01-01-2014 04:33 AM - edited 02-21-2020 07:25 PM
Hello Dear Group
I have as ASA 5510 is configured for Remote Access VPN, ASA authenticates Remoter Clients with Radius Server (Accounting Software) and will Assigne an IP Address from VPN-Pool (172.16.20.0/24) . All prose in authentiction use with radius server is successful, but there is no any iternet browsing on client side. I have configured a Dynamic NAT Rule on outside ASA interface as I write in the below :
Interface : Outside
Source : VPN-Users Object (Address Pool 172.16.20.0/24)
Translate to Outbound interface.
the NAT Rule in above doesn't work. ( I think traffice is not returing to VPN POOL Address via outside interface)
Note : this VPN Users have to access to INTERNET only. (because of that the range of pool address is different with Inside Network Interface)
Its a favor if you help me how to NAT .
Thank You
Best Regards
Solved! Go to Solution.
01-01-2014 06:42 AM
Hi,
Would really need to see your current NAT configurations in CLI format to determine the problem.
Naturally the problem might be as simple as missing the following command on the ASA
same-security-traffic permit intra-interface
This command is required on the ASA for traffic to come through an interface and leave through the same interface. In your case this interface would be the "Outside" as the VPN Client traffic is coming to the ASA through that interface as is trying to leave through that interface towards the Internet.
- Jouni
01-01-2014 06:42 AM
Hi,
Would really need to see your current NAT configurations in CLI format to determine the problem.
Naturally the problem might be as simple as missing the following command on the ASA
same-security-traffic permit intra-interface
This command is required on the ASA for traffic to come through an interface and leave through the same interface. In your case this interface would be the "Outside" as the VPN Client traffic is coming to the ASA through that interface as is trying to leave through that interface towards the Internet.
- Jouni
02-08-2014 11:27 AM
Thank You
Sent from Cisco Technical Support iPad App
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide