Solved

Cisco VPN client cannot reach other remote networks through tunnel

Posted on 2008-10-14
3
315 Views
Last Modified: 2012-05-05
Hi all,

I have a Cisco ASA5510 firewall running v7.0(7) which has a Lan 2 Lan VPN with our American office. All users on both Lans can access resources on the other Lan fine.

We also have roaming users who connect to our office via Cisco VPN client software and they can access all our local network resources fine.

However, the roaming users cannot access the American resources, i.e. they connect to our office but cannot then continue through the lan 2 lan vpn successfully. They get correct DNS resolution of the American resources. The roaming VPN has split tunneling enabled, I tried disabling this but it made no change, except blocking any internet access they had.

Is this a limitation of the ASA or is there a config that I'm overlooking?

many thanks,

Alasdair Barclay
0
Comment
Question by:Alasdairb
  • 2
3 Comments
 
LVL 57

Accepted Solution

by:
Pete Long earned 250 total points
ID: 22711174
you need to enable hair pinning


To VPN into a security appliance (Cisco PIX or ASA) then come back out of that appliance to another site via VPN is called hair pinning. To do it you need a PIX/ASA that is running version 7.0(1) or above - which you do. .
To enable this on your firewall simply add the following line

same-security-traffic permit intra-interface
0
 

Author Closing Comment

by:Alasdairb
ID: 31505854
Perfect answer and easy to implement - thanks!
0
 
LVL 57

Expert Comment

by:Pete Long
ID: 22719564
ThanQ :)
0

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

If you have an ASA5510 then this sort of thing would be better handled with a CSC Module, however on an ASA5505 thats not an option, and if you want to throw in a quick solution to stop your staff going to facebook during work time, then this is the…
Concerto Cloud Services, a provider of fully managed private, public and hybrid cloud solutions, announced today it was named to the 20 Coolest Cloud Infrastructure Vendors Of The 2017 Cloud  (http://www.concertocloud.com/about/in-the-news/2017/02/0…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Windows 10 is mostly good. However the one thing that annoys me is how many clicks you have to do to dial a VPN connection. You have to go to settings from the start menu, (2 clicks), Network and Internet (1 click), Click VPN (another click) then fi…

830 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question