Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people, just like you, are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
Solved

Cisco ASA SSL VPN

Posted on 2010-09-09
5
660 Views
Last Modified: 2013-11-13
Hi,

I have a Cisco ASA 5510.  We have setup an SSL VPN using client download.  When the user connects to the SSL VPN they can browse and ping all resources on the internal network and use internal DNS, but they can no longer use the internet.  When loading websites the browser session just times out.

When I rund CMD prompt I pinging to www.google.com resolves to an IP address, but does not reply, same with tracert, it resolves but never reaches the google server.  

I think this could be an issue with split tunneling/DNS.  The fact that users can access all network resources, but cannot get out on the internet tells me that they are trying to come through the tunnel to use their local internet connection.  How would I change this?  

Any help would be much appreciated.  

Thanks

Neo3998
0
Comment
Question by:neo3998
  • 2
  • 2
5 Comments
 
LVL 17

Expert Comment

by:Kvistofta
ID: 33635667
Verify this:

1) Nat for outside traffic to outside.Like:
nat (outside) 1 10.0.0.0 255.255.255.0 where the ip network is your vpn client pool)
global (outside) 1 1.2.3.4 (where 1.2.3.4 is a public ip.

2) Is there any split-tunnel-policy defined in the group-policy?

3) Add "same security permit-intra-interface"

Verify these steps, if it still doesnt work please post your sanitized config here for investigation.

/Kvistofta
0
 
LVL 2

Author Comment

by:neo3998
ID: 33635981
Hi,

I am making changes via ASDM as I am not too great with Cisco command line.  How would I make these changes using this method?  

Thanks

Neo3998
0
 
LVL 17

Expert Comment

by:Kvistofta
ID: 33636080
I never use ASDM, cant tell you. Maybe someone else here can fill the gap? Unless you post the config here. This can be extracted from asdm from any of the top-menus in the gui.

/Kvistofta
0
 
LVL 57

Accepted Solution

by:
Pete Long earned 500 total points
ID: 33636814
0
 
LVL 2

Author Closing Comment

by:neo3998
ID: 33644745
Thanks very much :)
0

Featured Post

Netscaler Common Configuration How To guides

If you use NetScaler you will want to see these guides. The NetScaler How To Guides show administrators how to get NetScaler up and configured by providing instructions for common scenarios and some not so common ones.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
NAT Public IP through a VPN 17 68
cisco switch 3750E port channel down 13 29
VPN Ports 8 27
What is an ASP Table on a Cisco ASA? 3 15
Although it can be difficult to imagine, someday your child will have a career of his or her own. He or she will likely start a family, buy a home and start having their own children. So, while being a kid is still extremely important, it’s also …
Concerto Cloud Services, a provider of fully managed private, public and hybrid cloud solutions, announced today it was named to the 20 Coolest Cloud Infrastructure Vendors Of The 2017 Cloud  (http://www.concertocloud.com/about/in-the-news/2017/02/0…
In this fourth video of the Xpdf series, we discuss and demonstrate the PDFinfo utility, which retrieves the contents of a PDF's Info Dictionary, as well as some other information, including the page count. We show how to isolate the page count in a…
With the power of JIRA, there's an unlimited number of ways you can customize it, use it and benefit from it. With that in mind, there's bound to be things that I wasn't able to cover in this course. With this summary we'll look at some places to go…

809 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question