06-03-2025 05:43 AM
Hello Guys,
I need Help with my case,my device is FPR 1140 and i want connect it to AWS,I have done this step
2. NAT exempt for the AnyConnect traffic to the remote subnet.
3. Add your AnyConnect subnet to the Site 2 Site VPN crypto ACL at both ends of the Site 2 Site VPN.
4. Add split tunneling remotesubnet to the split tunnel ACL.
and now got the problem, my Traffic RAVPN & LAN overlapping, i already config NAT Exempt for both RAVPN and LAN to the remote subnet,when i enable both NAT Exempt,Either the Traffic RAVPN to aws is UP or the LAN UP , i need to do "Clear Crypto ikev1 sa" after try to Change/troubleshooting the configuration to check the traffic is up or not.need help,Thank You
06-03-2025 07:45 AM
What do you mean by overlapping? is AnyConnect pool part of your LAN subnet?
06-03-2025 08:58 AM
I mean when i enable both nat exempt Ravpn subnet and Lan subnet, one of these traffic will go down and other wil go up to remote site subnet, anyconnect pool is not part of my LAN subnet
06-03-2025 10:08 AM
Would you mind sharing your sanitized configs for review?
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide