cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
855
Views
0
Helpful
2
Replies

VPN tunnel Asymmetric routing

Izac ICT
Level 1
Level 1

Hello all,

I'm struggling to access some web servers from client VPN. I suspect that there is asymmetric routing since VPN device and web servers  are in the same VLAN on the switch and in the same security zone on the firewall.  Please see the below diagram.

 Gateway, VPN device, and web servers are in 10.10.10/24 subnet

VPN tunnel is on 10.112.124.0/24 and on the firewall there is a static route to VPN tunnel(10.112.124.0/24) via VPN device (10.10.10.18)

 

Do you think the return traffic is going via L2 on the switch? I'm really confused.

 

VPN-Topology-asy.JPG

 

Thanks.

Cheer,

Isac

2 Replies 2

Hello,

 

--> I'm struggling to access some web servers from client VPN.

 

Can you access the web servers at all ? Which IP addresses are your VPN clients getting ?

 

Post the configuration of the Cisco switch...

Hello Georg,

 

Web servers can be accessed from anywhere else except the client VPN.

VPN clients gets IP from this range 10.112.124.0/24.

 

Regards,

Isac

Review Cisco Networking products for a $25 gift card