cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
480
Views
0
Helpful
1
Replies

AnyConnect VPN to multiple inside VLAN?

MARTIN DESAX
Level 1
Level 1

Hello,

We have an ASA 5020 8.4 with:

outside IF: public IP

inside IF 1: Management LAN 172.16.0.0/24  (Sec Level 99)

inside IF 2: VLAN2 10.0.50.0/24   (Sec Level 50)

inside IF 3: VLAN3 10.0.90.0/24   (Sec Level 50)

etc.

My AnyConnect VPN Client configuration:

VPN Access IF: outside IF

Bypass IF ACL.

Traffic between IF with same security level enabled.

VPN IP pool 172.17.0.80...99/24 (used only for the VPN clients)

NAT rules: IF1, IF2, IF3 to outside IF (VPN IP pool) no nat.

My workstation can connect to the ASA with the Anyconnect Client and I can access hosts on the inside IF 1: Management LAN 172.16.0.0/24

BUT I can't access any of the other inside IF/VLAN.

What is wrong with my configuration?

1 Reply 1

MARTIN DESAX
Level 1
Level 1

I think I've found the problem.

I had made NAT Rules but they were in the wrong order! I had the NAT rule which is needed for the Internet access before the NAT rules for the internal VPN traffic.