01-31-2024 02:47 PM - edited 01-31-2024 02:49 PM
Hello,
I've set up anyconnect on a 800 series router succesfully. VPN clients can reach LAN addresses fine. LAN clients can also reach VPN connected machines, except from the router itself.
They are on the same subnet (10.10.10.0/24). Tunnel mode is split include the whole internal subnet.
Is it possible at all to reach VPN clients from the router directly?
Many thanks!
01-31-2024 03:43 PM - edited 01-31-2024 03:43 PM
how is your VTY lines config does it have any access class ?
Ip access-list extended vpn-client
Permit ip x.x.x.x
Line vty 0 4
Access-class vpn-client in
02-01-2024 01:45 AM
Hello,
Thanks for the suggestion.
I've added the following but still cannot access the VPN client from the router.
ip access-list extended vpn-client
permit ip 10.10.10.0 0.0.0.255 any
line vty 0 4
access-class vpn-client in
transport input ssh
Best regards,
Andras
02-01-2024 02:08 AM
When you try to access to router via RA use any other interface except the one that use for VPN (the one that you use to establish VPN).
MHM
02-01-2024 05:47 AM
what IP address you trying to SSH (now we know VPN IP address range ?)
Try troubleshooting, open ASDM monitor the real time logs, and try to SSH from VPN IP and check ?
02-03-2024 06:06 AM
Anyconnect listens on Cellular interface (LTE router). When I connect via anyconnect (cellular pulbic IP) I got an IP from the defined VPN pool. (10.10.10.80 10.10.10.90). I can reach any local address including routers' 10.10.10.1 from the VPN client but from the router I cannot reach (ping,etc) the VPN connected devices. Other devices on the LAN for example the wifi AP (10.10.10.3) can ping the VPN connected device also.
02-03-2024 12:37 PM
I am bit confused here -
clarify you have issue from Remote Access VPN to ping to connected device
example VPN Server IP 10.10.10.1 - Client ip example 10.10.10.81 - this is not working ?
and you confirmed that you able to ping Client IP example 10.10.10.81 to Client IP10.10.10.90 - working ?
you need to post show run config here (to verify ) - or refer below document.
02-03-2024 01:46 PM
Can you try pinging the VPN client using ping with source interface the LAN interface?
 
					
				
		
02-01-2024 07:45 AM
Hello,
what do you mean by 'accessing the VPN clients from the router' ? What kind of access are you talking about ?
 
					
				
				
			
		
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide