06-25-2017 08:44 AM - edited 03-05-2019 08:45 AM
06-25-2017 11:13 AM
Hello,
can you draw your setup out and post it ? Inter-VLAN routing should happen at the core switch, not the ASA, only Internet traffic should go out to the ASA.
06-26-2017 01:53 AM
hello Georg,
I entirely agree that intervlan routing shoud happen on the core-switch.
Please find attached my setup.
For outgoing traffic (everything works fine):
- my internal Equipment has an IP 172.17.110.100 with Gateway 172.17.110.240 (core-switch)
- my core-switch has PBR enabled and forward the traffic (using set next-hop) to the ASA (172.17.110.254)
- the ASA forwards the traffic to the Internet
For incoming traffic (using remote VPN):
- my client has an IP assigned by a pool assigned by DHCP from the ASA)
- I can reach my ASA
- The problem is that my remote client cannot reach the internal LAN. The cause must be due to an asymetric route, the internal Equipment having a default Gateway of 172.17.110.240 and my ASA having an IP of 172.17.110.254.
Hope this helps,
Thierry
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide