11-10-2017 01:55 PM - edited 03-12-2019 04:43 AM
Hi
I have cisco asa connected to cisco 887vaw router with dsl internet connection.
I have internet connection working on both. I have configured vpn IPsec on cisco asa, I can connect from inside but I can not connect from remote.
can you help please?
Solved! Go to Solution.
12-05-2017 02:01 PM
Hamid
I see this in the config
ip access-list extended LAN
permit ip any any
I suggest that you remove the permit any any from the ACL.
I wonder if anything shows up in the logs on the router when you attempt to start the VPN from an Internet source?
Perhaps it might show us something helpful if you turn on debug for address translation on the router and then attempt to start the VPN from an Internet source, and then look for any debug output.
HTH
Rick
12-06-2017 01:53 PM
Hi Richard
Thank you very much for your reply.
It is working with removing permit ip any any, but I loose internet connection for the router.
any solution for that please ?
Kind Regards
Hamid
12-06-2017 02:43 PM
12-07-2017 08:47 AM
Hamid
I am very glad to know that you have resolved this issue and that it is working.
HTH
Rick
12-06-2017 02:38 PM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide