cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
394
Views
5
Helpful
5
Replies
Highlighted
Beginner

ASA L2TP/IP Sec VPN users unable to use Internet.

Dear Team,

I have using Cisco ASA I have configured L2TP/IPsec VPN, Users able to connect from out side network and able to reachable Inside Network but VPN users unable to use internet. 

When I will untick network gateway under VPN setting I will able to use internet but not reachable form inside network.

I have note that internet is working form my local network not going through VPN & CISCO ASA. 

Can some one guide to resolved issue ASA

2 ACCEPTED SOLUTIONS

Accepted Solutions
Highlighted
VIP Mentor

Hi @sachinc01 

 

Try adding this NAT:

 

object network NETWORK_OBJ_10.84.37.192_26
nat (GTMH_Outside,GTMH_Outside) dynamic interface

If this doesn't work please run a packet-tracer from the CLI and provide the output for review.

 

HTH

View solution in original post

Highlighted
VIP Mentor

In your packet-tracer example the traffic does not appear to be hitting the NAT rule provided in the example above. It is matching another NAT rule. Try temporarily removing the NAT rule for testing, e.g.

 

no nat (GTMH_Outside,GTMH_Outside) source static any any destination static NETWORK_OBJ_10.84.37.192_26 NETWORK_OBJ_10.84.37.192_26 no-proxy-arp 

....or amend this NAT rule and replace "any any" and be more specific with the source network

 

Make the change and test again

View solution in original post

5 REPLIES 5
Highlighted
VIP Mentor

Hi @sachinc01 

 

Try adding this NAT:

 

object network NETWORK_OBJ_10.84.37.192_26
nat (GTMH_Outside,GTMH_Outside) dynamic interface

If this doesn't work please run a packet-tracer from the CLI and provide the output for review.

 

HTH

View solution in original post

Highlighted

Dear Sir,

 

Thanks for help I have run below command  for VPN Users 

ciscoasa(config)# object network dial
nat (GTMH_Outside,GTMH_Outside) dynamic interface

PFA packet tracer,

I have untick on VPN setting (default gateway on remote network )but my traffic gong through Local Network to reach internet

but no access inside network through VPN,

When untick I able to reach inside network but VPN users  no internet access

Highlighted

Dear Sir,

 

I was done config but issue not resolved yet I have send Packet tracer report please check and revert.

Highlighted
VIP Mentor

In your packet-tracer example the traffic does not appear to be hitting the NAT rule provided in the example above. It is matching another NAT rule. Try temporarily removing the NAT rule for testing, e.g.

 

no nat (GTMH_Outside,GTMH_Outside) source static any any destination static NETWORK_OBJ_10.84.37.192_26 NETWORK_OBJ_10.84.37.192_26 no-proxy-arp 

....or amend this NAT rule and replace "any any" and be more specific with the source network

 

Make the change and test again

View solution in original post

Highlighted

Dear Sir,

 

Thanks a lot Issue has been resolved :):)

Thanks for grate Support !!!!!

Now I want to allow 4 Website to VPN users & other side need to block how to do this please guide,

Or shared link how to do this.

 

Regards,

Sachin