01-30-2025 05:07 PM
I recognize that this is probably poor site design but it's what I have to work with.
I have a main office with subnet 192.168.15.0/24.
There's a site to site VPN with a partner site (I don't own the firewall on their side) with subnet 10.2.22.0/24. There are no issues with users accessing resources on each side.
I have users connecting to my main site with Secure Client. Here's where I think the problem is. They are issued IP addresses in the same range as the main site users so 192.168.15.0/24.
The remote users can access the main site resources fine but they cannot reach any of the resources on the other side of the site to site tunnel.
Is there any way that I can fix this without creating a new address pool for the Secure Client users? The reason is that I don't own that firewall on the other end of the site to site tunnel and it is difficult for me to get them to add a new subnet to their rules.
I have that command "same-security-traffic permit intra-interface" on my main site firewall. Not sure I needed it though.
Thanks
Solved! Go to Solution.
01-30-2025 05:31 PM
01-30-2025 05:31 PM
Have you consider to use NAT?
01-30-2025 05:34 PM
To be honest I'm not very good at Cisco stuff. I inherited the infrastructure and I'm able to get around a bit.
Can you give a brief idea of how NAT would work in this scenario?
01-30-2025 05:46 PM
Sure. What firewall do you have and which IOS version It runs?
01-30-2025 05:49 PM
My main site has an FPR1010. Software is 9.19(1).
01-30-2025 06:07 PM
I figured it out
I read something about nat exemption and created a rule (using ASDM because my CLI skills are poor) and traffic is flowing now.
Thank your help. Your hint about NAT helped me.
01-31-2025 12:24 AM
Glad to hear Man. I would suggest the same thing.
You rock It.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide