05-24-2011 11:26 PM
Dear all,
please if some one know about how enable the internet whenever we want to connect to by VPN clinet not by enabling the split-tunnel i want to have everything be possible by VPN conection of Corproate network, such internet and local.
i have two ASA5520 one is for VPN only next one is for outside internet,
please i'm waiting for you repsond ASAP.
thanks
zubair
Solved! Go to Solution.
05-24-2011 11:34 PM
Yes, you can configure tunnel default gateway so that all VPN traffic after being decrypted on the ASA gets routed to a particular hop.
route inside 0.0.0.0 0.0.0.0
So if your ASA inside interface that terminates the VPN is in the same subnet as the ASA inside interface that provides the Internet access, then the next-hop ip address on above route would be the ASA inside interface that provides the Internet access.
The ASA that provides the internet access also needs to be configured with route for tohe VPN Client pool subnet so that it gets routed to the ASA that terminates the VPN.
Hope that helps.
05-24-2011 11:34 PM
Yes, you can configure tunnel default gateway so that all VPN traffic after being decrypted on the ASA gets routed to a particular hop.
route inside 0.0.0.0 0.0.0.0
So if your ASA inside interface that terminates the VPN is in the same subnet as the ASA inside interface that provides the Internet access, then the next-hop ip address on above route would be the ASA inside interface that provides the Internet access.
The ASA that provides the internet access also needs to be configured with route for tohe VPN Client pool subnet so that it gets routed to the ASA that terminates the VPN.
Hope that helps.
05-25-2011 12:53 AM
thanks thanks thanks alot it's really working fine
gread day a head!!!
zubair
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide