Link to home
Start Free TrialLog in
Avatar of Lizandro Diaz
Lizandro DiazFlag for United States of America

asked on

AnyConnect to multiple sites

Hello Cisco pros.

We have a HQ and 3 sites all with Cisco ASA 5505. Now I'm looking to be able to connect to HQ via Anyconnect and with that same connection be able to remote into the branch sites. All sites are connected to HQ via Site-to-Site.
Any ideas how can I get this done?
Thanks so much for your help.

User generated image
Avatar of asavener
asavener
Flag of United States of America image

First, all of the ASAs will need to have the site-to-site VPN updated to include the subnet that is assigned to remote access VPN devices.

Next, exclude the remote access VPN pool from NAT on the remote ASAs.  (Presumably, this has already been done on the HQ ASA.)

Finally, enable intra-interface traffic on the HQ ASA.   (same-security-traffic permit intra-interface)
Avatar of Lizandro Diaz

ASKER

Can I do this via ASDM or any ideas where can I get commands?
SOLUTION
Avatar of Pete Long
Pete Long
Flag of United Kingdom of Great Britain and Northern Ireland image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
I tried what Pete said and it worked!!!
Thanks so much Pete.  Before closing this question. Pete do you do you how to add multiple IP to AnyConnect see screenshot so you can see what I'm talking about. I know this is out of the scope, but I thought I may ask.

User generated image
ASKER CERTIFIED SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Well, Pete knows and answered my questions.
Thanks Pete.