02-20-2024 12:20 PM
Hi all,
I staged a management tunnel for AnyConnect on my FTD and I'm able to authenticate to it via machine cert at my Windows Login. The issue is that it doesn't seem to have connectivity into my environment. I see that users are getting IP's from the pool in the FMC User Access Dashboard:
But strangely, I cannot ping any of those IP addresses, and even stranger is that the FTD does not have routes to this pool in its routing table. (the .240 addresses are the non-mgmt prod tunnel pool)
The final weird part is that the show vpn-sessiondb anyconnect shows users in the group policy but no "assigned IP address" section as they do with our prod vpn pool.
02-20-2024 12:24 PM
the route with "V" is for anyconnect Users
so the FTD add route to RIB
for ping from which IP you ping ?
MHM
02-20-2024 12:25 PM
I know that. My whole point is that V routes aren't showing up for the proper pool.
02-20-2024 12:31 PM - edited 02-20-2024 12:43 PM
MHM
02-20-2024 12:37 PM
No. The pool is .239 that I am referring to.
02-20-2024 01:08 PM
Correct' can yoh check the gateway IP in user dashboard' are the gateway IP is for this ftd
If fmc mgmt multi ftd you can see vpn of other ftd not this one.
Can yoh check
Thanks
MHM
02-21-2024 06:15 AM
Confirmed they are getting the right gateway. Not multi mgmt ftd.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide