Solved

Cisco ASA 5510 AnyConnect DNS issues.

Posted on 2014-01-23
6
2,738 Views
Last Modified: 2014-02-15
Please bear with me. I've not had much hands on with ASA configuration etc...

I'm looking at setting up some users with an AnyConnect VPN connection and to then connect to our internally hosted Terminal Server farm.

The AnyConnect connection looks to be setup however when I establish a connection I cannot connect to any resources when using the DNS name. I can use the IP address OK and it resolves it fine.

I've seen a setting in the ASDM Connection Profiles VPN profile and within it under the DNS section its set to the Default DNS and the internal DNS servers are listed. However when I click on manage under the DNS Lookup section DNS Enabled is disabled on the outside interface.
I'm thinking that this is the issue. Would this be the case? What reason would it be disabled for?

Any help/advice would be great. Step by step via ASDM preferred.

Thanks,
Rich
0
Comment
Question by:mudfrog
6 Comments
 
LVL 13

Expert Comment

by:Michael Machie
ID: 39804070
It seems as if 'Split Tunneling' is configured on your VPN group. Please forgive me as I do not work with our ASA and do not configure the VPN Groups so I do not have instructions on how to configure it but this would be the cause.

Split Tunneling allows the User to connect to your network and access resources, via IP, but also splits out the HTTP traffic from your browser to use your LOCAL internet connection. When this is set up, the VPN group is required to use IP addresses for access to network (VPN) resources - servers, printers, shares etc.
If you did not have split tunneling configured all internet traffic from the VPN connected machine would route through your office's ISP connection, which could cause delays with accessing sites etc depending on your office's speeds.
0
 
LVL 9

Accepted Solution

by:
BigPapaGotti earned 350 total points
ID: 39804640
I want to make sure we are looking in the same location. Please follow the steps below to troubleshoot

1. Login to ASDM
2. Click on Configuration at the top of the screen
3. Click on "Remote Access VPN"
4. Expand "Network (Client) Access"
5. Click on "AnyConnect Connection Profiles"
6. Towards the bottom of your screen you will see a section for Connection Profiles. Highlight your connection profile and click on the "Edit" icon.
7. Towards the bottom of your screen you will see "DNS Servers:" Do you have any IP Addresses configured here? Also do you have a domain name configured in this box?

Now when the client connects you say that you are able to connect to devices via IP address but not DNS name correct? From a client connected to the VPN please perform the steps below.

1. Click Start
2. Type in "Command Prompt"
3. In a command prompt window type in "ipconfig /all"
4. Paste the results for review.
5. Try to perform a lookup via the nslookup command.
6. Type in "nslookup "name of device on your network"
7. Paste the results for review.
8. Finally try to ping the IP Address of your DNS server via the "ping" command.

Also can you let me know the subnet you are using on your local network before you connect to the VPN. For instance are you using 192.168.1.XXX in your home as well as 192.168.1.XXX at the office. or are they on different subnets? What about the DNS server is it on a similar network as your home network?
0
 
LVL 57

Expert Comment

by:Pete Long
ID: 39810123
Can you post a sanitised config?

pl
0
What is SQL Server and how does it work?

The purpose of this paper is to provide you background on SQL Server. It’s your self-study guide for learning fundamentals. It includes both the history of SQL and its technical basics. Concepts and definitions will form the solid foundation of your future DBA expertise.

 

Assisted Solution

by:mudfrog
mudfrog earned 0 total points
ID: 39847633
First of all apologies for the late response. I was pulled away onto other things.

BigPapaGotti, I have had a look at your suggestion and from what I can see its possible that the vpn connection profile is using DfltGrpPolicy (System Default) and a DefaultWEBVPNGroup as its Default Group Policies.
Upon looking in this policy it has no reference to any DNS servers within either of them.

Could it be this that is the issue?
0
 

Assisted Solution

by:mudfrog
mudfrog earned 0 total points
ID: 39847740
I have finally cracked it.

I did change the DfltGrpPolicy group policy which was being referenced and this has resolved the problems with DNS.

i am now able to connect and use DNS to connect to resources.

Happy Days!

I just need to sort out the AnyConnect licensing so I can then start to roll it out to users.
0
 

Author Closing Comment

by:mudfrog
ID: 39861142
Because I found part of the problem myself.
0

Featured Post

Netscaler Common Configuration How To guides

If you use NetScaler you will want to see these guides. The NetScaler How To Guides show administrators how to get NetScaler up and configured by providing instructions for common scenarios and some not so common ones.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
using BGP Attributes 2 89
VPN issue 2 58
Voicemail on Cisco Unity Express unit has quit working 6 27
Cisco Aironet 1140: setting up basic SSID 12 12
Remote Desktop Connections allow you to control remote host machines via the magic of the Internet and RDP (Remote Desktop Protocol). For the purposes of this article we will assume you are connecting from your home PC or laptop to a remote offic…
Remote Desktop Shadowing often has a lot of benefits. When helping end users determine problems, it is much easier to see what is going on, what is being slecected and what is being clicked on. While the industry has many products to help with this,…
How to install and configure Citrix XenApp 6.5 - Part 1. In this video tutorial we have explained step by step installation of Citrix XenApp 6.5 Server on Windows Server 2008 R2 is explained in this video. We have explained the difference between…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

777 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question