09-26-2018 09:12 AM - edited 09-26-2018 09:15 AM
I have a ASA5506 at my office and a guest from a different company is trying to connect to their VPN at their office but its failing to connect.
The VPNs i use going outwards all work fine with no ACLs or NAT (sophos VPN, cisco anyconnect) but theirs is windows VPN using L2TP.
I have set up ACLs and NATs to allow VPN traffic through before but that has only been my office side where people are VPN'ing in from their homes etc. This time its a user trying to VPN from my network out to their office (which I have no knowledge of apart from I have the IP address they are VPN'ing to)
I cant get my head around what way I do the NAT and ACLs for this to work.
I know i need to pass through/allow UDP 4500, 500, 1701 and IP 50 for L2TP but that's about it.
I also have a router outside of the firewall so im guessing i need to double nat as well.
any help would be appreciated.
09-26-2018 09:26 AM
09-26-2018 09:32 AM
09-26-2018 09:35 AM
09-27-2018 01:30 AM
10-01-2018 06:31 AM
This is config now and it doesnt work. Neither direction ACLs are getting hit.
access-list WIFI_access_in extended permit udp any any object-group L2TP
access-list WIFI_access_in extended permit esp any any
access-list WIFI_access_in extended permit IP any any
access-list WIFI_access_out extended permit udp any any object-group L2TP
access-list WIFI_access_out extended permit esp any any
access-list WIFI_access_out extended permit IP any any
access-group WIFI_access_in in interface WIFI
access-group WIFI_access_out out interface WIFI
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide