Link to home
Start Free TrialLog in
Avatar of nappyshock
nappyshock

asked on

ASA SSL clientless VPN

I have an outside interface IP address on the ASA with a 255.255.255.248 subnet allowing 6 IP addresses. I have setup clientless SSl vpn enabled on the outside interface and when i try to access it to the IP address within the subnet that is actually configured on the outside interface it works fine.
However if i try and set it up so the tunnel-group group-url points to one of the other IP's in the subnet it won't work.
Can anyone confirm whether it only works on the actual configured IP or should i be able to connect on any of the IPs in the subnet.

ie if IP was as shown below the address 1.1.1.1 would work but 1.1.1.2 - 1.1.1.6 would not.

 interface GigabitEthernet0/1
 nameif outside
 security-level 0
 ip address 1.1.1.1 255.255.255.248
ASKER CERTIFIED SOLUTION
Avatar of Member_2_2473503
Member_2_2473503
Flag of Philippines image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of nappyshock
nappyshock

ASKER

Thanks for quick response.
Thanks ebjers for the quick response!
I reason i was going to put the clientless SSL VPN on a seperate IP was because port 80/443 on the actual interface IP is being used by the SSL anyconnect client.
I suppose i could use a different port for the clientless SSL VPN.
in that case if your license allows it create a sub-interface