cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
365
Views
1
Helpful
6
Replies

[FTD] Mgmt Tunnel not getting routes or showing IP's in vpn-sessiondb

Monadnock
Level 1
Level 1

Hi all, 

  I staged a management tunnel for AnyConnect on my FTD and I'm able to authenticate to it via machine cert at my Windows Login. The issue is that it doesn't seem to have connectivity into my environment. I see that users are getting IP's from the pool in the FMC User Access Dashboard:

Monadnock_0-1708460198554.png

But strangely, I cannot ping any of those IP addresses, and even stranger is that the FTD does not have routes to this pool in its routing table. (the .240 addresses are the non-mgmt prod tunnel pool)

Monadnock_2-1708460284440.png

Monadnock_1-1708460260072.png

 

The final weird part is that the show vpn-sessiondb anyconnect shows users in the group policy but no "assigned IP address" section as they do with our prod vpn pool.

 

 

6 Replies 6

the route with "V" is for anyconnect Users 
so the FTD add  route to RIB 
for ping from which IP you ping ?
MHM

 I know that. My whole point is that V routes aren't showing up for the proper pool. 

MHM

No. The pool is .239 that I am referring to. 

Correct' can yoh check the gateway IP in user dashboard' are the gateway IP is for this ftd  

If fmc mgmt multi ftd you can see vpn of other ftd not this one.

Can yoh check 

Thanks 

MHM

 Confirmed they are getting the right gateway. Not multi mgmt ftd.