troubleshooting Question

CISCO L2L VPN stopping all traffic going over VPN

Avatar of DLeaver
DLeaverFlag for United Kingdom of Great Britain and Northern Ireland asked on
CiscoVPN
5 Comments1 Solution262 ViewsLast Modified:
Evening

I have a client who has multiple sites connecting back to a HQ site.  Currently all traffic is sent over the VPN's.  I want to stop this, and originally thought it was a routing issue however the default route is pointing to the current WAN IP for this device so I assume it is an ACL setting.

What ACL is needed to allow the internet traffic out locally and not over the VPN?

If the VPN went down would the local site revert sending traffic to the internet locally or just fail to get internet access?

Part of Config pasted below (IP's changed) - Dialer1 is the WAN interface:

!
ip classless
ip route 0.0.0.0 0.0.0.0 Dialer1
ip route 210.145.15.60 255.255.255.255 Dialer1
ip route 210.145.15.16 255.255.255.255 Dialer1
ip tacacs source-interface Ethernet0
no ip http server
no ip http secure-server
!
!
access-list 23 permit 210.145.15.16
access-list 23 permit 210.145.15.60
access-list 23 permit 10.44.0.0 0.0.255.255
access-list 23 permit 192.168.40.0 0.0.0.255
access-list 23 permit 10.12.0.128 0.0.0.31
access-list 23 permit 172.16.0.0 0.0.255.255
access-list 23 permit 10.9.4.0 0.0.0.255
access-list 101 permit ip 192.168.40.0 0.0.0.255 any
dialer-list 1 protocol ip permit
snmp-server community
no cdp run
ASKER CERTIFIED SOLUTION
DLeaver

Our community of experts have been thoroughly vetted for their expertise and industry experience.

Join our community to see this answer!
Unlock 1 Answer and 5 Comments.
Start Free Trial
Learn from the best

Network and collaborate with thousands of CTOs, CISOs, and IT Pros rooting for you and your success.

Andrew Hancock - VMware vExpert
See if this solution works for you by signing up for a 7 day free trial.
Unlock 1 Answer and 5 Comments.
Try for 7 days

”The time we save is the biggest benefit of E-E to our team. What could take multiple guys 2 hours or more each to find is accessed in around 15 minutes on Experts Exchange.

-Mike Kapnisakis, Warner Bros