Solved

Cisco ASA VPN - Is there any way to get a remote remote site to pass ALL Traffic across an IPSec VPN so that a central content filter will apply?

Posted on 2014-04-06
3
381 Views
Last Modified: 2014-05-30
Hello,

I have a (2) Site IPSec setup, and I want to get the internet traffic from the remote site to pass to the HUB site so that the content filter at that site processes the traffic from the remote site as well.  

I have done this with IOS VPN's before (GRE over IPSec with the default route pointing to a TUNNEL interface) but I have never found a solution that will let me do this with Cisco ASA's.  Sonicwalls seem to have it covered with the checkbox "Force all traffic to remote site" in the VPN ... I can't imagine that this is not possible with a Cisco ASA, which is supposed to be a superior device and platform.  

Note:  Because of the appliance (Barracuda 410), we cannot use WCCP as an option since the Barracuda will ONLY allow one host to do WCCP.

Thanks!
0
Comment
Question by:jkeegan123
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
3 Comments
 
LVL 16

Expert Comment

by:max_the_king
ID: 39982662
Hi,
you haven't fully described your architecture so i'm assuming that you have branch sites connected via vpn with head quarter, and the site-to-site vpns are up and running.

What i usually implement to my customers is a rule on the branch offices which do not let them go out on the internet, by simply setting an access-list on internal interface.
Then i allow branch offices to surf on the internet by using proxy settings in their browsers, where the proxy IP is the Barracuda appliance which is ubicated in the head quarter LAN.

The only way to avoid the need of proxy settings for the branch offices would be to define vlans on the central ASA, and define the same vlans on the barracuda, using virtual ip address on each subnet the barracuda should serve, but it would become really complicated, especially when troubleshooting.
My customers are happy to use proxy for branch offices anyway.

hope this helps
max
0
 
LVL 17

Accepted Solution

by:
MAG03 earned 500 total points
ID: 39990968
You can define in the crypto ACL that the destination is "any".  So basically anything that matches the defined source address will be encrypted and sent over the VPN tunnel.

Just remember to adjust your nat exempt statements to also define a destination of any.
0
 
LVL 5

Author Comment

by:jkeegan123
ID: 40032813
@MAG03:  Have you used this to accomplish this task?  This sounds like it would actually work well!
0

Featured Post

Industry Leaders: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Configuring WAN interface on Cisco ASA5525 3 61
VTP servers with 3650 switches 5 54
BGP DUAL ISP with IP SLA 10 69
VoIP Polycom Phones not working 30 70
If you have an ASA5510 then this sort of thing would be better handled with a CSC Module, however on an ASA5505 thats not an option, and if you want to throw in a quick solution to stop your staff going to facebook during work time, then this is the…
Exchange server is not supported in any cloud-hosted platform (other than Azure with Azure Premium Storage).
As a trusted technology advisor to your customers you are likely getting the daily question of, ‘should I put this in the cloud?’ As customer demands for cloud services increases, companies will see a shift from traditional buying patterns to new…
Both in life and business – not all partnerships are created equal. Spend 30 short minutes with us to learn:   • Key questions to ask when considering a partnership to accelerate your business into the cloud • Pitfalls and mistakes other partners…

738 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question