cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
43041
Views
15
Helpful
30
Replies
Highlighted

Re: object network Remote_Subnet

I have to update with this simple comment because sometimes the simple things get you in the end.  In my case I had everything setup correctly.  Nat exempt, split tunneling allowed access to all required networks, and even a nat rule:

nat (inside,outside) source static any any destination static AnyConnect_Pool AnyConnect_Pool no-proxy-arp route-lookup

 

ASA# show ip
System IP Addresses:
Interface Name IP address Subnet mask Method
GigabitEthernet1/1 outside x.x.x.x 255.255.255.255 CONFIG
GigabitEthernet1/2 inside 10.110.0.1 255.255.255.240 CONFIG
GigabitEthernet1/3 office 10.110.10.1 255.255.255.224 CONFIG

 

The problem is the NAT rule, I was able to connect to anything on the inside interface, but because there was a rule that said inside,outside I couldn't get to the office network.  Changed the rule to:

nat (any,outside) source static any any destination static AnyConnect_Pool AnyConnect_Pool no-proxy-arp route-lookup