cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
312
Views
0
Helpful
2
Replies

ASA5505 Hairpinning

Adam Campbell
Level 1
Level 1

I have an ASA5505 version 9.0(3).  I want to hairpin traffic destined for the internet for my VPN clients.  The clients come in the same interface that they will need to go out for internet access.  I have already seen the same-security-traffic permit intra-interface command and have tried this and still nothing.  VPN clients are able to connect just fine and access all internal resources they are just unable to access the internet after connecting.  Help.

1 Accepted Solution

Accepted Solutions

Marvin Rhoads
Hall of Fame
Hall of Fame

Please refer to the configuration in this TAC document.

One key point you need is a NAT rule (outside,outside) for the VPN pool.

View solution in original post

2 Replies 2

Marvin Rhoads
Hall of Fame
Hall of Fame

Please refer to the configuration in this TAC document.

One key point you need is a NAT rule (outside,outside) for the VPN pool.

That was it.  Thanks Marvin!!