Solved

Cisco ASA - Split Tunneling - allowing access to just one website?

Posted on 2014-12-15
3
327 Views
Last Modified: 2014-12-21
So I do not have split tunneling enabled for security reasons.  Users connect to AnyConnect to access a critical business application.  Recently the vendor of this application did a security upgrade.  Users now are prompted to verify a certificate that is hosted by godaddy.  So they need to be able to get to crl.godaddy.com, which resolves to about  3 different IP addresses.  I don't want to just enable split tunneling and give them free reign to the internet while connected.  I need to find a way to lock this down.  So below is what I have done so far:

Created a VPN Filter for those public IP's below:

object-group network DM_INLINE_NETWORK_50
 network-object host x.x.x.228
 network-object host x.x.x.237
 network-object host x.x.x.237

access-list VPN_FILTER extended permit ip object AC-pool object-group DM_INLINE_NETWORK_50

__________________________________________________________________________________________________________________________


OBJECT GROUP and NAT/PAT

object network AnyConnect-pool
 range 172.28.0.1 172.28.3.254
object network godaddy1
 host x.x.x.228
object network godaddy2
 host x.x.x.237
object network godaddy3
 host x.x.x.237

nat (outside,outside) source dynamic AnyConnect-pool interface destination static godaddy1 godaddy1
nat (outside,outside) source dynamic AnyConnect-pool interface destination static godaddy2 godaddy2
nat (outside,outside) source dynamic AnyConnect-pool interface destination static godaddy3 godaddy3

So if they put one of those public IP Addresses in their browser once connected to Anyconnect, they can verify the certificate and it works.  The problem is that the application looks for crl.godaddy.com not the public IP address, so if fails.  What can I do so it can look at the fqdn and not the public IP address?
0
Comment
Question by:denver218
  • 2
3 Comments
 
LVL 5

Expert Comment

by:Dawid Fusek
ID: 40500643
hi mate,

the easiest way I sometimes using when some app need access to something that should be in the internet but from security reasons is not accessible via the internet (public IP) that if it's accessible via name you can do the following:
- rewrite that name in your local IP address in some policy of VPN software
- set (if possible) this names with local IP to hosts files of the users computers
- us your own DNS server for that users and precise that name for them to track to your local IP's...

the problem is that this methods are workaround and not working in some cases, example with certification revocation lists, etc because app should see that you are trying too foolish it by changing the certificate servers IP... so in your case (in my opinion) you have to give users access via this VPN to that 3 servers (they don't need access to whole internet at all).

regards
NTShad0w
0
 
LVL 4

Accepted Solution

by:
denver218 earned 0 total points
ID: 40502475
The above configuration worked, I just had to allow DNS in the VPN filter.  They only have access to those 3 IP's on the internet.  They can't get to anything else.
0
 
LVL 4

Author Closing Comment

by:denver218
ID: 40511422
Found the solution on my own.
0

Featured Post

Secure Your Active Directory - April 20, 2017

Active Directory plays a critical role in your company’s IT infrastructure and keeping it secure in today’s hacker-infested world is a must.
Microsoft published 300+ pages of guidance, but who has the time, money, and resources to implement? Register now to find an easier way.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
VPN problems 4 62
Dlink-DIR 816 router 4 39
Grant drive/folder change permissions to VPN user 6 29
Password recovery 2950 is Deleting configuration Why 8 34
In the world of WAN, QoS is a pretty important topic for most, if not all, networks. Some WAN technologies have QoS mechanisms built in, but others, such as some L2 WAN's, don't have QoS control in the provider cloud.
Many of the companies I’ve worked with have embraced cloud solutions due to their desire to “get out of the datacenter business.” The ability to achieve better security and availability, and the speed with which they are able to deploy, is far grea…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Both in life and business – not all partnerships are created equal. As the demand for cloud services increases, so do the number of self-proclaimed cloud partners. Asking the right questions up front in the partnership, will enable both parties …

679 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question