Heads Up :
The post you are writing will appear in a public forum. Please ensure all content is appropriate for public consumption. Review the employee guidelines for the community here.
My setup - one hub (ASA 5505) with 3 L2L spokes. All L2L communication is working fine. I'm trying to setup remote access into the hub and then access the other spokes. I can connect to the hub and its local network via remote VPN - but cannot acc...
I have a MacOS X IPSec client that isn't receiving the split-dns setup from my ASA 5505.Here's the relevant data from my ASA device:group-policy vpnpolicy attributes wins-server none dns-server value 192.168.1.3 vpn-tunnel-protocol IPSec l2tp-ipsec s...
Our central office has a VPN 3005 and a PIX 515. The VPN 3005 is the hub for 7 branch offices/spokes - each of which has a PIX 506e. The PIX 515 serves as the firewall for the cental office.From what I can tell, the ASA devices don't suffer the sam...
I've had a VPN 3005 concentrator running in my office for a little over a year without any issues. In the last couple of days, it has started to spontaneously restart itself every couple of minutes (ususally). Every now and then it will stay up for...
I'd like to have a traditional hub/spoke VPN design with a VPN 3005 concentrator as the hub and PIX 506e firewalls as the spokes.Everything has been working nicely - from spoke to hub and vice versa. However, I can't seem to ping from spoke-to-spoke...
If you see the config I posted, I already have those entries. Obviously, I already have the 'same-security-traffic permit intra-interface' enabled to allow hairpinning. Otherwise, my spoke-to-spoke communciation wouldn't be working.I also already h...
I'm not quite sure I understand. My home ISP is assigning me two DNS servers - 69.94.156.1 and 151.164.8.201. My corporate DNS server - as configured by my VPN settings on the ASA - is 192.168.1.3. There is no overlap between my split-tunnel list ...
Yes, I'm well aware of the limitations of the v6.x software. My 515 won't support v7.x without hardware upgrades, which is why I was asking about the ASA. If I get an ASA 5510 as a replacement for my PIX 515, would it also eliminate my need for the...
Heavy traffic isn't an issue - I have a max of 8 simulanteous connections (LAN-to-LAN), and I'm barely tickling the throughput/CPU gauges. Don't recall if I mentioned this in my first post, but I took the unit out of production and set it up in an i...
Simply switching the match address statement back to my wan_acl access-list seems to have solved the problem. I could have sworn I'd attempted it before, but maybe there was another setting or two that I've tweaked since then. Don't know, but here'...