cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
461
Views
5
Helpful
1
Replies

ASA strange code (for Anyconnect?). Please explain...

May you please explain the relevance of this code, perhaps for the Anyconnect logic?...

object network VPN-Pool
nat (Outside,Outside) dynamic interface

...and this...

nat (Outside,Outside) source static VPN-Pool VPN-Pool destination static VPN-Pool VPN-Pool no-proxy-arp route-lookup

Thank you!

1 Accepted Solution

Accepted Solutions

@jmaxwellUSAF 

object network VPN-Pool
nat (Outside,Outside) dynamic interface

This allows full tunnel anyconnect RAVPN user traffic that is routed back to the ASA to be natted, to access the internet.

nat (Outside,Outside) source static VPN-Pool VPN-Pool destination static VPN-Pool VPN-Pool no-proxy-arp route-lookup

NAT Exemption rule, that allows anyconnect VPN-Pool networks to communicate with each other - without unintentially being translated. Essentially, this NAT rule is translating VPN-Pool network to itself.

View solution in original post

1 Reply 1

@jmaxwellUSAF 

object network VPN-Pool
nat (Outside,Outside) dynamic interface

This allows full tunnel anyconnect RAVPN user traffic that is routed back to the ASA to be natted, to access the internet.

nat (Outside,Outside) source static VPN-Pool VPN-Pool destination static VPN-Pool VPN-Pool no-proxy-arp route-lookup

NAT Exemption rule, that allows anyconnect VPN-Pool networks to communicate with each other - without unintentially being translated. Essentially, this NAT rule is translating VPN-Pool network to itself.