09-13-2011 05:42 AM - edited 03-04-2019 01:35 PM
Firstly i hope this is in the right forum.
I have setup a cisco 877 router at our branch office and setup a vpn to our head office which works ok but the internet will only work if the vpn is on.
The vpn drops frequently at the moment so the branch office users are left without internet for a little while depending on how long it takes for the vpn to come back up which can take from a few seconds to a few hours.( another problem entirely).
I am assuming that i need split tunnelling which i thought i had setup but obviusly not.
I have attached the complete config of the router.
Could someone please have a look and see where i have gone wrong.
Many Thanks
Gareth
09-13-2011 07:10 AM
You are doing split tunneling but the ACL configured on Dialer0 is blocking inbound internet traffic.
09-13-2011 07:23 AM
I must have misunderstood the things i have read on the internet about blocking all inbound traffic from the internet.
I thought that when a session was initiated from the inside that a return path was automatically created.
Or do you mean i have blocked that aswell and if so can you tell me what i need to remove to allow it.
Thanks
Gareth
09-13-2011 07:41 AM
You can - but need to configure reflexive ACL
09-13-2011 08:49 AM
Thanks for the help Edison
Sorry for being a bit thick but to make my access list reflexive, if i have understood what i have just read, all i have to do is add reflect (name) to the end of the items that are already there and then create another extended access-list to evaluate the inbound traffic.
Thanks again
Gareth
09-13-2011 09:21 AM
Gareth,
This link explains the process better:
Keep in mind, traffic originated from the router such as routing protocols, IPSec tunnel, etc - can't be evaluated so you need to allow that traffic outside the reflexive list. The link above indicates an example on how EIGRP is allowed along with the reflexive list.
Please remember to rate helpful posts.
Regards,
Edison
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide