12-14-2022 10:55 AM
Hi,
I configured vpn ssl with anyconnect. When I connect to vpn from my remote host i can ping only Asa's outside interface. From inside i have static route to internal network and i can ping all internal resources. From outside I have static route to any and i can ping internal resources and internet. Firewall permit any any. I configured NAT rule :
My topology looks that :
Anyone know where looking for solution ?
Solved! Go to Solution.
12-16-2022 01:39 AM
i finded solution. i had to add rule on firewall permit icmp.
12-14-2022 11:20 AM
@lukaszhar what is the default gateway of the internal network? Is traffic routed to the ASA's inside interface?
Run packet-tracer from the CLI and provide the output for review.
Please provide your ASA configuration.
12-14-2022 11:59 AM
internal network's default gateway is mikrotik's interface. Everythink is working without asa. Im configuring it for testing anyconnect vpn ssl. From inside interface i have static route to internal network and i have access there. I dont have access only from remote host. I can ping only outside interface.
12-14-2022 12:04 PM
@lukaszhar do you have a static route for the RAVPN IP pool network on the mikrotik switch to the ASA's inside interface? Without it the mikrotik switch won't route the traffic of the RAVPN anyconnect user back to the ASA, hence why you cannot connect to the internal network when connected to the VPN.
12-14-2022 12:44 PM
i added this static and still the same ;/
12-14-2022 12:50 PM
Run packet-tracer from the CLI and provide the output for review.
Please provide your ASA configuration.
12-14-2022 01:33 PM
friend, I think the issue is in static route in Mikrotik
you use interface not next-hop IP in static route ? if yes use next-hop IP (ASA inside interface IP ) and check again
12-14-2022 02:15 PM
No changes ;/ still i can ping only outside interface
12-14-2022 02:23 PM
are you using split tunnel or tunnel all ?
12-14-2022 02:38 PM
tries both
12-14-2022 02:40 PM
when i try with split tunnel i cant even ping outside intervace
12-14-2022 04:12 PM
can you confirm what I note in your topology ?
12-15-2022 12:26 AM - edited 12-15-2022 12:26 AM
x.x. - everywhere the same value
12-15-2022 12:27 AM
12-15-2022 12:32 AM
@lukaszhar well its clear you have misconfigured NAT rule, can you provide your configuration as already requested? We can then review and determine what you have misconfigured.
If you don't wish to provide your configuration, here is an example NAT Exemption rule, which will ensure RAVPN traffic is not unintentially translated:
object network RAVPN
subnet 192.168.10.0 255.255.255.0
object network LAN
subnet 10.1.1.0 255.255.255.0
nat (INSIDE,OUTSIDE) source static LAN LAN destination static RAVPN RAVPN no-proxy-arp
Amend your subnets and interface names accordingly.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide