11-20-2020 11:17 PM
Hello Team,
Please help me advise for my issue:
I have setup mobile VPN in Firepower 2130, there are few vlan 20,21,22 in FW for inside network. Among them, vlan 21 need to access internet and i do manual NAT under polices.
when my pc connected vpn, it cannot ping to vlan 21. if i remove NAT rule , i can ping to vlan 21 ip address. But i need vlan 21 to have internet access and want
Solved! Go to Solution.
11-21-2020 12:04 AM
You probably need a NAT exemption rule, to ensure traffic between VLAN21 and RAVPN network is not unintentially natted by another nat rule. This new nat rule would be placed above the dynamic nat rule you created for internet access.
Please provide a screenshot of your current nat rules.
11-21-2020 12:04 AM
You probably need a NAT exemption rule, to ensure traffic between VLAN21 and RAVPN network is not unintentially natted by another nat rule. This new nat rule would be placed above the dynamic nat rule you created for internet access.
Please provide a screenshot of your current nat rules.
11-21-2020 03:40 AM
11-21-2020 05:25 AM
HI Guys,
When i disable NAT rules (Internet access for VLAN 21), i able to ping it. I also suspect due to NAT rules.
But when i disable NAT Empet setting in VPN , this is no effect in testing.
i tested two NAT rules for internet access, one is manual NAT and one AUTO NAT (either one enable). but still not work(unpingable). Please help me advise what would be possible cause.
11-21-2020 02:18 AM
can you please share the NAT config here,
all NAT in ASA.
11-21-2020 03:41 AM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide