08-27-2009 01:17 AM
Hello,
When I log in thru ASA Remote Access VPN via VPN client, I hvae a new IP assigned but the default gateway is blank. Why is it so ?
Solved! Go to Solution.
08-28-2009 03:13 AM
Voila!!!
Worked. It was the route on the ASA.
But tell me one thing, how does the routing table in ASA(VPN) affect the connected host. Since the host is already connected with CAT65K as the default gateway and CAT65's routing table should only be relevant.
08-28-2009 03:17 AM
Well the ASA still needs to route the traffic to and from the host. If the ASA has a default route point out to the internet, and no internal routes - it does not matter of the cat has routes or not, even with directly connected vlans.
08-28-2009 04:37 AM
Hi Andrew,
If I were to add one more ASA in the front so that the topology now becomes
ASA -> ASA -> Host -> CAT65K -> FWSM -> Target Host
where should the VPN be ideally terminated. Should it be the first ASA or the second.
08-28-2009 05:02 AM
I personally terminate VPN's on ASA's that already sit behind another firewall.
Protects your VPN device from attempted DoS attacks.
08-28-2009 12:12 PM
In my case the second ASA has AIP-SSM module.
Should I pass the VPN traffic to the IPS module ? If so then how should it be defined in the class-map for IPS traffic.
08-28-2009 01:13 PM
Why would you want to pass the VPN traffic thru an IPS - you know the VPN traffic is OK, as it's from configured peers?
08-28-2009 01:19 PM
Ok. If I were to avoid it how could it done. Because the traffic coming from internet onto the same segment in currently being scanned.
And the VPN traffic for remote management is also connected to the same segment. How can I exempt the VPN traffic from being sent to AIP-SSM.
Secondly, is it safe from security perspective to allow internet access while the host is connected over the VPN (split tunnel) to corporate network.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide