[Last Call] Learn about multicloud storage options and how to improve your company's cloud strategy. Register Now

x
?
Solved

Cisco VPN client cannot reach other remote networks through tunnel

Posted on 2008-10-14
3
Medium Priority
?
321 Views
Last Modified: 2012-05-05
Hi all,

I have a Cisco ASA5510 firewall running v7.0(7) which has a Lan 2 Lan VPN with our American office. All users on both Lans can access resources on the other Lan fine.

We also have roaming users who connect to our office via Cisco VPN client software and they can access all our local network resources fine.

However, the roaming users cannot access the American resources, i.e. they connect to our office but cannot then continue through the lan 2 lan vpn successfully. They get correct DNS resolution of the American resources. The roaming VPN has split tunneling enabled, I tried disabling this but it made no change, except blocking any internet access they had.

Is this a limitation of the ASA or is there a config that I'm overlooking?

many thanks,

Alasdair Barclay
0
Comment
Question by:Alasdairb
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
3 Comments
 
LVL 57

Accepted Solution

by:
Pete Long earned 1000 total points
ID: 22711174
you need to enable hair pinning


To VPN into a security appliance (Cisco PIX or ASA) then come back out of that appliance to another site via VPN is called hair pinning. To do it you need a PIX/ASA that is running version 7.0(1) or above - which you do. .
To enable this on your firewall simply add the following line

same-security-traffic permit intra-interface
0
 

Author Closing Comment

by:Alasdairb
ID: 31505854
Perfect answer and easy to implement - thanks!
0
 
LVL 57

Expert Comment

by:Pete Long
ID: 22719564
ThanQ :)
0

Featured Post

Technology Partners: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This past year has been one of great growth and performance for OnPage. We have added many features and integrations to the product, making 2016 an awesome year. We see these steps forward as the basis for future growth.
For months I had no idea how to 'discover' the IP address of the other end of a link (without asking someone who knows), and it drove me batty. Think about it. You can't use Cisco Discovery Protocol (CDP) because it's not implemented on the ASAs.…
Windows 10 is mostly good. However the one thing that annoys me is how many clicks you have to do to dial a VPN connection. You have to go to settings from the start menu, (2 clicks), Network and Internet (1 click), Click VPN (another click) then fi…
Both in life and business – not all partnerships are created equal. As the demand for cloud services increases, so do the number of self-proclaimed cloud partners. Asking the right questions up front in the partnership, will enable both parties …

650 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question