cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1598
Views
0
Helpful
5
Replies

After anyconnect VPN is connected,i cannot ping to one of internal network

may.thu
Level 1
Level 1

Hello Team,

 

Please help me advise for my issue:

 

 I have setup mobile VPN in Firepower 2130, there are few vlan 20,21,22 in FW for inside network. Among them, vlan 21 need to access internet and i do manual NAT under polices.

when my pc connected vpn, it cannot ping to vlan 21. if i remove NAT rule , i can ping to vlan 21 ip address. But i need vlan 21 to have internet access and want

1 Accepted Solution

Accepted Solutions

@may.thu 

You probably need a NAT exemption rule, to ensure traffic between VLAN21 and RAVPN network is not unintentially natted by another nat rule. This new nat rule would be placed above the dynamic nat rule you created for internet access.

 

Please provide a screenshot of your current nat rules.

View solution in original post

5 Replies 5

@may.thu 

You probably need a NAT exemption rule, to ensure traffic between VLAN21 and RAVPN network is not unintentially natted by another nat rule. This new nat rule would be placed above the dynamic nat rule you created for internet access.

 

Please provide a screenshot of your current nat rules.

Hello.

 

Thanks for your reply. Kindly find current attached files for NAT rules.

HI Guys,

When i disable NAT rules (Internet access for VLAN 21), i able to ping it. I also suspect due to NAT rules.

But when i disable NAT Empet setting in VPN , this is no effect in testing.

i tested two NAT rules for internet access, one is manual NAT and one AUTO NAT (either one enable). but still not work(unpingable). Please help me advise what would be possible cause.

can you please share the NAT config here,

all NAT in ASA.

Hello.

 

Thanks for your reply. Kindly find current attached files for NAT rules.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: