tunneling is working, but we need to get full tunneling to work. I can reach and configure it from distance and can use CLI commands through ADSM if needed. Everything works perfect with the VPN and Split-tunneling, but as mentioned, can't get all traffic through. Any pointers? I can get screen shots later if needed.

The guide I've used amongst others is Configure AnyConnect Management VPN Tunnel on ASA - Cisco

The configuration is below.

Installed through VPN Wizard for Secure Client

External (named A3_WAN) 212.85.71.xxx

Internal VLAN (named AH_LAN) 192.168.0.100 - 192.168.0.200

VPN pool (named VPN_Pool) 192.168.250.1 - 192.168.250.254

The Group policy configured to use the VPN_Pool, correct DNS server 192.168.0.250 (Internal server), doesn't use WINS.

Tunneling All Traffic

I'm certain that my problems lays within NAT and/or ACL, ACE.

What would be the correct way to get this to work with full tunneling. Tried several guides and the setup looks ok, but never works as full tunneling, always missing out on Internet access through VPN.

Thanks in advance!

/ Anders

5 Replies 5

You have asa behind router and you use anyconnect' and you want full tunnel?

MHM

Hi,

Yes, I think it´s now called Secure Client, but yes!

We use a Firepower 1010 ASA and want to use ASDM to configure it.

AndersMattsson
Level 1
Level 1

Anyone has an idea? Really can't figure out what's the problem here...

AndersMattsson
Level 1
Level 1

Figured it out. Missed out on

object network VPNgrp

   subnet 192.168.250.0 255.255.255.0

   nat (outside,outside) dynamic interface

 

Then it worked!

Why you want to use full tunnel ?

If the asa behind router ?

MHM