07-08-2008 07:10 AM - edited 02-21-2020 03:48 PM
Hi - not sure how to do this so I hope you can help. I have a number of servers in a disaster recovery site that is at the other ond of a L2L VPN tunnel. Now on this end, I have users who VPN in to the ASA. The users can get everywhere except to the machines on the other end of the L2L tunnel. Let me know if you have any ideas. How can I route or allow traffic from users coming in on a remote access vpn tunnel to a server at the far end of an L2L tunnel? I can post a config if needed. Thanks!
07-08-2008 08:03 AM
You cannot do this is versions 6 and below, but the command you need is:-
same-security-traffic permit intra-interface
HTH.
07-08-2008 08:33 AM
08-05-2008 06:52 AM
Had to step away from this to deal with some other stuff, but now I am back. Ok, so I added that command but still cannot get to the DR site. Let me try to explain our setup. In the coporate HQ, we have an ASA 5520 (ASA - 1). Inside address 192.168.2.2. There is a L2L tunnel to an ASA 5520 in another state (ASA - 2) - inside address of that one 192.168.100.2. I have VPN user connect to ASA-1 and they get an address of 192.168.200.X. I need them to to be able to get to the servers behind ASA - 2 (192.168.100.X). The VPN users can get to everything else on our network (192.168.0.0, 10.0.0.0) but not the 192.168.100.0 subnet.
08-05-2008 06:59 AM
You need to add the interesting traffic to ASA 1.
access-list
..and ASA 2.
access-list
Also, nat exemption for ASA 2.
access-list
Also, be sure if you are split tunneling the vpn clients, that the 192.168.100 network is being tunneled.
08-05-2008 08:20 AM
ok, thanks I'll give that a shot.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide