cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
238
Views
0
Helpful
2
Replies

VPN's through ASA need to be pushed inbound to filter server?

whiteford
Level 1
Level 1

Hi,

I was wondering how others do this, but I have got users/offices going through my Cisco Concentrator. However I want to move these off and onto our Cisco ASA.

The problem is I need to monitor users internet traffic which is on a server inside (Surf Control), this works for the Concentrator as users come in and go via the ASA firewall and out, along the way the traffic is caught be the web filter server. The ASA is doesn't do this, as the VPN traffic comes into the ASA and straight out again to the internet.

How can I get round this?

2 Replies 2

aghaznavi
Level 5
Level 5

Identify the port and enable or rechange the class map , policy map in your device depends up on your requirements.

Well all I need to do is forward inbound VPN traffic internally then backout again to get monitored by our Surfcontrol/websense server. Have you used the route tunneled command?

eg

route inside 0.0.0.0 0.0.0.0 1.2.3.4 tunneled