force all internet traffice to go through the ASA VPN tunnel

Posted on 2009-02-17
Last Modified: 2012-05-06
I have configured 2 cisco asa 5505 and they are connecting network 1 and network 2  to each other via a VPN tunnel.

Network 1 has limited internet access via its gateway and I would like to find a way to redirect all the internet traffic on network1 to use the vpn tunnel as the main gateway and not the asa1 gateway.

is that feasible?


Question by:odewulf
    LVL 43

    Expert Comment

    So, essentially, you want to tunnel all traffic to network2?  If so, change your crypto access-lists to the following:


    access-list crypto extended permit ip any  <-- is network1


    access-list crypto extended permit ip any

    Make sure the NAT on ASA1 encompasses network1 ( in this example).
    LVL 43

    Accepted Solution

    You will also need to disable NAT for network1 on ASA1 so it isn't NAT'ed prior to being sent over the tunnel.  You can remove the global and nat commands on ASA1.

    By the way, you will use the same amount of bandwidth on your Internet circuit at network1.  The traffic will be IPSEC versus HTTP, FTP, etc but the bandwidth used will be the same.

    Author Comment

    thanks I am going to try that. I have some issues to resolve first with the port forwarding and then I will give it a try

    Write Comment

    Please enter a first name

    Please enter a last name

    We will never share this with anyone.

    Featured Post

    Highfive + Dolby Voice = No More Audio Complaints!

    Poor audio quality is one of the top reasons people don’t use video conferencing. Get the crispest, clearest audio powered by Dolby Voice in every meeting. Highfive and Dolby Voice deliver the best video conferencing and audio experience for every meeting and every room.

    I recently updated from an old PIX platform to the new ASA platform.  While upgrading, I was tremendously confused about how the VPN and AnyConnect licensing works.  It turns out that the ASA has 3 different VPN licensing schemes. "site-to-site" …
    This article will cover setting up redundant ISPs for outbound connectivity on an ASA 5510 (although the same should work on the 5520s and up as well).  It’s important to note that this covers outbound connectivity only.  The ASA does not have built…
    Internet Business Fax to Email Made Easy - With eFax Corporate (, you'll receive a dedicated online fax number, which is used the same way as a typical analog fax number. You'll receive secure faxes in your email, fr…
    This video discusses moving either the default database or any database to a new volume.

    779 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    9 Experts available now in Live!

    Get 1:1 Help Now