Avatar of leadtheway
leadtheway
Flag for United States of America asked on

Configure Identity NAT ASA 8.2.3

Have ASA running 8.2.3, setup remote access vpn and using windows built in to access.  Get connected and get an IP either by DCHP or by creating address pool..either works, but i can't access anything on the network. I was told I need identity nat because the addresses are getting natted before they traverse back to the vpn client. But I'm not sure how to setup either CLI or ADSM access is available.  Attached is config..thanks
BKKASA-scrub.txt
Cisco

Avatar of undefined
Last Comment
Marius Gunnerud

8/22/2022 - Mon
Marius Gunnerud

you would need to do something like this:

object network LOCAL_NET
subnet 10.10.10.0 255.255.255.0

object network REMOTE_NET
subnet 11.11.11.0 255.255.255.0

nat (inside,outside) source static LOCAL_NET LOCAL_NET destination static REMOTE_NET REMOTE_NET
leadtheway

ASKER
ok, maybe this is the problem then  the pool that we created for VPN users is on the same subnet as the LAN
Marius Gunnerud

if you issue the management-access inside command on the ASA, are you able to ping the inside interface of the ASA when connected to the VPN?

Even if the address pool is the same as the local network, you will still need to have an Identity NAT configured when there is NATing between the interfaces.
Experts Exchange has (a) saved my job multiple times, (b) saved me hours, days, and even weeks of work, and often (c) makes me look like a superhero! This place is MAGIC!
Walt Forbes
leadtheway

ASKER
can ping a server by IP but not by dns
Marius Gunnerud

if you do an nslookup for the dns name, what IP is returned, and from which DNS server do you get the IP from?
leadtheway

ASKER
i think the pool has a static dns assigned,
Get an unlimited membership to EE for less than $4 a week.
Unlimited question asking, solutions, articles and more.
ASKER CERTIFIED SOLUTION
Marius Gunnerud

Log in or sign up to see answer
Become an EE member today7-DAY FREE TRIAL
Members can start a 7-Day Free trial then enjoy unlimited access to the platform
Sign up - Free for 7 days
or
Learn why we charge membership fees
We get it - no one likes a content blocker. Take one extra minute and find out why we block content.
Not exactly the question you had in mind?
Sign up for an EE membership and get your own personalized solution. With an EE membership, you can ask unlimited troubleshooting, research, or opinion questions.
ask a question