Heads Up :
The post you are writing will appear in a public forum. Please ensure all content is appropriate for public consumption. Review the employee guidelines for the community here.
We have one remote ipsec tunnel group, the clients' address pool use 172.18.33.0/24 which setup from "ip local pool" command. The remote cliens have to use full ipsec tunnel.Due to ip overlap or route issue, we would like NAT this local pool from 172...
We have a CSS11501 which do the load balance and SSL proxy for mail cluster. Mail servers behind CSS need originate traffic to outside through different tcp and udp ports. We setup source group which nat private ip adderss to public ip for outbound c...
I can ping the FWSM interface that is directly connected to my inside network, but I am unable to ping outside interfaces. All applications(like http, ssh etc) from inside network to outside works fine. I can also ping switch's vlan interface which c...
FedericoThanks for your reply!Yes, we want 172.18.33.0 nat to 192.168.3.0 when vpn clients access certain servers through asa outside interface. I am not sure if policy NAT can do this for vpn local pool.Due to complicated routing and other reason, w...
Gilles;Thanks for your reply! We haven't changed anything as I know. We had problem with UDP packets before. When backend servers tried connect to outside DNS servers through udp 53, we saw packet drop. We rerouted DNS traffic bypass CSS.This time ba...
We had same problem as you after we upgraded concentrator from 4.1.5.B to 4.1.7.F. Our Movian vpn client dropped connection after phase 1 completed.Did you find work around for your movian client or you downgrade concentrator's OS?Thanks