09-19-2012 08:49 AM - edited 02-21-2020 06:20 PM
Hi,
I have ASA 5510 and configured client VPN or Annyconnect VPN, when I connect to the ASA remotely using anyconnect I am able to get IP address as configued, from Internal network I can ping and RDP that anyconnect VPN desktop, but the problem is from the remote anyconnect VPN client I am unable to access internal network, when I use ASA packet tracer and check traffic from internal to anyconnect pool of addresses it gives result ok, but when i use packet tracer to check traffic on outside interface from anyconnect address pool to internal subnet it always gives the packet is dropped at WebVPN - SVC, and I can find any where related configuration for that.
any one can help in this would be appreciated.
Thanks
09-19-2012 10:00 AM
Hi,
Do you have a NAT exempt rule for this traffic?
Thanks in advance.
Portu.
09-19-2012 10:07 AM
I have the NAT exempt rule that is why from internal to anyconnect client works fine , shoudl be there any other NAT exempt ??
09-19-2012 10:14 AM
Oh so you it works one way, sorry, did not catch that.
Any logs during the connection attempt?
Thanks.
09-19-2012 10:27 AM
any particuler logs I should look for, I did not check any. or is there any debug command i should enable at ASA side
09-21-2012 08:51 AM
Hi,
Please do the following:
1- logging buffered debugging
2- capture capin interface inside match ip anyconnect_pool netmask local_network netmask
Then have the clients access the network.
1- show log | inc anyconnect_assigned_ip
2- show cap capin
Let me know.
Thanks.
Portu.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide