02-13-2019 02:47 AM
Hello,
I have configured a new VPN. But the problem is that whenever I try to access this VPN, the Internet from the Computer would go down.
Thanks for the sincere reply.
02-13-2019 02:52 AM
Hi there,
It sounds like once the VPN is established all of your traffic non-local traffic is being sent to the ASA endpoint and hitting various polices.
If you want to maintain a local connection to the internet you will need to configure split-tuneling for the anyconnect VPN. This will allow you to specify which subnets you can reach via the VPN, everything else will leave via the local LAN gateway.
This is viewed as a security risk in most situations.
cheers,
Seb.
02-13-2019 10:26 PM
Thanks Seb,
Even if all the traffics are going to the ASA, I should have the Internet Connectivity by default.
I thought of configuring the split-tunnelling but abandoned the thought.
Anyway I will try to configure the split-tunnel and will see the output.
Regards,
Pankaj
02-13-2019 11:24 PM
Yes, you will still have internet connectivity, but the AnyConnect client will adjust you routing table as @Dennis Mink points out, which will send any traffic not destined to the local subnet (except the encrypted tunnel traffic itself) via the tunnel.
Once your traffic arrives at the ASA you will need to have the correct routing and firewall policy in place to allow access to the internet.
cheers,
Seb.
02-13-2019 04:00 AM
when on the VPN do a "print route" from a command prompt to see if you have a default route on the VPN
02-13-2019 10:20 PM - edited 02-13-2019 10:21 PM
Thanks Dennis,
I couldn't see any output while running (While on configured VPN) the command - "print route"-
02-14-2019 02:18 AM
looking at the machines routing table:
0.0.0.0 0.0.0.0 10.100.100.1 10.100.100.13 2 there is a default route, can you confirm, 10.100.100,x is the VPN interface;s IP address?
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide