?
Solved

ASA AnyConnect tunneling

Posted on 2016-11-18
3
Medium Priority
?
62 Views
Last Modified: 2016-11-18
I have a firewall connected to the internet which doesn't have an inside interface.  The firewall has 2 public IP addresses.  The first public IP address is used for the firewall's outside interface.

I'd like to use the second public IP address to forward traffic to and from a Cisco AnyConnect client.  The client would VPN into the firewall and use the public IP address to communicate with the internet and the internet should be able to initiate connections to the client on port 443.

Right now my VPN works but something's wrong with the NAT rules because I can't access the internet.  After figuring this part out, I'd also like to make sure internet hosts are able to talk to my VPN client on the firewall's public IP address.

ASA.txt
0
Comment
Question by:GuyFaux
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
3 Comments
 

Author Comment

by:GuyFaux
ID: 41893876
Internet access with the secondary public IP has been confirmed.  Now I just need to make sure that requests to the public IP are forwarded to the VPN'ed in client.
0
 

Accepted Solution

by:
GuyFaux earned 0 total points
ID: 41893917
This command makes it work:

object network 192.168.0.1
 nat (outside,outside) static X.X.X.165
0
 

Author Closing Comment

by:GuyFaux
ID: 41893918
Found my own solution.
0

Featured Post

Optimum High-Definition Video Viewing and Control

The ATEN VM0404HA 4x4 4K HDMI Matrix Switch supports 4K resolutions of UHD (3840 x 2160) and DCI (4096 x 2160) with refresh rates of 30 Hz (4:4:4) and 60 Hz (4:2:0). It is ideal for applications where the routing of 4K digital signals is required.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

There’s a movement in Information Technology (IT), and while it’s hard to define, it is gaining momentum. Some call it “stream-lined IT;” others call it “thin-model IT.”
This article is in regards to the Cisco QSFP-4SFP10G-CU1M cables, which are designed to uplink/downlink 40GB ports to 10GB SFP ports. I recently experienced this and found very little configuration documentation on how these are supposed to be confi…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
As a trusted technology advisor to your customers you are likely getting the daily question of, ‘should I put this in the cloud?’ As customer demands for cloud services increases, companies will see a shift from traditional buying patterns to new…
Suggested Courses

770 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question