06-01-2011 12:51 PM
I've setup several ASA's with Anyconnect based SSL VPNs, but I've never been able to ping an IP address that has been assigned to the remoted in user. Should I be able to ping the remoted in user? Do I need to configure anything in group policy or user attributes to enable this?
Newt
Solved! Go to Solution.
06-01-2011 02:24 PM
Newt,
Absolutely, you will be able to ping the RA client when he/she connects, if the client is able to ping your internal resources but the connection does not work the other way then most likely the firewall of the RA client is blocking those packets. Most of the software firewalls including the Windows Firewall drop unsolicited incoming traffic that does not correspond to either traffic sent in response to a request of the computer (solicited traffic) or unsolicited traffic that has been specified as allowed (excepted traffic).
Regards.
06-01-2011 02:24 PM
Newt,
Absolutely, you will be able to ping the RA client when he/she connects, if the client is able to ping your internal resources but the connection does not work the other way then most likely the firewall of the RA client is blocking those packets. Most of the software firewalls including the Windows Firewall drop unsolicited incoming traffic that does not correspond to either traffic sent in response to a request of the computer (solicited traffic) or unsolicited traffic that has been specified as allowed (excepted traffic).
Regards.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide