12-05-2007 01:31 PM - edited 02-21-2020 03:24 PM
Really appreciate for any thought about this problem?
After vpn in, a remote PC is assigned ip address 10.1.8.13 255.255.254.0 from the ASA. I did ipconfig on the pc and it shows default gateway is 10.1.8.1 The remote pc can access all internal subnets and able to ping the internal interface of the firewall 10.1.2.10 and both ip addresses of the vlan interface of the 6509 where the inside interface of the ASA plug to. that vlan interface has ip addresses 10.1.2.3 and 10.1.8.1 which is a secondary address
The problem is all internal devices including the ASA can NOT ping 10.1.8.13. The servers push some updates to the remote PC, but that does not work.
I turn off the firewall on the PC.
12-05-2007 05:24 PM
this sounds like a nat 0 issue.
access-list nat0_acl permit ip any 10.1.8.0 255.255.254.0
nat (inside) 0 access-list nat0_acl
do you have anything like that in your config?
is nat-control enabled (sh run nat-control)
12-28-2007 07:37 PM
Are you routing the network correctly on the 6509?
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide