02-27-2023 02:31 PM
Hello.
In the most standard vanilla ASA-5525 split tunnel config, and also routing config...
when a www IP-address is added to the split-tunnel ACL, does that traffic hairpin out of the ASAs outside interface to the www, or does it traverse the LAN to different gateway?
Thank you.
Solved! Go to Solution.
02-27-2023 02:39 PM - edited 02-27-2023 11:58 PM
@jmaxwellUSAF both options are achievable.
You'd need to allow the traffic to hairpin with the command "same-security-traffic permit intra-interface" and create an auto nat rule with the source and destination interface of the outside interface.
To route via another another gateway, define a static route and append the keyword tunneled, this route would apply to decrypted vpn traffic only. Example: "route inside 0.0.0.0 0.0.0.0 x.x.x.x tunneled"
02-27-2023 02:39 PM - edited 02-27-2023 11:58 PM
@jmaxwellUSAF both options are achievable.
You'd need to allow the traffic to hairpin with the command "same-security-traffic permit intra-interface" and create an auto nat rule with the source and destination interface of the outside interface.
To route via another another gateway, define a static route and append the keyword tunneled, this route would apply to decrypted vpn traffic only. Example: "route inside 0.0.0.0 0.0.0.0 x.x.x.x tunneled"
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide