11-17-2020 01:29 AM
hello there,
I created an ASAv on azure and wanna to test the anyconnect.
I using split-tunnel-policy tunnelall, So i expect the anyconnect client access internet via vpn tunnel.
after the config done, there has some issues:
anyconnect client only able to connect the internal network, it can ping all interface on ASA, but it lost the internet access.
it not able to access google, youtube etc....
no idea how whats wrong with my config. and I raised a ticket to azure and there said I should come to cisco.....
please give me a hint .... I attached the config ,the sensitive info has been removed:
thanks!!!!
Solved! Go to Solution.
11-17-2020 01:34 AM
Hi @ronald.su
Add the command same-security-traffic permit intra-interface to allow the traffic to hairpin back out the same interface it came in on.
HTH
11-17-2020 01:34 AM
Hi @ronald.su
Add the command same-security-traffic permit intra-interface to allow the traffic to hairpin back out the same interface it came in on.
HTH
11-18-2020 05:20 PM
oh ! you r right ! i forgot that!
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide