cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1286
Views
3
Helpful
2
Replies

Anyconnect - VPN client local network overlap with split-tunnel injected route

Tzy Chun Chong
Level 1
Level 1

Hi Security Expert,

I got a VPN client office using 192.168.14.0/24 network. Once they established the Anyconnect vpn connection to the main office, they're unable to access to their own local 192.168.14.0 servers and printers. I've check our VPN split-tunnel ACL is actually injecting the generic 192.168.0.0/16 network to the client, that causing their windows lost their own windows route 192.168.14.0/24 point to its own NIC interface.

This looks like overlapping of subnet 192.168.14.0/24 from the client office which fall under the generic injected split-tunnel route 192.168.0.0/16.

How can we tackle this issue instead of requesting the client office to change their IP segment away ?

Appreciate the idea and i will rate for helpful response. Thanks.

Regards

Tzy

2 Replies 2

Shakti Kumar
Cisco Employee
Cisco Employee

Hi ,

I guess you are looking for below solution

http://www.cisco.com/c/en/us/support/docs/security/asa-5500-x-series-next-generation-firewalls/70847-local-lan-pix-asa.html

Please mark correct if usefeul

Thanks

shakti

Partially related but it never told how to tackle overlapping issue... I still rate your helpful share, thanks.