Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people, just like you, are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
Solved

Cisco VPN with Anyconnect - What outside IP address to use?

Posted on 2013-12-04
7
954 Views
Last Modified: 2014-01-22
Ok, this may seem like a silly connection but here goes.

I have a Site-to-site vpn set up between two of our offices.  The main and a branch.  For this site to site vpn I'm using our 'public' IP address that all the workstations get when they access the internet, (we use NAT).  The site-to-site works fine.

We also want to set up an anyconnect VPN.  It works internally using 192.168.1.1.  I thought I could use one of our 5 external IP's (e.g. 70.x.x.19).  Is this the correct way of doing this?  I'm basically am confused on what IP address I shoud be using.  We have 5 address, 4 are used already for email server, web server and two other servers.

Any help would be appreciated!
0
Comment
Question by:Jesh1975
  • 4
  • 3
7 Comments
 
LVL 12

Expert Comment

by:Henk van Achterberg
ID: 39696582
You should use the "interface IP address" for anyconnect. You cannot use another IP address for terminating anyconnect on it.

If you have for example the outside interface with ip 2.2.2.2/29 then you cannot use 2.2.2.3 for anyconnect, you have to use 2.2.2.2.
0
 

Author Comment

by:Jesh1975
ID: 39696609
Ok.  That is what I thought, but the problem is the outside IP is 10.1.10.200, which connects to our comcast business modem.

Inside 192.168.1.1/24
Outside 10.1.10.200/24
Then the cable modem is our public 70.xx.xx.xx.  

So I'm not sure what we are supposed to do here?
0
 
LVL 12

Expert Comment

by:Henk van Achterberg
ID: 39696616
You say that you have several public IP's but your ASA has a private IP address? Why is that?
0
Efficient way to get backups off site to Azure

This user guide provides instructions on how to deploy and configure both a StoneFly Scale Out NAS Enterprise Cloud Drive virtual machine and Veeam Cloud Connect in the Microsoft Azure Cloud.

 

Author Comment

by:Jesh1975
ID: 39696632
Our setup is:

Inside->Firewall->Cable modem so all traffic hits the cable modem first, then is routed to the firewall, which has always been like this for this company.  I don't think we can make the cable modem 'transparent'.

Any ideas??
0
 
LVL 12

Accepted Solution

by:
Henk van Achterberg earned 500 total points
ID: 39696655
well if that is the case you should look at the cable modem if you can NAT all ports to one inside IP address (10.1.10.200). If that is not the case you should MAP port by port. At least HTTPS, 443, to 10.1.10.200.

You should use the external 70.x.x.x IP for your clients to connect.
0
 

Author Comment

by:Jesh1975
ID: 39696707
Thank you this worked.  I still don't understand why my other public IP addresses (e.g. email, web server and so on) are working correctly.  They all work and do not have one to one mapping or anything.

Anyhow, I mapped our sslvpn.xxxx.com address to 10.1.10.200 (ASA "outside") and it worked!  Next on the list is getting VPN clients to be able to access the 192.168.1.0/24 network (the inside).

Thanks again for your help!
0
 

Author Comment

by:Jesh1975
ID: 39800633
Update: This ended up breaking our site-to-site VPN.  I forgot to update the comments on this.  I'm going to need to reopen this question...
0

Featured Post

Netscaler Common Configuration How To guides

If you use NetScaler you will want to see these guides. The NetScaler How To Guides show administrators how to get NetScaler up and configured by providing instructions for common scenarios and some not so common ones.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Lync - CUCM Integration Question 2 34
Cisco Maximum Prefixes Allowed for Customer 5 32
Cisco ASA blocks some https sites. 27 42
domian network access 5 20
This is an article about my experiences with remote access to my clients (so that I may serve them) and eventually to my home office system via Radmin Remote Control. I have been using remote access for over 10 years and have been improving my metho…
Let’s list some of the technologies that enable smooth teleworking. 
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Windows 10 is mostly good. However the one thing that annoys me is how many clicks you have to do to dial a VPN connection. You have to go to settings from the start menu, (2 clicks), Network and Internet (1 click), Click VPN (another click) then fi…

809 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question