How to open ports on Cisco ASA from off site through VPN connection

Posted on 2011-05-05
Medium Priority
Last Modified: 2012-05-11
I have an ASA setup and when I am off-site and I connect to the ASA via Cisco VPN Client, I cannot connect to certain software packages that require connections using specific ports, plus if I run a tracert, I get no response at each hop, just the ip I am running the tracert on. Is there some setting I need to enter on the ASA to allow me to setup VPN so that anyone off-site can run run all software package like they were on-site and that I can get responses from all hops via a tracert command?
Question by:Greg27
LVL 20

Accepted Solution

Svet Paperov earned 1000 total points
ID: 35705869
Ones the VPN connection is established there are two possibilities: either the whole traffic is tunnelled through the VPN (including the Internet one) or only a specified traffic is tunnelled, if split-tunnel and split-dns are configured for the VPN tunnel (on ASA site). In both cases the communication on all TCP and UDP ports to a tunnelled IP address goes through the VPN – that means, there is no need to open additional port on the firewall.

If you are doing tracert to an internal IP address through the VPN, you will not see any internet hop, again, because the traffic is tunnelled.

May be the only missing command on ASA is: same-security-traffic permit intra-interface

Assisted Solution

Ironmannen earned 1000 total points
ID: 35708441
Is the traffic routed on the main site? Then you will have problems if you have not created NAT rules for the traffic. Can you help us out with a description of the following:
From IP (VPN assigned):?
To IP (server):
Running config from the ASA:

Author Closing Comment

ID: 35899666
Thanks for the help guys. I no longer have access to the firewall, so I cannot go any furhter with this issue, but I wanted to reward you both for the help. I am just not adding it to the knowledge base.

Featured Post

Free Backup Tool for VMware and Hyper-V

Restore full virtual machine or individual guest files from 19 common file systems directly from the backup file. Schedule VM backups with PowerShell scripts. Set desired time, lean back and let the script to notify you via email upon completion.  

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

On Feb. 28, Amazon’s Simple Storage Service (S3) went down after an employee issued the wrong command during a debugging exercise. Among those affected were big names like Netflix, Spotify and Expedia.
Considering cloud tradeoffs and determining the right mix for your organization.
Both in life and business – not all partnerships are created equal. As the demand for cloud services increases, so do the number of self-proclaimed cloud partners. Asking the right questions up front in the partnership, will enable both parties …
Both in life and business – not all partnerships are created equal. Spend 30 short minutes with us to learn:   • Key questions to ask when considering a partnership to accelerate your business into the cloud • Pitfalls and mistakes other partners…
Suggested Courses

850 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question