Solved

ASA VPN Access List Issue

Posted on 2009-07-09
7
249 Views
Last Modified: 2012-05-07
I have an ASA 5510 with an access list that permits traffic to a SQL sever from a few IP sources, one being the VPN pool of addresses....I have a client who is VPN'd in from a hotel, and could not access the server?  The only way to do it was to add his source IP address to the permit list?  Since my VPN pool of addresses is permitted to this server shouldn't the source IP be one from the VPN pool?

the syslog message was Source IP 166.x.x.x Description: Deny tcp src outside.....by access group outside_access_in...

This is very strange to me why it would be denying the connection from the source outside, when he is VPN'd in...I confirmed it in the ASA, and his IP on his machine was one from the VPn pool?  Any suggestions would help...
0
Comment
Question by:bbresslin
  • 3
  • 3
7 Comments
 
LVL 33

Expert Comment

by:MikeKane
ID: 24826191
Would you post the code from the ASA if possible.  

There must be a problem between the IP pool config and the access-list somewhere.....
0
 
LVL 10

Expert Comment

by:stsonline
ID: 24826835
FYI, the reason the source is shown as outside is that whenever a VPN connection is established, it is generally coming in from the Internet, which is the outside interface. It looks weird, but that's the reason - the source is indeed on the outside interface.
0
 
LVL 1

Author Comment

by:bbresslin
ID: 24840410
The config on the ASA is massive and would take forever to scrub, but I can add some bullet points..

There is an access list on the outside interface allowing traffic from a few specific ip addresses to this particular server....A single public IP from another remote site, and the VPN pool of addresses...since "technically" the VPN pool of addresses aren't attached to the outside interface of the firewall, would the access list be blocking access to the app server on the outside since the traffic is coming from an IP address not being allowed on the outside interface?
0
PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

 
LVL 33

Expert Comment

by:MikeKane
ID: 24840980
Is the source IP 166.x.x.x part of your pool?    

Is your client vpn running a split tunnel config?   IS the traffic from the client coming across the vpn or the public net?  

Is there an access list applied to the inside interface in either direction?    Is the vpn pool on nonat?
0
 
LVL 1

Author Comment

by:bbresslin
ID: 24841308
166 is not part of the pool....VPN client is running split tunneling....traffic from client is coming across remote access VPN....VPN pool is nat exempt...
0
 
LVL 33

Accepted Solution

by:
MikeKane earned 500 total points
ID: 24841502
If 166 is not in the global pool, then I would double check your split tunnel rules also.    The split tunnel may not be catching traffic destined for this server.    If its a public web server, and the client is resolving the name to a public IP (as it normally would), then the traffic probably isn't VPN'd
0
 
LVL 1

Author Closing Comment

by:bbresslin
ID: 31605450
Customer is accessing via vpn, however the server is resolving to a public IP address, so it is not seeing this traffic as VPN traffic, client needed to access the server using the internal ip address rather than the name...
0

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Questions on windows ports 13 79
Lotus notes 9 firewall ports to be opened from Internal Firewall for the contractor ? 7 95
l2tp tunnel from pc to router 14 87
RDP Sonicwall 8 85
I recently had the displeasure of buying a new firewall at one of the buildings I play Sys Admin at. I had to get a better firewall than the cheap one that I had there since I was reconnecting the main office to the satellite office via point-to-poi…
This article offers some helpful and general tips for safe browsing and online shopping. It offers simple and manageable procedures that help to ensure the safety of one's personal information and the security of any devices.
Two types of users will appreciate AOMEI Backupper Pro: 1 - Those with PCIe drives (and haven't found cloning software that works on them). 2 - Those who want a fast clone of their boot drive (no re-boots needed) and it can clone your drive wh…
With Secure Portal Encryption, the recipient is sent a link to their email address directing them to the email laundry delivery page. From there, the recipient will be required to enter a user name and password to enter the page. Once the recipient …

831 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question