10-17-2018 07:48 AM - edited 02-21-2020 09:29 PM
Hi all,
I'm experiencing some VPN connection issue on my Cisco ASA 5515.
Some days ago there was a problem with my ISP and I was forced to create a secondary outside interface (OUTSIDE2), on a different ISP connection.
I changed the default route and all was fixed.
When the first ISP was up, I tried to use both internet connections, with apparently no issues at all (unless I set the right routing of course).
But I got some issue when I tried VPN Remote access. I was able to connect using both public IP address but traffic is not working when I use the first ISP connections (right now the second ISP connection is the default route).
I checked the logs but no deny, no error logs, nat exempt is ok, routing is ok, nothing at all.
It simply doesn't work when I use the connection that is NOT used for default route.
Any hints?
10-17-2018 12:48 PM
post the full configuration to look.
10-18-2018 12:07 AM
Hi balaji,
unfortunately I can't, due to our internal security policies :-(
10-18-2018 01:01 AM
we can only suggest at this stage to look ACL and routing.
10-18-2018 01:23 AM
that's what I did for hours.
My first suspect is the default gateway.
Right now I have 2 default route.
First one points to one ISP and has metric with 10.
Second one points to second ISP and has metric with 20.
I just made a test, fixing the routing so that the public ip address of remote clients is routed vs OUTSIDE1.
This way, I have no issues, so it seems there's no "dynamic" routing.
10-19-2018 07:50 AM
Have you looked PBR as an option.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide